Coldcard Bug Leads to $130 Million Bitcoin Theft

We may earn commissions from affiliate links or include sponsored content, clearly labeled as such. These partnerships do not influence our editorial independence or the accuracy of our reporting. By continuing to use the site you agree to our terms and conditions and privacy policy.

Article Details

A critical Coldcard PRNG bug has compromised Bitcoin wallets, leading to $130 million in losses. Users must move funds to new seed phrases immediately.

Estimated losses have reached approximately $130 million, and users who generated affected seed phrases between 2021 and July 2026 must create a new wallet and move their funds, as the software update itself cannot fix keys that are already compromised.

Bug Reduces Protection to Approximately 40 Bits

The issue dates back to March 2021. On specific Coldcard models, the device could silently switch from the intended hardware random number generator to a weaker software-based PRNG.

Analysis suggests this flaw could reduce effective entropy from the standard 128 bits to roughly 40 bits on older Mk2 and Mk3 models, and to about 72 bits on newer devices.

This difference is critical. With a sufficiently small range of possible values, an attacker can generate a vast number of potential keys and compare them against addresses on the public BTC blockchain. Physical access to the wallet is not required for this exploit.

Thefts Reach Approximately $130 Million

The systematic draining of wallets began on July 30, with blockchain analysts linking thousands of addresses to this vulnerability. Estimates from Galaxy Research place total losses at around $130 million, though the exact figure varies depending on the methodology and identified addresses.

Reports indicate that an investigation is currently underway while blockchain analysts track the movement of the stolen BTC.

Update Does Not Protect Existing Seed Phrases

Coldcard’s emergency update addresses the issue for new wallet creation but cannot repair a vulnerable seed phrase that has already been generated. Consequently, affected users must generate a new seed and transfer their Bitcoin to the new addresses.

Coldcard is also changing the wallet creation process. Users are now required to manually add additional randomness through:

  • 65 key presses
  • 50 dice rolls
  • 128 coin flips

This additional step reduces the risk that a future problem with the device’s internal generator could once again result in predictable private keys.

Breach Reveals Weakness in the Self-Custody Model

In this specific attack, users did not need to share their seed phrases, nor did attackers need physical access to the Coldcard device. The problem occurred at the moment of key generation, where insufficient randomness made the keys easier to calculate.

The case demonstrates why hardware wallet security involves more than just how a private key is stored. It is equally vital that the key is generated in a way that prevents an attacker from limiting the possible combinations and discovering it through computation.

Leave Reaction
Share Article
Nikolay is a cryptocurrency analyst and market writer with years of experience tracking digital asset trends and emerging blockchain technologies. A long-time crypto enthusiast, he actively trades across major exchanges and specializes in identifying early-stage projects and meme tokens. His analysis combines technical insight with a strategic, long-term investment perspective.
comment-icon Commentaries
Add your comment

Fill in necessary fields and publish