TechNewsReel
Live

Coldcard Firmware Flaw Exposes 1,367 Bitcoin in PRNG Failure

A critical vulnerability in the 'Fort Knox' of hardware wallets allowed attackers to predict seed phrases, undermining the promise of self-custody.

TechNewsReel Newsroom · August 21, 2026

A critical firmware vulnerability in Coinkite's Coldcard hardware wallets has resulted in the theft of approximately 1,367.05 Bitcoin, shaking confidence in one of the industry's most secure storage solutions. The flaw, which dates back to a March 2021 release (version 4.0.1), allowed attackers to predict the seed phrases used to secure user funds.

According to reports from Galaxy Research and Business Punk, the exploit targeted 4,585 addresses across three initial waves of attacks. The stolen assets are valued at approximately $86 million to $89 million. The breach was not a result of a hack into the Bitcoin protocol itself, but rather a systemic failure in how the device generated the private keys that grant access to those funds.

The Entropy Failure

The vulnerability centered on the device's pseudo-random number generator (PRNG). In the affected firmware, the device failed to utilize hardware entropy and instead fell back to a predictable software-based random number generator. In some instances, this caused the device to generate seeds based on predictable data, such as device serial numbers.

Because the seed phrase is the master key to a Bitcoin wallet, any predictability in its generation allows an attacker to mathematically reconstruct the key. Aneirin Flynn, CEO of Failsafe, noted that while the device is designed to generate passwords, if the underlying mathematics are flawed, those passwords can be reconstructed.

A Blow to Self-Custody

Coldcard wallets have long been regarded as the 'Fort Knox' of Bitcoin storage due to their air-gapped, offline architecture, which is designed to keep private keys entirely isolated from the internet. This incident demonstrates that even air-gapped security is irrelevant if the core security architecture—the generation of the seed—is deterministic rather than truly random.

This failure strikes at the heart of 'self-custody,' the ethos of being one's own bank. By proving that high-end hardware can harbor fundamental flaws, the event may push cautious users away from self-managed wallets and back toward custodial services or Bitcoin ETFs, where a third party manages the technical risks of key generation.

Future Outlook

While the initial waves of theft are documented, the industry is now monitoring for further losses. Galaxy Research estimates that a potential fourth wave of attacks could bring total losses up to $130 million, involving roughly 1,600 Bitcoin across 7,300 addresses. Users of older Coldcard firmware are urged to audit their security and migrate funds to wallets generated with verified, high-entropy randomness.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.