TechNewsReel
Live

Coldcard RNG Flaw Leads to $89 Million Bitcoin Heist

A critical firmware vulnerability allowed attackers to predict seed phrases and drain thousands of addresses.

TechNewsReel Newsroom · August 4, 2026

A critical vulnerability in the random number generator (RNG) of Coldcard hardware wallets has resulted in the theft of approximately $89 million in Bitcoin. The flaw allowed attackers to predict private seed phrases, bypassing the physical security of the devices to drain funds from thousands of users.

According to reports from CoinDesk, Decrypt, and BleepingComputer, the exploit targeted over 4,500 addresses. The scale of the attack was evident in its first wave, where attackers drained 1,083 bitcoin from 1,196 different addresses in a window of just 41 minutes. Total observed losses are currently estimated between $88.6 million and $89 million.

The Failure of Cold Storage

Hardware wallets like Coldcard are marketed as "cold storage," designed to keep private keys entirely offline to eliminate the risk of remote hacking. The security of this system relies on the absolute randomness of the seed phrase generated during setup. If the RNG is flawed or predictable, the resulting keys are no longer unique or secret. In this instance, a bug in the firmware meant that attackers could mathematically recreate the private keys for any wallet generated with the affected software, granting them full control over the funds without ever needing physical access to the hardware.

Implications for Crypto Security

This incident strikes at the fundamental trust in hardware wallets, which have long been viewed as the gold standard for cryptocurrency security. The breach demonstrates that offline storage is not an absolute safeguard if the underlying cryptographic implementation is compromised. For the broader industry, this highlights a systemic risk: a single firmware error can invalidate the security of thousands of devices simultaneously, potentially leading to massive losses that cannot be reversed due to the nature of the blockchain.

Immediate Response and Outlook

In response to the ongoing attacks, the CEO of Coinkite has urged customers to immediately generate new recovery phrases and move their funds to secure addresses, as reported by Fox Business. While the immediate focus is on fund migration, the industry is now watching for further evidence of similar RNG flaws in other hardware providers. It remains to be seen if more addresses will be compromised as attackers continue to scan for wallets generated with the vulnerable firmware.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.