Coldcard Entropy Bug: Firmware Flaw Drains $70M in Bitcoin from 1,196 Wallets
A hardware wallet trusted for years as a fortress of cold Bitcoin storage turned out to harbor a silent betrayal. A concealed firmware defect rendered the randomness generated during key creation entirely predictable – and attackers exploited that predictability to drain more than $70 million in Bitcoin from thousands of unsuspecting holders.
Coinkite Acknowledges the Vulnerability
Coinkite, the manufacturer of the Coldcard wallet, published a technical backgrounder on the entropy flaw acknowledging that the defect affected the Mk3 model and urging owners to transfer their funds to freshly generated addresses without delay.
The following day, the company broadened the scope of its warning. The risk, it clarified, extends to newer devices as well – the Mk4, Mk5, and Q models are all implicated.
The Root Cause: A Weak Software RNG Replaced the Hardware Generator
The vulnerability originates in the way seed phrases were constructed by affected firmware. A seed phrase is the sequence of words from which a wallet’s private key is mathematically derived. Beginning with firmware version 4.0.1, released in March 2021, the device silently substituted a weaker software-based random number generator in place of the dedicated hardware RNG it had previously relied upon.
Why 40 Bits of Entropy Is Catastrophically Insufficient
The consequence of this substitution was severe. Affected wallets received approximately 40 bits of entropy during key generation instead of the 128 bits that the security model demands. At 40 bits, the private key space shrinks to a range that can be exhausted through brute-force search using modern computing resources.
Single-signature wallets created without supplemental entropy – specifically, without at least 50 independent dice rolls or a strong, unique BIP-39 passphrase – were the most acutely exposed.
The Theft: $70 Million Across 1,196 Addresses
The first wave of unauthorized withdrawals materialized on Thursday, July 30. Within that initial sweep, 594.5 Bitcoin – valued at more than $35.7 million at the time – was drained from single-key addresses whose owners had no warning.
According to subsequent analysis by Galaxy Research and engineers at payments company Block, the total theft ultimately climbed to 1,082.65 Bitcoin across 1,196 compromised addresses – surpassing $70 million in value. Victims reported that funds held in apparent security since 2021 had vanished without a trace. At the time of publication, withdrawals from vulnerable wallets were reportedly still continuing.
Coinkite’s Position on the Connection
Coinkite has not yet directly confirmed that the thefts are causally linked to the entropy defect. However, the company has acknowledged the seed phrase generation bug itself. The investigation remains active and ongoing.
What Affected Users Should Do Immediately
Coldcard owners are urged to migrate their Bitcoin to a new wallet as promptly as possible. For those who generated their seed phrase without supplemental entropy – that is, without performing at least 50 independent dice rolls – Coinkite specifically recommends generating an entirely new seed phrase on a device running updated firmware.
A segment of the security community has gone further, advising users to suspend all use of Coldcard devices entirely until the full scope of the vulnerability has been authoritatively established and resolved.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.