Coldcard Bitcoin exploit explained: How a firmware bug turned entropy into a ticking time bomb

1 hour ago 1



For five years, a subset of Coldcard hardware wallets were generating Bitcoin keys with the cryptographic equivalent of a flimsy padlock. The bug, introduced during a March 2021 firmware rewrite in version 4.0.1, replaced the device’s hardware random number generator with a software-based pseudorandom number generator. The result: seed phrases that looked secure but were dramatically easier to crack than anyone realized. Attackers figured it out in late July 2026, executing coordinated sweeps that drained approximately 594 BTC, roughly $38 million, from around 500 wallets in under 30 minutes. Some estimates put the total losses across all affected users at over 1,300 BTC, north of $80 million. What went wrong with entropy Here’s the thing about Bitcoin security: it all comes down to randomness. When a hardware wallet generates your seed phrase, it needs to pull from a source of entropy, true unpredictability, that makes your private keys essentially impossible to guess. The industry standard target is 128 bits of entropy, which translates to a number so astronomically large that brute-forcing it would take longer than the age of the universe. Coldcard’s firmware version 4.0.1 broke...

Read Entire Article