TechNewsReel
Live

Coldcard RNG Flaw Leads to $88.6 Million Bitcoin Theft

A critical vulnerability in the Mk3 hardware wallet's random number generator allowed attackers to derive private keys and drain millions in assets.

TechNewsReel Newsroom · August 3, 2026

A catastrophic security failure in the Coldcard Mk3 hardware wallet has resulted in the theft of approximately $88.6 million in Bitcoin. The breach, which came to light on July 31, 2026, stems from a critical vulnerability in the device's random number generator (RNG) that rendered recovery seeds predictable.

The exploit targeted wallets that generated their seeds using firmware versions 4.0.1 through 5.0.3. The theft occurred in rapid waves. On July 30, 2026, Galaxy Research reported that 1,196 Bitcoin addresses were drained of 1,082.65 BTC—roughly $70.2 million—in a 41-minute sweep. This was followed by another aggressive attack on July 31, where approximately 594 BTC, valued at $38 million, was stolen in a 25-minute window between 01:31 and 01:56 UTC. In response, manufacturer Coinkite issued an urgent security advisory on July 31, demanding that affected users move their funds immediately.

The Root of the Failure

Coldcard is marketed as an air-gapped, high-security device, but the breach revealed a systemic flaw in its core entropy process. The vulnerability was traced back to a firmware integration error introduced as early as March 2021 in version 4.0.0. This error caused the device to skip essential hardware-based randomness, instead relying on predictable software-based generation. Because the resulting seeds were not truly random, attackers were able to mathematically derive the private keys for wallets, regardless of whether the assets had been dormant for years or recently deposited.

Industry Implications

This event represents a severe blow to the perceived reliability of "gold standard" hardware security. The realization that a trusted device could fail so fundamentally triggered a massive panic among the user base. Data shows a mass migration of funds, with approximately 39,600 BTC moved in sub-1 BTC transfers as users rushed to secure their assets. Analysts have noted that the scale of this movement is comparable to the volatility seen during the FTX collapse, highlighting how a single point of failure in hardware can create broader market instability.

What Remains

While Coinkite has alerted users, the full extent of the damage may still be emerging as more users discover their funds are missing. The industry is now facing a critical reckoning regarding the auditing of RNG processes in hardware wallets. Investors and security researchers are watching to see if other devices utilizing similar firmware architectures are susceptible to the same class of predictable seed generation.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.