Coldcard RNG Flaw Leads to Over $100 Million in Bitcoin Theft
A critical firmware vulnerability disabled the hardware wallet's random number generator, allowing attackers to predict private keys.
A critical security flaw in Coldcard hardware wallets has resulted in the theft of more than $100 million in Bitcoin. The vulnerability stems from a firmware issue that disabled the device's built-in random number generator, rendering private keys predictable and accessible to attackers.
The exploit occurred across three confirmed attack waves, according to reports from Cointelegraph. Data from Galaxy Research indicates the scale of the breach has grown significantly, with over 1,596 BTC stolen from approximately 7,300 addresses. The theft was made possible by a firmware flaw dating back to March 2021 that turned off the secure element's hardware-based randomness generator. Without this entropy, the cryptographic keys used to secure funds became mathematically guessable by sophisticated actors.
The Role of Entropy in Hardware Security
Coldcard, developed by Coinkite, is marketed as a high-security, Bitcoin-only device featuring dual secure elements and air-gapped signing. The fundamental security of any hardware wallet relies on entropy—the high-quality randomness used to generate a private key. If the random number generator (RNG) is compromised or disabled, the resulting keys are no longer unique or random, effectively leaving the digital vault unlocked for anyone who knows the flaw's pattern.
Industry Implications
This incident underscores a systemic risk in hardware security: air-gapping a device provides no protection if the underlying cryptographic primitives are flawed. While air-gapping prevents remote hacking via the internet, it cannot protect against keys that are inherently weak at the moment of creation. The breach damages the perception of hardware wallets as a definitive security solution and highlights the danger of maintaining long-term fund exposure in wallets generated with flawed firmware.
What to Watch
Users are being urged to evaluate the firmware versions used during their wallet setup. While the core cause of the vulnerability has been identified as a 2021 firmware flaw, the industry is now watching for similar RNG failures in other secure-element-based devices. It remains to be seen if further attack waves will emerge as more compromised addresses are identified by researchers.