Threat reportVulnerabilityTL-2026-1829
Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addresses
Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin (TL-2026-1829), also tracked as Coldcard RNG Flaw, is a critical-severity software vulnerability, first published 2026-08-03. It has no confirmed attribution, affects Coinkite Coldcard Mk2/Mk3, maps to 17 MITRE ATT&CK techniques (T1036, T1110, T1110.002), and is covered by 9 detection rules and 26 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-1829
- Threat ID
- TL-2026-1829
- Also known as
- Coldcard RNG Flaw, Coldcard Entropy Collapse Incident
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- finance, cryptocurrency
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 26
How Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin works
A March 2021 code defect silently disabled the STM32 hardware RNG on Coinkite Coldcard wallets (Mk2/Mk3/Mk4/Mk5/Q), collapsing seed entropy to roughly 40-72 bits. Attackers exploited the weakness to reconstruct private keys offline and stole 1,367.05 BTC (~$88.6M) from 4,585 addresses across three waves between July 30 and August 1, 2026, before Coinkite shipped emergency firmware on July 31, 2026.
On March 1, 2021, a code change in Coinkite's libngu cryptographic library introduced a defect in the macro guard controlling Coldcard hardware wallets' random number generator (RNG) selection. The check tested only whether the MICROPY_HW_ENABLE_RNG configuration macro was defined, not whether it was enabled -- and because the Coldcard board configuration defines the macro while setting it to zero, the #ifndef guard silently passed and the firmware bound to MicroPython's deterministic Yasmarang software fallback PRNG instead of the intended STM32 true hardware RNG. Firmware 4.0.0, released March 17, 2021, introduced the affected wallet-generation code path, and the defect persisted undetected in production firmware for roughly five years.
The Yasmarang fallback is seeded from fixed or highly-constrained values -- the low 32 bits of the microcontroller's UID XORed with the SysTick counter, plus the RTC time-of-day and subsecond registers -- none of which constitute cryptographic entropy. A March 2022 attempt (firmware v5.0.0, Mk4) to mitigate the flaw via secure-element reseeding introduced a second defect: ngu.random.reseed() only accepts a 32-bit integer, so only 4 bytes of a SHA256d digest computed from two secure-element RNG reads reach the reseed call, overwriting a single Yasmarang state word rather than initializing a proper DRBG. The practical result is an effective entropy ceiling of roughly 40 bits on Mk2/Mk3 (pre-reseed) and roughly 72 bits on Mk4/Mk5/Q (post-reseed) -- far short of the 128 bits a standard 12-word BIP-39 mnemonic is expected to provide.
Because a wallet's public key, address, or xpub functions as a free candidate-validation oracle against the public Bitcoin blockchain, an attacker can enumerate the constrained fallback-PRNG state space offline, derive secp256k1 keys and addresses for each candidate, and check them against known on-chain addresses -- recovering the private key the moment a match is found, entirely without ever touching the victim's device. Galaxy Research identified an automated, large-scale sweep of 1,196 addresses (1,082.65 BTC, ~$70.2M) in a 41-minute window on July 30, 2026, roughly 30 hours before Coinkite's public disclosure -- indicating the flaw, or an equivalent one, had already been independently discovered and weaponized. Chainalysis found the attacker prioritized high-value wallets, extracting roughly $30M in the first ten minutes alone. Two further waves on August 1, 2026 brought the cumulative total to 1,367.05 BTC (~$88.6M) across 4,585 addresses; the third wave (207.7294 BTC) used materially different transaction construction (P2WSH batch outputs to individually specified destinations, default-derivation-path-only targeting) from waves 1-2, leaving Galaxy Research unable to confirm whether one attacker evolved their tooling or a second actor independently exploited the same weakness. Reported attacker-controlled addresses (~600) remain unspent as of the latest reporting.
Coinkite shipped emergency firmware (4.2.0 for Mk2/Mk3; 5.6.0/6.6.0X for Mk4/Mk5; 1.5.0Q/6.6.0QX for Q) on July 31, 2026, but the fix only prevents new seeds from being generated with weak entropy -- it cannot repair a seed already generated on vulnerable firmware. Any funds secured by a Coldcard-generated seed from firmware predating the patch, and not supplemented with at least 50 independent dice rolls or a strong BIP-39 passphrase at generation time, must be migrated to a freshly generated seed. Beyond wallet seeds, the same weak-RNG code path affects paper-wallet key generation, cloning/USB-encryption ECDH keys, Key Teleport ephemeral keys, Web2FA TOTP secrets and per-request nonces, Secure Notes dense-password generation (which calls generate_seed() twice against the same small-state generator), and seed XOR masks used in Coldcard's multi-part seed-split feature; functions calling the hardware RNG directly (ckcc.rng_bytes) were never affected. Coldcard Mk1 firmware (through v3.0.6) predates the defective code path and is unaffected, as are Coinkite's TAPSIGNER, SATSCARD, and OPENDIME products, which use a different codebase. Coldcard co-founder NVK and other industry commentators have suggested AI-assisted code review or exploit development may have accelerated either the defect's discovery or its weaponization, though this remains unconfirmed. The incident closely parallels Coinspect's July 2026 'Ill Bloom' disclosure of a separate PRNG weakness in several mobile software wallets, which had already drained over $5M from thousands of addresses across six blockchains -- underscoring a broader pattern of insufficiently audited randomness in cryptocurrency key-generation code.
MITRE ATT&CK techniques used in TL-2026-1829
Defense Evasion
Credential Access
T1110 Brute Force; T1110.002 Password Cracking; T1212 Exploitation for Credential Access; T1552.004 Private Keys
Collection
Resource Development
T1587.001 Malware; T1587.004 Exploits; T1588.002 Tool; T1588.005 Exploits; T1588.006 Vulnerabilities
Reconnaissance
T1592.002 Software; T1592.004 Client Configurations; T1596.005 Scan Databases
defense-impairment
T1600.001 Reduce Key Space; T1600.002 Disable Crypto Hardware
Impact
Affected products and versions in Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin
- Coinkite — Coldcard Mk2/Mk3
Vulnerable versions: 4.0.0; 4.0.1-4.1.9
Fixed in: 4.2.0 - Coinkite — Coldcard Mk4/Mk5
Vulnerable versions: < 5.6.0 standard; < 6.6.0X Edge
Fixed in: 5.6.0; 6.6.0X - Coinkite — Coldcard Q
Vulnerable versions: < 1.5.0Q standard; < 6.6.0QX Edge
Fixed in: 1.5.0Q; 6.6.0QX
Remediation for Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin
Patches
- Coinkite Coldcard firmware 4.2.0 (Mk2/Mk3)
- Coinkite Coldcard firmware 5.6.0 standard / 6.6.0X Edge (Mk4/Mk5)
- Coinkite Coldcard firmware 1.5.0Q standard / 6.6.0QX Edge (Q)
Immediate actions
- Immediately migrate all funds from any Coldcard-generated seed created before the patched firmware (Mk2/Mk3 < 4.2.0, Mk4/Mk5 < 5.6.0 standard / < 6.6.0X Edge, Q < 1.5.0Q standard / < 6.6.0QX Edge) to a newly generated seed on updated firmware
- Update Coldcard firmware to 4.2.0 (Mk3), 5.6.0 or 6.6.0X (Mk4/Mk5), or 1.5.0Q/6.6.0QX (Q) before generating any new seed
- Do not reuse or re-import a seed that was originally generated on vulnerable firmware, even after updating -- the update does not repair already-generated seeds
- Verify the newly generated seed/address with a small test transaction before transferring the remaining balance
Workarounds
- Seeds generated with 50 or more independent dice rolls supplied during creation are not considered at risk from this issue alone
- A strong independent BIP-39 passphrase mitigates exposure even on an already-generated vulnerable seed, though migration to a new seed is still recommended
Longer-term hardening
- Supplement all future seed generation with at least 50 independent fair dice rolls or an equivalent externally-verifiable entropy source rather than trusting device RNG alone
- Apply a strong, independently memorized BIP-39 passphrase as a second factor of entropy on top of the device-generated seed
- Monitor addresses derived from pre-patch firmware for anomalous outbound sweeps (fixed low fee-rate-per-input, no-change outputs)
- Adopt multisignature wallet setups spanning independently-sourced-entropy devices/vendors to reduce single-point-of-RNG-failure risk
Weaknesses (CWE) in Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin
Timeline of Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin
- A macro-check defect is introduced in Coinkite's libngu library: the guard tests whether MICROPY_HW_ENABLE_RNG is defined rather than whether it is enabled, causing the build to silently bind to the deterministic Yasmarang software PRNG instead of the STM32 hardware RNG.
- Coldcard firmware v4.0.0 ships, introducing the affected wallet seed-generation code path built on the flawed RNG guard.
- Mk4 firmware v5.0.0 adds a secure-element reseed intended to strengthen the fallback PRNG, but only 4 bytes of the SHA256d digest reach ngu.random.reseed(), capping the effective entropy ceiling at roughly 2^32 (~72 bits observed).
- Coinspect publicly discloses the unrelated 'Ill Bloom' PRNG vulnerability affecting several mobile Bitcoin/multi-chain software wallets, which had already drained over $5M from 2,114+ addresses -- establishing a recent precedent for weak-entropy wallet-seed flaws.
- Wave 1: attackers sweep 1,196 Coldcard-derived Bitcoin addresses in a 41-minute automated operation, stealing 1,082.65 BTC (~$70.2M), roughly 30 hours before Coinkite's public disclosure -- Chainalysis found ~$30M taken in the first 10 minutes as high-value wallets were prioritized.
- Coinkite publicly discloses the Coldcard RNG flaw and ships emergency firmware 4.2.0 (Mk2/Mk3), 5.6.0/6.6.0X (Mk4/Mk5), and 1.5.0Q/6.6.0QX (Q).
- A third wave (207.7294 BTC) is identified using materially different transaction construction -- P2WSH batch outputs to individually specified destinations, targeting only default derivation paths -- raising the possibility of either evolved attacker tooling or a second independent actor.
- Galaxy Research identifies a second wave of sweeps from Coldcard-derived addresses following the same automated-tooling signature as Wave 1.
- Galaxy Research confirms a cumulative total of 1,367.05 BTC (~$88.6M) stolen from 4,585 addresses across the three waves and reports roughly 600 suspected attacker-controlled addresses to federal investigators and compliance firms; the addresses remain unspent.
- Cyber Security News publishes coverage summarizing the incident and Coinkite's remediation guidance, triggering this hunt.
Sources cited for Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin
- Coldcard Hardware Wallet RNG Flaw Leads to $88.6 Million Bitcoin Theft
- Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware
- Coldcard Security Advisory
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
- COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
- Galaxy Research identifies 1,367 BTC drained in attacks on Coldcard addresses
- Coldcard Hack Tops $88.6M as Galaxy Finds Third Attack Wave
- Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach
- Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets
- Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets
- Coinkite Issues Mk3 Security Warning After 594 BTC Swept in Minutes
- Ill Bloom: Crypto Wallet Vulnerability
Detection coverage for TL-2026-1829
As of 2026-08-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1829 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.