Coldcard RNG Bug Spanning Nearly Five Years: Suspected Attack Waves, Seed Weakening, and Renewed Scrutiny of Self-Custody

AI Market Summary
A five-year Coldcard firmware RNG flaw weakened seed generation across multiple models, with Galaxy Research estimating four suspected attack waves tied to 5,294 addresses and 1,815.75 BTC based on on-chain patterns. The issue is a wallet key-generation failure, not a break in Bitcoin cryptography, but it undermines self-custody confidence and may drive short-term security-driven fund movements as users rotate seeds and migrate holdings.
Impact level
● Medium
Affected assets
BTC/USDT+0.93%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
A flaw in Coldcard's random number generation, introduced during a 2021 code migration, weakened wallet seeds produced by certain Coldcard models and firmware versions for almost five years. Instead of drawing entropy from the intended hardware source, the affected firmware relied on a predictable software pseudorandom number generator. As a result, the effective search space is estimated to have fallen to about 40 bits on Mk2 and Mk3 devices, and to roughly 72 bits on later models. The weakness is not remediated by a firmware update after the fact, nor by importing the affected mnemonic into another wallet. Users must create a brand-new seed using patched firmware or another trusted setup and then move funds to the new wallet. Galaxy Research reported four suspected attack waves tied to an estimated 5,294 addresses and 1,815.75 BTC. The firm said the numbers are derived from on-chain transaction patterns and do not represent individually verified victims or confirmed final losses. The issue is described as a key-generation failure in specific Coldcard firmware, not a break in Bitcoin's underlying cryptography.