Skip to content
News · · 3 min read · 506 words

Coldcard RNG Flaw: Coinkite Discloses Five-Year Entropy Failure After Mass Bitcoin Theft

A 2021 firmware change routed Coldcard seed generation through a software pseudorandom generator instead of the hardware RNG, cutting entropy from 128 bits to about 72. Coinkite patched on 30 July; wallets were being swept within hours.

Share
Editorial illustration: a wide funnel narrowing to a thin neck, only a few spheres trickling through — reduced entropy.
Editorial illustration: a wide funnel narrowing to a thin neck, only a few spheres trickling through — reduced entropy.

What Coinkite disclosed

Coinkite confirmed that a firmware migration in March 2021 introduced an integration error in which ngu.random fell through to MicroPython’s deterministic Yasmarang generator rather than the STM32 hardware RNG on the device. Seeds produced under the affected builds therefore drew on substantially less entropy than the design intended — approximately 72 bits against a target of 128.

The distinction matters. 128 bits of entropy is not searchable. 72 bits is a different proposition entirely for a well-resourced attacker with a specific, enumerable target set.

The sweep

Reporting on the scale of the theft varies by outlet and by the date the count was taken, and Conisec reports that divergence rather than picking a number. CoinDesk reported a 594 BTC sweep inside 25 minutes on 31 July. The Hacker News reported roughly $70 million taken in a 41-minute window. Crypto Briefing put the figure at approximately 1,367 BTC — near $89 million — across 4,585 addresses over several waves from 30 July. Fortune subsequently reported a $116 million total.

These are not contradictory so much as cumulative: the counts were taken at different points in an ongoing sweep. We will update this record as the affected parties publish confirmed totals.

The timing problem

The most uncomfortable detail is sequencing. Reporting indicates a substantial portion of the theft occurred on 30 July — the same day as the patch, and hours before the advisory reached most users. Whoever was exploiting the flaw understood it before the disclosure landed.

That is the perennial tension in coordinated disclosure: a patch is itself a signal, and for a defect affecting keys that already exist, patching does not retroactively protect anyone. New firmware fixes seed generation going forward. It cannot add entropy to a seed created in 2022.

What Conisec will not tell you to do

Coinkite has advised affected users to migrate funds to newly generated seeds unless their entropy was independently supplemented or a strong BIP-39 passphrase was in use. That is Coinkite’s instruction to its own customers, and we report it as theirs. Conisec does not tell readers to move funds — we link the vendor’s advisory and let the issuer’s own instructions stand. See our editorial guidelines for why.

We will also not link any third-party “checker”, “migration” or “recovery” tool. After a disclosure of this size those appear within hours, rank well, and are the second attack. Reach Coinkite through a channel you already had.

Why this one is different

Most hardware wallet incidents in our tracker involve the user approving something they did not understand — the Ledger Connect Kit compromise is the clearest case. The device behaved correctly; the human was deceived.

Here the device did not behave correctly. The single thing a hardware wallet exists to guarantee — that your key was generated unguessably, inside the device, out of reach of software — was not true, and nobody knew for five years. It is a supply-chain failure in the most literal sense: a dependency’s fallback path quietly replaced a hardware guarantee.

Sources

  1. CoinDesk, Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep (31 Jul 2026)
  2. The Hacker News, Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes (1 Aug 2026)
  3. Crypto Briefing, Hackers exploit Coldcard firmware flaw, stealing $89 million in Bitcoin (2 Aug 2026)
  4. Blockhead, A five-year-old Coldcard bug let hackers guess bitcoin wallet keys, Coinkite confirms (3 Aug 2026)
  5. Fortune, Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit (3 Aug 2026)

Not advice. Conisec reports for information only. Nothing in this article is financial, legal, tax or security advice. Verify against the primary sources linked above before acting on anything.

Keep exploring