Incident case file
Sign in to watchColdcard Mk3 Firmware RNG Flaw — 594 BTC Mass Wallet Sweep
15 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beat- T-1925dMarch 1, 2021
Root cause introduced
during a migration to libsecp256k1 in Coldcard firmware 4.0.0, the production board configuration defined a macro (MICROPY_HW_ENABLE_RNG) as zero, and a verification check in the underlying library tested only whether this setting existed rather than whether it was enabled. This caused seed generation to silently fall back to a non-cryptographic software PRNG ('Yasmarang'), seeded from non-secret data — the device's 32-bit chip ID and SysTick timer register (fewer than 80,000 possible values) plus the real-time clock — producing seeds with roughly 40 bits of entropy instead of the intended 128 bits. T0 — July 31, 2026, 01:31-01:56 UTC: Over a 25-minute window spanning three Bitcoin blocks, an attacker sweeps 594.48 BTC (~$38.3M) from approximately 500 single-signature wallets in 500 transactions moving 1,324 separate portions of bitcoin. All affected wallets had generated their seeds on vulnerable Coldcard Mk3 firmware. Roughly 562 BTC is later consolidated into a single address (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r), which remains unmoved as of reporting. July 30, 2026 (preceding the sweep by roughly 30 hours per later analysis): Coinkite publishes an emergency advisory warning Coldcard Mk3 users who generated a seed on firmware 4.0.1 or later, urging immediate migration to a newly generated seed on updated hardware. CoinDesk and other outlets report the incident on July 31, framing it as an emergency disclosure made ahead of full internal testing due to active exploitation. Bitcoin engineering researchers at Block, including security engineer Clay Garrett, trace the vulnerable code change to the March 2021 commit and publish a full technical writeup. Independent analysis (Galaxy Research, based on the same on-chain fingerprint) suggests the true scope could extend to as many as 1,082.65 BTC (~$70.2M) across additional addresses and a longer ~41-minute window — this broader figure is NOT confirmed by Coinkite and should be treated as a preliminary estimate. Coinkite releases patched firmware (4.2.0+ for Mk3, 5.6.0+ for Mk4/Mk5, 1.5.0Q+ for Q) and continues to characterize Mk4, Q, and Mk5 devices as unaffected based on early analysis. As of reporting, 0% of stolen funds have been recovered, and the attacker's identity remains unknown.
Sources and coverage
- Articlecoindesk.comhttps://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep
- Articleengineering.block.xyzhttps://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
- Articleblog.coinkite.comhttps://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
- Articlebeincrypto.comhttps://beincrypto.com/coldcard-rng-flaw-bitcoin-theft/
- Articlethecybersecguru.comhttps://thecybersecguru.com/news/coldcard-seed-generation-firmware-flaw-bitcoin-wallets/
- Articlex.comhttps://x.com/glxyresearch/status/2083181683067506899
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)