Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
MacSync macOS Stealer Targets Users With Fake Claude Guide
August 3, 2026
Critical Coldcard RNG Flaw Linked to $88.6 Million Bitcoin Theft
August 3, 2026
Critical N-able N-central CVE-2023-40578 Lets Attackers Seize RMM Control
August 3, 2026
Home/CyberSecurity News/Critical Coldcard RNG Flaw Linked to $88.6 Million Bitcoin Theft
CyberSecurity News

Critical Coldcard RNG Flaw Linked to $88.6 Million Bitcoin Theft

Key Takeaways A critical firmware vulnerability in Coldcard hardware wallets, CVE-2024-XXXX (awaiting official assignment), has been exploited, leading to the theft of approximately $88.6 million in...

Marcus Rodriguez
Marcus Rodriguez
August 3, 2026 4 Min Read
3 0

Key Takeaways

  • A critical firmware vulnerability in Coldcard hardware wallets, CVE-2024-XXXX (awaiting official assignment), has been exploited, leading to the theft of approximately $88.6 million in Bitcoin.
  • The flaw, present in specific firmware versions of Mk3, Mk4, Mk5, and Q devices, compromised the random number generator used for private key creation, making seeds predictable.
  • Attackers leveraged the weakened entropy to regenerate private keys offline and drain funds from affected wallets without physical access.
  • Firmware patches were released on July 31st (versions 4.2.0, 5.6.0, 1.5.0Q), but updating does not remedy already compromised seeds. Users must migrate funds.

Coldcard RNG Flaw Implicated in $88.6 Million Bitcoin Heist

A severe vulnerability within the firmware of Coldcard hardware wallets has been directly linked to a substantial Bitcoin theft totaling an estimated $88.6 million. The exploit capitalized on a compromised random number generator (RNG), enabling malicious actors to reconstruct victims’ private keys remotely, bypassing the need for direct access to the physical devices.

Table Of Content

  • Key Takeaways
  • Coldcard RNG Flaw Implicated in $88.6 Million Bitcoin Heist
  • Discovery and Extent of the Breach
  • Unconventional Attack Vector
  • Root Cause: A Flawed Random Number Generator
  • Affected Devices and Patch Availability
  • What You Should Do

Discovery and Extent of the Breach

On July 30, digital asset research firm Galaxy Research first identified suspicious activity when an attacker rapidly siphoned approximately 1,082.65 BTC, valued at roughly $70.2 million at the time, from 1,196 distinct addresses. This initial wave of transactions concluded within a mere 41 minutes.

By August 1, Galaxy Research observed subsequent transaction waves, escalating the total stolen amount to 1,367.05 BTC, with an approximate value of $88.6 million, across 4,585 addresses.

Analysis of the transaction patterns indicated that the first two waves likely originated from a single operator due to their consistent characteristics. However, the third wave exhibited notable differences, suggesting either an evolution in the attacker’s tools or the involvement of a separate entity exploiting the same underlying vulnerability.

Unconventional Attack Vector

This incident deviates significantly from typical hardware wallet attacks, which commonly involve social engineering tactics like phishing, the installation of malicious firmware, or direct physical tampering with the device. Instead, the exploit specifically targeted the integrity of the wallet creation process itself.

Root Cause: A Flawed Random Number Generator

Investigations by payments firm Block’s Bitcoin Engineering and Security teams traced the vulnerability to a code alteration implemented on March 1, 2021. This change inadvertently deactivated the STM32 hardware random number generator in Coldcard’s production configuration.

The core issue stemmed from a faulty check within the libngu library. This check only verified if a configuration macro was defined, not whether it was actively enabled. Consequently, the system defaulted to MicroPython’s deterministic Yasmarang software generator, which was seeded using the device’s unique identifier (UID) and its internal timer state. This design choice severely undermined the randomness of seed generation.

Attackers consolidated 1,082 BTC from 1,196 Bitcoin wallets into four unmoved addresses (Source : glxyresearch )
Attackers consolidated 1,082 BTC from 1,196 Bitcoin wallets into four unmoved addresses (Source : Glxyresearch )

Coinkite, the Canadian manufacturer of Coldcard, has since confirmed that the effective entropy for seed generation plummeted to approximately 40 bits on Mk3 devices and around 72 bits on Mk4, Mk5, and Q models. These figures are drastically lower than the industry standard of 128 bits typically associated with a robust BIP-39 recovery phrase. This diminished entropy allowed attackers to generate a feasible number of candidate seeds offline, derive their corresponding Bitcoin addresses, and then cross-reference these against publicly available blockchain data to identify and target wallets containing funds.

Affected Devices and Patch Availability

Coinkite’s official advisory specifies that Mk2 and Mk3 devices running firmware versions 4.0.1 through 4.1.9 are susceptible to this vulnerability. Additionally, Mk4, Mk5, and Q devices running any firmware version preceding 5.6.0, 5.6.0, and 1.5.0Q, respectively, are also at risk, although with a comparatively higher entropy level.

According to a post on X by Galaxy Research, the exposure to this flaw is determined by the firmware version active when a wallet’s seed was initially generated, not the firmware currently installed on the device. Wallets created before March 2021 or those generated using 50 or more dice rolls or a strong BIP-39 passphrase are not considered vulnerable.

In response to the exploit, Coinkite released emergency firmware patches on July 31. These include version 4.2.0 for Mk3 devices, 5.6.0 for Mk4 and Mk5, and 1.5.0Q for Q models. However, the company has explicitly stated that simply updating the firmware will not rectify seeds that have already been compromised due to the flaw.

What You Should Do

  • Install Patched Firmware: Immediately update your Coldcard device to the latest patched firmware version (4.2.0 for Mk3, 5.6.0 for Mk4/Mk5, 1.5.0Q for Q devices).
  • Generate a New Seed: If your wallet was created with affected firmware, generate an entirely new seed on your device after updating.
  • Verify New Address: Carefully verify the new Bitcoin address displayed on your Coldcard device.
  • Test Transaction: Send a small test transaction to the new address to confirm functionality.
  • Migrate Funds: Immediately transfer all remaining funds from your old, potentially compromised address to the newly generated, secure address.
  • Consider Multi-Signature Setups: For enhanced security against single-vendor vulnerabilities, explore multi-signature wallet configurations utilizing devices from different manufacturers.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitPatchphishingSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical N-able N-central CVE-2023-40578 Lets Attackers Seize RMM Control

Next Post

MacSync macOS Stealer Targets Users With Fake Claude Guide

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Brinks Home Confirms Data Breach After ShinyHunters Claim
August 1, 2026
Top 10 DNS Security Solutions for 2026
August 1, 2026
Critical Flaw in Google Ad Manager Exploited to Deliver Crypto-Stealing Malware
August 1, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us