TechNewsReel
Live

Coldcard RNG Flaw Leads to Millions in Bitcoin Theft

A critical vulnerability in Coinkite's hardware wallets allowed hackers to remotely guess seed phrases and drain assets.

TechNewsReel Newsroom · August 5, 2026

A critical security flaw in Coldcard hardware wallets has resulted in the theft of millions of dollars in Bitcoin, shattering the perceived safety of one of the industry's most prominent "cold storage" solutions. The breach allowed attackers to remotely drain funds from thousands of accounts without ever needing physical access to the devices.

The vulnerability originated from a March 2021 software update involving a cryptographic library integration that compromised the device's Random Number Generator (RNG). This flaw introduced a predictable pattern into the generation of seed phrases, the master keys used to recover wallets. By exploiting this mathematical predictability, hackers were able to guess recovery phrases remotely. The attacks unfolded in waves starting around July 30, 2026; in one particularly aggressive surge on that date, 1,196 addresses were drained in approximately 41 minutes. While total loss estimates vary across reports, some outlets cite figures between $116 million and $140 million USD.

The Failure of Cold Storage

Coldcard devices, manufactured by the Canadian firm Coinkite, are marketed specifically as cold storage. The core value proposition of such devices is that they keep private keys entirely offline, creating an "air gap" that theoretically makes remote hacking impossible. However, this exploit bypassed the physical security of the hardware entirely. Instead of attacking the device's perimeter, the hackers attacked the underlying mathematics of the keys themselves. By identifying the flaw in the RNG, the attackers turned a supposedly offline vault into a vulnerable target through a software-level error in the firmware.

Industry Implications

This incident undermines a fundamental belief in the cryptocurrency ecosystem: that self-custody via hardware wallets is immune to remote attacks. The breach highlights the catastrophic risk of "predictable randomness" in cryptographic systems, demonstrating that a single coding error in firmware can invalidate years of rigorous hardware security design. For the broader market, this may accelerate a shift in user behavior, potentially pushing some investors away from self-custody and back toward centralized exchanges where the burden of technical security is managed by a third party.

The Path Forward

In the wake of the breach, Coinkite has released a firmware fix to address the RNG vulnerability. Rodolfo Novak, CEO of Coinkite, expressed devastation over the event, stating, "I’m sorry and I’m devastated. Our team is heartbroken about yesterday’s news." In an official statement, the company added that they owe the community better and are working to understand how their designs allowed the failure to occur. Users are urged to update their firmware immediately, though those whose seed phrases were generated using the compromised 2021 update may already have had their funds compromised.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.