Coldcard PRNG Flaw Lets Attackers Reconstruct Private Keys: 1,367 BTC Drained
Key Takeaways
- •Attackers stole at least 1,367 BTC worth approximately $86 million from over 4,500 Coldcard-generated addresses without needing physical access to any device.
- •A March 2021 firmware error caused the pseudo-random number generator to rely on the microcontroller's serial number and clock registers instead of a dedicated hardware RNG, drastically reducing seed entropy.
- •Galaxy Research identified three coordinated attack waves, with the first wave alone draining 1,082.65 BTC from 1,196 addresses in just 41 minutes on July 30, 2026.
- •Coinkite's advisory covers Mk3, Mk4, Mk5, and Coldcard Q devices, and users who created seeds on vulnerable firmware must generate new seeds on patched firmware and migrate all funds.
- •The incident has prompted industry-wide calls for stronger independent auditing of entropy quality and formal security proofs for random-number generation in hardware wallets.

A firmware vulnerability in the Coldcard Bitcoin hardware wallet has enabled attackers to drain at least 1,367 BTC—worth approximately $86 million at current prices—from more than 4,500 cold storage addresses across three coordinated waves of attacks. The exploit did not require physical access to any device; instead, attackers reconstructed private keys from scratch using mathematical techniques. Coldcard, manufactured by Toronto-based Coinkite, is widely favored among Bitcoin self-custody advocates for its air-gapped design and security-first reputation, making the scale of the compromise particularly significant for the hardware wallet segment.
Galaxy Research said its Bitcoin on-chain analysis identified three suspected attack waves targeting addresses generated by Coldcard, involving 4,585 addresses and a total of 1,367.05 BTC… pic.twitter.com/JdSz4W1TIk — Wu Blockchain (@WuBlockchain) August 1, 2026
The breach strikes at the core premise of Bitcoin self-custody: that a private key stored offline is effectively unreachable. This attack demonstrated that a key generated with insufficient randomness can be neither unreachable nor unguessable. Bitcoin's transparent public ledger amplified the danger—because all addresses are visible on-chain, attackers could check candidate keys against real balances in real time, a property that makes entropy failures uniquely exploitable compared to opaque financial systems.
The incident has unfolded as BTC trades at approximately $62,250, down 1.4% on the day, amid circulating rumors that Michael Saylor may sell additional Bitcoin holdings and as the CLARITY Act deadline approaches without an apparent breakthrough.
$BTC is back into the $62,000-$62,500 level. Hold this level, and Bitcoin could rally towards $65,000. Lose this level, and BTC could drop to $60,000. pic.twitter.com/O877SmIdMU — Ted (@TedPillows) August 3, 2026
How a Broken Random-Number Generator Compromised Cold Storage
Coinkite confirmed that a March 2021 firmware error introduced a vulnerability in the device's pseudo-random number generator (PRNG) during seed phrase creation. Rather than drawing from a dedicated hardware random-number generator, the firmware relied on the microcontroller's serial number and clock registers. This drastically reduced the entropy of generated seeds, shrinking the keyspace from cryptographically vast to practically countable. PRNG vulnerabilities have surfaced in the cryptocurrency ecosystem before—a 2013 flaw in Android's secure random number generator led to predictable wallet keys and direct Bitcoin thefts—underscoring that entropy generation remains a recurring failure point across both software and hardware wallet platforms.
With the weakened keyspace, attackers could generate candidate seeds, derive their corresponding Bitcoin addresses, and check those addresses against the public blockchain for balances—all without ever touching the victim's hardware wallet.
Galaxy Research's analysis detailed the first attack wave: on July 30, attackers stole 1,082.65 BTC from 1,196 addresses in just 41 minutes. A second wave followed, draining approximately 208 BTC from 1,912 addresses using more sophisticated methods, including batching multiple victims' transactions together. Galaxy assessed that the attacks were likely orchestrated by a single operator, though it has not definitively linked all three waves.
$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack. My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet. This part's nerdy, but here's… pic.twitter.com/Lf9kJv9Jo4 — Jonathan Goodman (@itscoachgoodman) August 1, 2026
Affected Wallets and Required Actions
Coinkite initially issued a warning for Mk3 devices running firmware version 4.0.1 or later, subsequently expanding the advisory to include certain Mk4, Mk5, and Coldcard Q firmware versions. Emergency firmware updates were released, and CEO Rodolfo Novak issued an apology, taking "full accountability" for the bug.
However, installing the updated firmware alone does not remediate the vulnerability for seeds that were generated on an affected build. Users who created seeds on vulnerable firmware must generate an entirely new seed on patched firmware and migrate all funds to a new wallet. The period between the March 2021 firmware release and the July 2026 attacks means affected seeds could have been in use for over five years, compounding the number of wallets at risk.
Jan3 CEO Samson Mow urged all Coldcard users to migrate their funds immediately given the ongoing attacks. Block's Clay Garrett disclosed that a paid account was used to help identify source addresses involved in the attacks, and that this information has been shared with authorities.
Self-Custody Transfers Risk—It Does Not Eliminate It
The Coldcard incident reflects a broader pattern observed in 2026: while infrastructure and key-compromise incidents have become less frequent, they account for a disproportionate share of dollar losses across the cryptocurrency industry. For the hardware wallet sector, the episode raises questions about how entropy quality is independently audited and whether manufacturers should be required to publish formal security proofs for their random-number generation implementations.
Speculation on X has suggested that AI-assisted tools may have played a role in discovering or exploiting the PRNG flaw, though neither Coinkite nor Block has confirmed this.
The episode underscores a fundamental principle of hardware wallet security: the strength of a device depends critically on the quality of randomness used during key generation. As Galaxy Research noted, the declining cost of analyzing weak keyspaces means the industry must adopt stronger standards for entropy verification.
For Bitcoin holders using Coldcard devices in self-custody, the recommended steps are to check device firmware against Coinkite's official advisory, generate a new seed on fully updated firmware, and migrate all funds to a secure new wallet.