Threat reportVulnerabilityTL-2026-1829

Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addresses

criticalACTIVE

Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin (TL-2026-1829), also tracked as Coldcard RNG Flaw, is a critical-severity software vulnerability, first published 2026-08-03. It has no confirmed attribution, affects Coinkite Coldcard Mk2/Mk3, maps to 17 MITRE ATT&CK techniques (T1036, T1110, T1110.002), and is covered by 9 detection rules and 26 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
26Indicators of compromise

Key facts for TL-2026-1829

Threat ID
TL-2026-1829
Also known as
Coldcard RNG Flaw, Coldcard Entropy Collapse Incident
Severity
CRITICAL
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, cryptocurrency
Target regions
Global
Detection rules
9
Indicators of compromise
26

How Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin works

A March 2021 code defect silently disabled the STM32 hardware RNG on Coinkite Coldcard wallets (Mk2/Mk3/Mk4/Mk5/Q), collapsing seed entropy to roughly 40-72 bits. Attackers exploited the weakness to reconstruct private keys offline and stole 1,367.05 BTC (~$88.6M) from 4,585 addresses across three waves between July 30 and August 1, 2026, before Coinkite shipped emergency firmware on July 31, 2026.

On March 1, 2021, a code change in Coinkite's libngu cryptographic library introduced a defect in the macro guard controlling Coldcard hardware wallets' random number generator (RNG) selection. The check tested only whether the MICROPY_HW_ENABLE_RNG configuration macro was defined, not whether it was enabled -- and because the Coldcard board configuration defines the macro while setting it to zero, the #ifndef guard silently passed and the firmware bound to MicroPython's deterministic Yasmarang software fallback PRNG instead of the intended STM32 true hardware RNG. Firmware 4.0.0, released March 17, 2021, introduced the affected wallet-generation code path, and the defect persisted undetected in production firmware for roughly five years.

The Yasmarang fallback is seeded from fixed or highly-constrained values -- the low 32 bits of the microcontroller's UID XORed with the SysTick counter, plus the RTC time-of-day and subsecond registers -- none of which constitute cryptographic entropy. A March 2022 attempt (firmware v5.0.0, Mk4) to mitigate the flaw via secure-element reseeding introduced a second defect: ngu.random.reseed() only accepts a 32-bit integer, so only 4 bytes of a SHA256d digest computed from two secure-element RNG reads reach the reseed call, overwriting a single Yasmarang state word rather than initializing a proper DRBG. The practical result is an effective entropy ceiling of roughly 40 bits on Mk2/Mk3 (pre-reseed) and roughly 72 bits on Mk4/Mk5/Q (post-reseed) -- far short of the 128 bits a standard 12-word BIP-39 mnemonic is expected to provide.

Because a wallet's public key, address, or xpub functions as a free candidate-validation oracle against the public Bitcoin blockchain, an attacker can enumerate the constrained fallback-PRNG state space offline, derive secp256k1 keys and addresses for each candidate, and check them against known on-chain addresses -- recovering the private key the moment a match is found, entirely without ever touching the victim's device. Galaxy Research identified an automated, large-scale sweep of 1,196 addresses (1,082.65 BTC, ~$70.2M) in a 41-minute window on July 30, 2026, roughly 30 hours before Coinkite's public disclosure -- indicating the flaw, or an equivalent one, had already been independently discovered and weaponized. Chainalysis found the attacker prioritized high-value wallets, extracting roughly $30M in the first ten minutes alone. Two further waves on August 1, 2026 brought the cumulative total to 1,367.05 BTC (~$88.6M) across 4,585 addresses; the third wave (207.7294 BTC) used materially different transaction construction (P2WSH batch outputs to individually specified destinations, default-derivation-path-only targeting) from waves 1-2, leaving Galaxy Research unable to confirm whether one attacker evolved their tooling or a second actor independently exploited the same weakness. Reported attacker-controlled addresses (~600) remain unspent as of the latest reporting.

Coinkite shipped emergency firmware (4.2.0 for Mk2/Mk3; 5.6.0/6.6.0X for Mk4/Mk5; 1.5.0Q/6.6.0QX for Q) on July 31, 2026, but the fix only prevents new seeds from being generated with weak entropy -- it cannot repair a seed already generated on vulnerable firmware. Any funds secured by a Coldcard-generated seed from firmware predating the patch, and not supplemented with at least 50 independent dice rolls or a strong BIP-39 passphrase at generation time, must be migrated to a freshly generated seed. Beyond wallet seeds, the same weak-RNG code path affects paper-wallet key generation, cloning/USB-encryption ECDH keys, Key Teleport ephemeral keys, Web2FA TOTP secrets and per-request nonces, Secure Notes dense-password generation (which calls generate_seed() twice against the same small-state generator), and seed XOR masks used in Coldcard's multi-part seed-split feature; functions calling the hardware RNG directly (ckcc.rng_bytes) were never affected. Coldcard Mk1 firmware (through v3.0.6) predates the defective code path and is unaffected, as are Coinkite's TAPSIGNER, SATSCARD, and OPENDIME products, which use a different codebase. Coldcard co-founder NVK and other industry commentators have suggested AI-assisted code review or exploit development may have accelerated either the defect's discovery or its weaponization, though this remains unconfirmed. The incident closely parallels Coinspect's July 2026 'Ill Bloom' disclosure of a separate PRNG weakness in several mobile software wallets, which had already drained over $5M from thousands of addresses across six blockchains -- underscoring a broader pattern of insufficiently audited randomness in cryptocurrency key-generation code.

MITRE ATT&CK techniques used in TL-2026-1829

Defense Evasion

T1036 Masquerading

Credential Access

T1110 Brute Force; T1110.002 Password Cracking; T1212 Exploitation for Credential Access; T1552.004 Private Keys

Collection

T1119 Automated Collection

Resource Development

T1587.001 Malware; T1587.004 Exploits; T1588.002 Tool; T1588.005 Exploits; T1588.006 Vulnerabilities

Reconnaissance

T1592.002 Software; T1592.004 Client Configurations; T1596.005 Scan Databases

defense-impairment

T1600.001 Reduce Key Space; T1600.002 Disable Crypto Hardware

Impact

T1657 Financial Theft

Affected products and versions in Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin

  • Coinkite — Coldcard Mk2/Mk3
    Vulnerable versions: 4.0.0; 4.0.1-4.1.9
    Fixed in: 4.2.0
  • Coinkite — Coldcard Mk4/Mk5
    Vulnerable versions: < 5.6.0 standard; < 6.6.0X Edge
    Fixed in: 5.6.0; 6.6.0X
  • Coinkite — Coldcard Q
    Vulnerable versions: < 1.5.0Q standard; < 6.6.0QX Edge
    Fixed in: 1.5.0Q; 6.6.0QX

Remediation for Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin

Patches

  • Coinkite Coldcard firmware 4.2.0 (Mk2/Mk3)
  • Coinkite Coldcard firmware 5.6.0 standard / 6.6.0X Edge (Mk4/Mk5)
  • Coinkite Coldcard firmware 1.5.0Q standard / 6.6.0QX Edge (Q)

Immediate actions

  • Immediately migrate all funds from any Coldcard-generated seed created before the patched firmware (Mk2/Mk3 < 4.2.0, Mk4/Mk5 < 5.6.0 standard / < 6.6.0X Edge, Q < 1.5.0Q standard / < 6.6.0QX Edge) to a newly generated seed on updated firmware
  • Update Coldcard firmware to 4.2.0 (Mk3), 5.6.0 or 6.6.0X (Mk4/Mk5), or 1.5.0Q/6.6.0QX (Q) before generating any new seed
  • Do not reuse or re-import a seed that was originally generated on vulnerable firmware, even after updating -- the update does not repair already-generated seeds
  • Verify the newly generated seed/address with a small test transaction before transferring the remaining balance

Workarounds

  • Seeds generated with 50 or more independent dice rolls supplied during creation are not considered at risk from this issue alone
  • A strong independent BIP-39 passphrase mitigates exposure even on an already-generated vulnerable seed, though migration to a new seed is still recommended

Longer-term hardening

  • Supplement all future seed generation with at least 50 independent fair dice rolls or an equivalent externally-verifiable entropy source rather than trusting device RNG alone
  • Apply a strong, independently memorized BIP-39 passphrase as a second factor of entropy on top of the device-generated seed
  • Monitor addresses derived from pre-patch firmware for anomalous outbound sweeps (fixed low fee-rate-per-input, no-change outputs)
  • Adopt multisignature wallet setups spanning independently-sourced-entropy devices/vendors to reduce single-point-of-RNG-failure risk

Weaknesses (CWE) in Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin

CWE-330, CWE-338, CWE-337

Timeline of Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin

  • A macro-check defect is introduced in Coinkite's libngu library: the guard tests whether MICROPY_HW_ENABLE_RNG is defined rather than whether it is enabled, causing the build to silently bind to the deterministic Yasmarang software PRNG instead of the STM32 hardware RNG.
  • Coldcard firmware v4.0.0 ships, introducing the affected wallet seed-generation code path built on the flawed RNG guard.
  • Mk4 firmware v5.0.0 adds a secure-element reseed intended to strengthen the fallback PRNG, but only 4 bytes of the SHA256d digest reach ngu.random.reseed(), capping the effective entropy ceiling at roughly 2^32 (~72 bits observed).
  • Coinspect publicly discloses the unrelated 'Ill Bloom' PRNG vulnerability affecting several mobile Bitcoin/multi-chain software wallets, which had already drained over $5M from 2,114+ addresses -- establishing a recent precedent for weak-entropy wallet-seed flaws.
  • Wave 1: attackers sweep 1,196 Coldcard-derived Bitcoin addresses in a 41-minute automated operation, stealing 1,082.65 BTC (~$70.2M), roughly 30 hours before Coinkite's public disclosure -- Chainalysis found ~$30M taken in the first 10 minutes as high-value wallets were prioritized.
  • Coinkite publicly discloses the Coldcard RNG flaw and ships emergency firmware 4.2.0 (Mk2/Mk3), 5.6.0/6.6.0X (Mk4/Mk5), and 1.5.0Q/6.6.0QX (Q).
  • A third wave (207.7294 BTC) is identified using materially different transaction construction -- P2WSH batch outputs to individually specified destinations, targeting only default derivation paths -- raising the possibility of either evolved attacker tooling or a second independent actor.
  • Galaxy Research identifies a second wave of sweeps from Coldcard-derived addresses following the same automated-tooling signature as Wave 1.
  • Galaxy Research confirms a cumulative total of 1,367.05 BTC (~$88.6M) stolen from 4,585 addresses across the three waves and reports roughly 600 suspected attacker-controlled addresses to federal investigators and compliance firms; the addresses remain unspent.
  • Cyber Security News publishes coverage summarizing the incident and Coinkite's remediation guidance, triggering this hunt.

Sources cited for Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin

Detection coverage for TL-2026-1829

As of 2026-08-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1829 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
26 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats