← Blog · · df00tech

COLDCARD Hardware Wallet RNG Flaw Reportedly Linked to $88.6M Bitcoin Theft

security-news breach

What happened

According to a report from BleepingComputer, a vulnerability in the firmware of COLDCARD hardware wallets involved a flawed random number generator (RNG) used during seed generation. The outlet reports this weakness is likely linked to the theft of an estimated $88.6 million in Bitcoin from thousands of affected wallets whose seed phrases were generated while the flaw was present.

Details on the precise root cause of the RNG weakness, the affected firmware version range, and the exact attribution of the theft have not been independently confirmed here; this summary reflects what has been reported so far.

Why it matters for defenders

Hardware wallets are widely trusted as a strong, offline root of key material for cryptocurrency holdings, precisely because they are expected to generate cryptographically sound randomness. A flaw in the RNG undermines that trust model at its foundation: if seed entropy is predictable or reducible, an attacker who can reproduce or narrow the keyspace can derive private keys without ever touching the device or its owner's credentials.

This is relevant beyond the cryptocurrency space. Organizations that rely on hardware security modules, hardware tokens, or embedded devices for key generation should treat this as a reminder that RNG quality is a critical, easily-overlooked trust assumption in any cryptographic supply chain.

What defenders and holders should watch for now

  • If you use a COLDCARD wallet, check the vendor's official channels for firmware advisories, patch guidance, and any tooling to determine whether a given wallet's seed was generated during the affected period.
  • Treat any seed generated on potentially affected firmware as compromised; the standard mitigation for a broken RNG is to migrate funds to a newly generated wallet using confirmed-patched firmware or an alternate trusted device, not merely to update firmware in place.
  • Monitor wallet addresses tied to potentially affected seeds for unauthorized outbound transactions, and consider this an active theft scenario until vendor guidance says otherwise.
  • More broadly, incident responders and blockchain analytics teams should watch for indicators of RNG-related key compromise across other hardware wallet or key-management products, since weak entropy bugs are a known recurring class of vulnerability in embedded crypto implementations.

Developing story

This is a developing report and the full technical details of the RNG flaw, its scope, and formal vendor confirmation are still emerging. For the latest information, see the original report from BleepingComputer: COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.