Coldcard Hack: Bitcoin Losses and Seed Flaw Explained

요약:Galaxy Research estimates total losses from the Coldcard hack at about 2,055 Bitcoin ($130 million) across more than 7,700 victim addresses. The flaw stemmed from a March 2021 firmware integration error that routed seed generation to a deterministic software PRNG instead of the hardware random number generator, leaving roughly 40 bits of effective entropy on Mk3 and about 72 bits on newer models. On-chain analysis identified multiple sweep waves, including an initial drain of 1,082.65 BTC and a later wave of about 208 BTC, though Galaxy cautioned that each waves operator could not be conclusively linked. Coinkite shipped emergency firmware, but updating does not repair existing weak seeds; affected owners must generate new seeds and migrate coins, as restoring the old seed preserves the vulnerability.

In the latest Bitcoin news today, Analytical estimates from Galaxy Research, cited by analytics account Lookonchain, indicate that total losses tied to the Coldcard hack have reached approximately 2,055 Bitcoin (BTC), worth $130 million, across more than 7,700 victim addresses.

The estimate follows reports of multiple suspected on-chain sweep waves linked to a seed-generation flaw in devices made by Canadian firm Coinkite.

The flaw affected how seeds were generated on vulnerable firmware, allowing attackers to derive and test candidate keys offline when they could determine or sufficiently constrain relevant device information.

EXPLORE: Best Meme Coins to Buy for August

Bitcoin News Today: Coldcard Firmware Flaw and Weak Randomness

March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG) rather than the STM32 hardware random number generator (RNG).

The production configuration defined the hardware-RNG macro as zero, while the underlying libngu library checked whether the macro existed rather than whether it was enabled, binding the build to MicroPythons Yasmarang fallback.

The MicroPython fallback was initialized from chip unique identifiers and timer registers and did not collect fresh entropy after initialization. Block said an attacker able to determine or sufficiently constrain the device UID, timer state and prior RNG-call history could reproduce candidate output streams offline, then derive addresses and compare them with public blockchain data.

????URGENT COLDCARD SECURITY UPDATE

Read carefully before acting.

????Mk3 seed generated on 4.0.1+ without ≥50 private, independent dice rolls: begin a careful migration now.

????Mk4/Mk5<5.6.0 or Q <1.5.0Q: update first, generate a new seed, then migrate.

— COLDCARD (@COLDCARDwallet) July 31, 2026

Coinkite estimated effective entropy for affected seeds at roughly 40 bits on Mk3 hardware and about 72 bits on Mk4, Mk5 and Q models, compared with 128 bits for a 12-word BIP-39 seed. The practical cost of reproducing seeds depends on available UID information, boot timing, prior RNG calls and derivation cost, according to Block.

The incident highlights the importance of seed-generation security and auditing critical flaws in open-source repositories used by cryptographic hardware. Coinkite shipped emergency firmware for affected models and release tracks on July 31, but installing updated firmware does not repair an existing weak seed. The company advises owners with exposed seeds to generate a new seed on patched firmware and move their coins; restoring the old seed carries the weakness forward.

DISCOVER: Best Meme Coins to Buy in 2026

On-Chain Analysis of Suspected Sweep Waves

Detailed on-chain analysis of the Coldcard PRNG vulnerability identified an initial July 30 sweep that drained 1,082.65 BTC from 1,196 addresses in 41 minutes. That opening wave averaged close to one BTC per address.

This is insane!

According to @glxyresearch, the total losses from the #Coldcard hack may have reached 2,055 $BTC($130M).

More than 7,700 victim addresses have been affected.

— Lookonchain (@lookonchain) August 4, 2026

Subsequent tracking documented by CoinDesk reporting identified a third suspected wave that drained roughly 208 BTC from 1,912 addresses, or just over one-tenth of a BTC per victim.

In that later wave, transactions batched an average of six victims per sweep, sent each victims coins to a separate destination and used pay-to-witness-script-hash (P2WSH) outputs rather than the plain single-key outputs used in earlier waves.

Galaxy Research said it was confident that each wave was internally the work of one operator, but cautioned that on-chain data could not determine whether the same attacker was responsible for all three waves.

The firm also said it had not computationally confirmed that every identified address was generated with weak Coldcard entropy. Galaxy reported roughly 600 suspected attacker-controlled addresses to federal investigators, compliance firms and cybersecurity investigators.

Disclaimer: Coinspeaker is committed to providing unbiased and transparent reporting. This article aims to deliver accurate and timely information but should not be taken as financial or investment advice. Since market conditions can change rapidly, we encourage you to verify information on your own and consult with a professional before making any decisions based on this content.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

BitMEX 매각, 창업자 소유권과 축소되는 사업에 대한 매수자들의 반대로 무산

다음

비트코인 투자자들, 현물 ETF에 8억 5,300만 달러 쏟아부어. 블랙록의 IBIT가 대부분 차지