# Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addresses

> A March 2021 code defect silently disabled the STM32 hardware RNG on Coinkite Coldcard wallets (Mk2/Mk3/Mk4/Mk5/Q), collapsing seed entropy to roughly 40-72 bits. Attackers exploited the weakness to reconstruct private keys offline and stole 1,367.05 BTC (~$88.6M) from 4,585 addresses across three waves between July 30 and August 1, 2026, before Coinkite shipped emergency firmware on July 31, 2026.

- **Published:** 2026-08-03T00:00:00Z
- **Last reviewed:** 2026-08-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1829
- **ID:** TL-2026-1829
- **Severity:** CRITICAL
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On March 1, 2021, a code change in Coinkite's libngu cryptographic library introduced a defect in the macro guard controlling Coldcard hardware wallets' random number generator (RNG) selection. The check tested only whether the MICROPY_HW_ENABLE_RNG configuration macro was defined, not whether it was enabled -- and because the Coldcard board configuration defines the macro while setting it to zero, the #ifndef guard silently passed and the firmware bound to MicroPython's deterministic Yasmarang software fallback PRNG instead of the intended STM32 true hardware RNG. Firmware 4.0.0, released March 17, 2021, introduced the affected wallet-generation code path, and the defect persisted undetected in production firmware for roughly five years.

The Yasmarang fallback is seeded from fixed or highly-constrained values -- the low 32 bits of the microcontroller's UID XORed with the SysTick counter, plus the RTC time-of-day and subsecond registers -- none of which constitute cryptographic entropy. A March 2022 attempt (firmware v5.0.0, Mk4) to mitigate the flaw via secure-element reseeding introduced a second defect: ngu.random.reseed() only accepts a 32-bit integer, so only 4 bytes of a SHA256d digest computed from two secure-element RNG reads reach the reseed call, overwriting a single Yasmarang state word rather than initializing a proper DRBG. The practical result is an effective entropy ceiling of roughly 40 bits on Mk2/Mk3 (pre-reseed) and roughly 72 bits on Mk4/Mk5/Q (post-reseed) -- far short of the 128 bits a standard 12-word BIP-39 mnemonic is expected to provide.

Because a wallet's public key, address, or xpub functions as a free candidate-validation oracle against the public Bitcoin blockchain, an attacker can enumerate the constrained fallback-PRNG state space offline, derive secp256k1 keys and addresses for each candidate, and check them against known on-chain addresses -- recovering the private key the moment a match is found, entirely without ever touching the victim's device. Galaxy Research identified an automated, large-scale sweep of 1,196 addresses (1,082.65 BTC, ~$70.2M) in a 41-minute window on July 30, 2026, roughly 30 hours before Coinkite's public disclosure -- indicating the flaw, or an equivalent one, had already been independently discovered and weaponized. Chainalysis found the attacker prioritized high-value wallets, extracting roughly $30M in the first ten minutes alone. Two further waves on August 1, 2026 brought the cumulative total to 1,367.05 BTC (~$88.6M) across 4,585 addresses; the third wave (207.7294 BTC) used materially different transaction construction (P2WSH batch outputs to individually specified destinations, default-derivation-path-only targeting) from waves 1-2, leaving Galaxy Research unable to confirm whether one attacker evolved their tooling or a second actor independently exploited the same weakness. Reported attacker-controlled addresses (~600) remain unspent as of the latest reporting.

Coinkite shipped emergency firmware (4.2.0 for Mk2/Mk3; 5.6.0/6.6.0X for Mk4/Mk5; 1.5.0Q/6.6.0QX for Q) on July 31, 2026, but the fix only prevents new seeds from being generated with weak entropy -- it cannot repair a seed already generated on vulnerable firmware. Any funds secured by a Coldcard-generated seed from firmware predating the patch, and not supplemented with at least 50 independent dice rolls or a strong BIP-39 passphrase at generation time, must be migrated to a freshly generated seed. Beyond wallet seeds, the same weak-RNG code path affects paper-wallet key generation, cloning/USB-encryption ECDH keys, Key Teleport ephemeral keys, Web2FA TOTP secrets and per-request nonces, Secure Notes dense-password generation (which calls generate_seed() twice against the same small-state generator), and seed XOR masks used in Coldcard's multi-part seed-split feature; functions calling the hardware RNG directly (ckcc.rng_bytes) were never affected. Coldcard Mk1 firmware (through v3.0.6) predates the defective code path and is unaffected, as are Coinkite's TAPSIGNER, SATSCARD, and OPENDIME products, which use a different codebase. Coldcard co-founder NVK and other industry commentators have suggested AI-assisted code review or exploit development may have accelerated either the defect's discovery or its weaponization, though this remains unconfirmed. The incident closely parallels Coinspect's July 2026 'Ill Bloom' disclosure of a separate PRNG weakness in several mobile software wallets, which had already drained over $5M from thousands of addresses across six blockchains -- underscoring a broader pattern of insufficiently audited randomness in cryptocurrency key-generation code.

## MITRE ATT&CK

- T1587.004 Exploits
- T1587.001 Malware
- T1588.005 Exploits
- T1588.006 Vulnerabilities
- T1588.002 Tool
- T1596.005 Scan Databases
- T1592.004 Client Configurations
- T1592.002 Software
- T1552.004 Private Keys
- T1110 Brute Force
- T1110.002 Password Cracking
- T1212 Exploitation for Credential Access
- T1119 Automated Collection
- T1036 Masquerading
- T1600.001 Reduce Key Space
- T1600.002 Disable Crypto Hardware
- T1657 Financial Theft

## Sources

- [Coldcard Hardware Wallet RNG Flaw Leads to $88.6 Million Bitcoin Theft](https://cybersecuritynews.com/coldcard-hardware-wallet-rng-flaw-bitcoin-theft/)
- [Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware](https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware)
- [Coldcard Security Advisory](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/)
- [Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes](https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html)
- [COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft](https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/)
- [Galaxy Research identifies 1,367 BTC drained in attacks on Coldcard addresses](https://cryptobriefing.com/galaxy-research-coldcard-btc-attack-1367/)
- [Coldcard Hack Tops $88.6M as Galaxy Finds Third Attack Wave](https://www.cryptotimes.io/2026/08/02/coldcard-hack-tops-88-6m-as-galaxy-finds-third-attack-wave/)
- [Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach](https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack)
- [Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets](https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html)
- [Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets](https://decrypt.co/374817/coldcard-bitcoin-exploit-88-million-attackers-draining-wallets)
- [Coinkite Issues Mk3 Security Warning After 594 BTC Swept in Minutes](https://www.tftc.io/coldcard-mk3-rng-security-warning-594-btc-swept)
- [Ill Bloom: Crypto Wallet Vulnerability](https://illbloom.org/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1829
