How a five-year-old build flag drained $116 million from bitcoin’s most trusted hardware wallet

1 hour ago 3



A single line of firmware shipped in March 2021 told every Coldcard hardware wallet to skip its dedicated randomness chip. For five years nobody noticed. Then an attacker brute-forced the weak seeds in 41 minutes, draining 1,816 BTC from more than 5,200 addresses across four attack waves. The incident is the largest hardware wallet exploit in crypto history, and it is forcing the entire bitcoin self-custody model to answer a question it has avoided since inception: who audits the code that generates your keys? Summary A build configuration error in Coldcard firmware version 4.0.1, shipped in March 2021, routed seed generation to a deterministic software pseudorandom number generator instead of the device’s STM32 hardware random number generator, reducing effective entropy from 128 bits to approximately 40 bits on Mk3 devices and 72 bits on Mk4, Mk5, and Q models. An attacker began sweeping wallets on July 30, 2026, draining 1,082 BTC from 1,196 addresses in 41 minutes during the first wave, with Galaxy Research tracking total confirmed losses of 1,596 BTC across three waves and estimating the figure could reach 2,055 BTC (approximately $130 million) if a suspected fourth wave is ve...

Read Entire Article