TechNewsReel
Live

Coldcard RNG Flaw Leads to $130 Million Bitcoin Theft from Offline Wallets

A critical firmware vulnerability allowed hackers to predict recovery phrases and drain air-gapped wallets without physical access.

TechNewsReel Newsroom · August 7, 2026

A critical software bug in the seed generation process of Coldcard hardware wallets has allowed attackers to predict and brute-force recovery phrases, leading to massive losses for Bitcoin holders. The vulnerability enabled hackers to drain funds from offline "cold" wallets without requiring physical access to the devices or any internet connectivity.

According to security firms Elliptic and Galaxy Research, the total losses from the exploit are estimated at approximately $130 million. The theft was made possible by a flaw in the Random Number Generator (RNG) fallback and a 32-bit reseed vulnerability within the firmware, which reports indicate dates back to 2021. Because the RNG was predictable, attackers could mathematically determine the recovery phrases used to secure the wallets, bypassing the security of the hardware entirely.

The Failure of Air-Gapping

Coldcard, manufactured by Coinkite, is marketed as a high-security, air-gapped Bitcoin-only wallet designed specifically for self-custody. The device's core value proposition is that private keys never touch the internet, theoretically making them immune to remote hacking. By keeping the device offline, users believe they are protected from the vast majority of digital threats.

However, this incident demonstrates that air-gapping is irrelevant if the initial generation of the key is flawed. For victims, the realization that their physical security measures were useless has been devastating. Jonathan Goodman, a victim of the hack, noted that despite keeping his devices in multiple safes and safety deposit boxes and never sharing his seed phrase, his funds were still stolen. "None of it mattered," Goodman said.

Systemic Risks in Self-Custody

This exploit highlights a systemic risk inherent in the "not your keys, not your coins" philosophy of self-custody. It reveals that a single line of flawed code from a trusted hardware manufacturer can invalidate every other security layer a user implements, including physical vaults and offline storage. When the root of trust—the seed generation—is compromised, the entire security architecture collapses.

The event has reignited a fierce debate within the Bitcoin ecosystem regarding the trade-offs between self-custody and third-party custody. While self-custody removes the risk of a centralized exchange failing, it introduces a dependency on the technical perfection of the tools used to generate and store keys.

Looking Ahead

As the industry digests the scale of the Coldcard failure, the focus shifts to how other hardware wallet manufacturers handle RNG fallbacks and entropy. Users are now questioning whether other "secure" devices may harbor similar dormant vulnerabilities in their firmware. While the technical nature of the RNG flaw is now documented, the full extent of the impact may continue to emerge as more users discover their offline funds have been moved.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.