TechNewsReel
Live

Coldcard Mk3 Entropy Flaw Leads to $89 Million Bitcoin Theft

A critical failure in the hardware wallet's random number generator allowed attackers to brute-force private keys in a coordinated strike.

TechNewsReel Newsroom · August 4, 2026

A critical vulnerability in Coinkite's Coldcard Mk3 hardware wallets resulted in the theft of approximately $88-89 million in Bitcoin on July 30. The incident highlights a systemic failure in the device's core security architecture, proving that even air-gapped systems are vulnerable if their underlying cryptography is flawed.

In a coordinated burst lasting approximately 25 minutes, attackers drained roughly 1,083 BTC from about 1,196 different addresses. The exploit was made possible by a failure in the Coldcard Mk3's random number generator (RNG). Instead of producing the industry-standard 128 bits of entropy required for a secure seed, the devices generated seeds with only about 40 bits of entropy. This massive reduction in randomness allowed attackers to brute-force the limited entropy space and derive the private keys for a large number of users.

The Role of Entropy in Hardware Security

Hardware wallets are designed to keep private keys entirely offline, serving as a fortress against remote hacking attempts. The security of these devices relies on high-quality entropy—true randomness—to ensure that the seed phrase used to recover a wallet cannot be guessed or predicted. When an RNG fails to provide sufficient entropy, the resulting keys are no longer mathematically unique enough to resist targeted attacks.

In the case of the Mk3, the gap between 40 bits and 128 bits of entropy represents a catastrophic loss of security. This flaw turned a virtually impossible guessing game into a computationally feasible task for sophisticated actors, effectively stripping away the mathematical protections that users rely on for long-term storage.

Implications for Air-Gapped Security

This breach undermines the perceived safety of "air-gapped" security. While air-gapping protects a device from network-based attacks, it offers no protection if the keys themselves are generated using a flawed process. The incident demonstrates that the physical isolation of a device is irrelevant if the cryptographic foundation is compromised.

For the broader industry, this serves as a warning that hardware manufacturers must prioritize the verification of their RNGs. Systemic failures of this nature can affect thousands of users simultaneously, regardless of how the device is stored or used. The reliance on a single point of failure in the entropy generation process creates a vulnerability that cannot be patched via software once the seed is generated.

Future Outlook and Verification

Industry observers are now focusing on the necessity of certified hardware randomness to ensure that entropy generation meets rigorous, independent standards. While the core details of the July 30 theft are well-documented, the industry continues to analyze the full scope of the affected devices.

Users of the Coldcard Mk3 are encouraged to verify the integrity of their seeds and monitor for any further vulnerabilities as the community works to establish more transparent certification processes for hardware randomness. This event underscores the need for open-source entropy audits to prevent similar failures in the future.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.