Threat reportVulnerabilityTL-2026-1835
Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned) Linked to $88.6M Multi-Wave Bitcoin Theft
Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned) (TL-2026-1835), also tracked as Coldcard RNG Incident, is a critical-severity software vulnerability, first published 2026-08-03. It has no confirmed attribution, affects Coinkite COLDCARD Mk2/Mk3, maps to 16 MITRE ATT&CK techniques (T1027, T1059, T1059.006), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-1835
- Threat ID
- TL-2026-1835
- Also known as
- Coldcard RNG Incident, Coldcard Entropy Bug, COLDCARD Predictable RNG Fallback
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, financial services, individual consumers, self-custody bitcoin holders
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 24
How Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned) works
A March 2021 firmware regression in Coinkite's COLDCARD Bitcoin-only hardware wallet caused wallet-seed generation to silently fall back from the on-chip STM32 hardware RNG to MicroPython's deterministic Yasmarang PRNG, cutting effective seed entropy from 128 bits to as little as ~32-72 bits. Beginning July 30, 2026, an unattributed actor exploited this across three waves, draining roughly 1,367 BTC (~$88.6M) from thousands of COLDCARD-generated addresses; Coinkite has shipped patched firmware for all affected models but confirms existing compromised seeds cannot be repaired in place and must be replaced.
COLDCARD hardware wallets (Coinkite Inc.) ship a dedicated hardware true-random-number generator, but a firmware regression merged in early 2021 caused builds to silently bind to MicroPython's software PRNG fallback instead. The root cause is a three-layer configuration defect: the production board config (`stm32/COLDCARD_MK4/mpconfigboard.h`, lines 77-78) defines `MICROPY_HW_ENABLE_RNG` as `0` because Coinkite supplies its own hardware-RNG wrapper; the libngu cryptographic library's availability guard in `switck/libngu/ngu/random.c` (lines 22-30) uses `#ifndef MICROPY_HW_ENABLE_RNG`, which verifies only that the macro is *defined*, not that it is *enabled* (non-zero) — so the guard passes even with the macro set to zero, and the build links against MicroPython's `rng_get()` fallback in `Coldcard/micropython/ports/stm32/rng.c` (lines 64-98) instead of the real hardware RNG. That fallback (an implementation of the Yasmarang PRNG) is initialized only from `pad = UID_low32 ^ SysTick->VAL`, `n = RTC->TR`, and `d = RTC->SSR` — the device's fixed 96-bit UID (only the low 32 bits used), a free-running down-counter (at most ~80,000 distinct values on Mk2/Mk3, ~120,000 on current devices), and RTC time registers correlated with (and potentially static relative to) boot time — none of which are cryptographically secure entropy sources, and the resulting stream is fully deterministic for a known device and timing state.
The regression first shipped in COLDCARD Mk2/Mk3 firmware v4.0.0 (commit merged 2021-03-17, tracing to a libngu macro-check change from 2021-01-28 and a seed-generation migration to libngu via commit `b18723dd` on 2021-03-01, which replaced `rng_bytes(seed)` with `seed = random.bytes(32)` routed through `ngu.random.bytes`), leaving firmware versions 4.0.1 through 4.1.9 affected until the fix in 4.2.0. Independent root-cause analysis (Block Inc. Engineering) computed the resulting search space precisely: for Mk2/Mk3 v4 firmware with a known UID and call history the keyspace collapses to 2^0 (fully deterministic); with only timers unknown it ranges from ~2^16.29 (SysTick alone) up to ~2^40.7 (all timers). Later COLDCARD Mk4, Q, and Mk5 models added a secure-element-based reseed step (`shared/mk4.py`, commit `01cb43f7`) intended to mitigate the flaw — it draws 32 bytes from one secure element via `callgate.read_rng(1)` and 8 bytes from a second via `callgate.read_rng(2)`, SHA256d-hashes them, then calls `ngu.random.reseed(n)` with only the first 4 bytes of the digest unpacked as a 32-bit integer, discarding the rest and never resetting the other Yasmarang state words. This caps the mitigated devices' effective security at ≤2^32 possible outputs (~2^31 average enumeration to a successful guess) rather than restoring 128-bit security; Coinkite's own advisory (which separately cites commit `621e808712464688584fdffad9eba132cc7c27cd` in `shared/seed.py`, lines 276-332, describing how COLDCARD hashes the device-generated seed together with any user-supplied dice rolls) states this yields ~72 bits of entropy for Mk4/Q/Mk5 versus the expected 128, and that seeds lacking 50+ independent physical dice rolls (contributing ≥128 bits) remain under-entropied regardless of firmware version.
Exploitation began July 30, 2026 — roughly a day before Coinkite's public disclosure — when an attacker drained 1,082.65-1,083 BTC (~$70.2M) from 1,196 addresses in a 41-minute window (Wave 1), using single-input sweep transactions with no change output and a uniform, well-above-market transaction fee (a hardcoded ~30 sat/vByte, a 30-75x overpay versus the ~0.4-1.0 sat/vByte prevailing median), consistent with automated/scripted tooling that offline-reconstructs candidate seeds from the constrained keyspace, derives corresponding Bitcoin addresses, and checks them against the public blockchain. Chainalysis's timing analysis of Wave 1 found the attacker extracted roughly $30M within the first ten minutes alone and $1.8M from a single victim, indicating the wallets had likely been identified and studied by value in advance rather than drained in random order. Coinkite shipped emergency patched firmware within roughly two days of the first wave and destroyed its remaining device stock awaiting shipment that still carried the affected firmware. Galaxy Research subsequently identified two further waves on August 1: a wave targeting materially smaller balances (~208 BTC across ~1,912 addresses, averaging ~0.1 BTC/victim, running Friday midday through Saturday morning UTC) that batched an average of six victims per sweep transaction (versus Wave 1's one-at-a-time sweeps), scanned only the default derivation path per seed (rather than testing multiple branches), shifted output style from plain single-key outputs to Pay-to-Witness-Script-Hash (P2WSH, which supports multisig/timelock spending conditions), and — unlike Waves 1-2, which consolidated stolen funds into a handful of shared collector addresses — routed each victim's coins to its own unique destination address, likely to reduce on-chain clustering and complicate downstream tracing. Cumulative losses across all three waves reached approximately 1,367 BTC (~$88.6M) from between 4,385 and 4,585 addresses depending on source and reporting cutoff. Galaxy Research reported roughly 600 suspected attacker-controlled addresses to federal investigators, compliance firms, and cross-industry cyber investigators, crediting victims who voluntarily shared addresses/txids for helping establish the on-chain attacker pattern; it assesses Waves 1-2 likely share an operator based on transaction-pattern similarity (identical fee, no-change, shared-collector signature) but cannot confirm the same is true of Wave 3, while noting the same sweep signature 'looks the same as if a coin owner chose to move coins,' complicating attribution.
Security researchers have drawn a direct parallel to Ledger Donjon's 2022 discovery that the Trust Wallet browser extension generated wallets fully recoverable from their public address alone, requiring roughly five months to patch before public disclosure — both incidents illustrate that a biased or deterministic RNG produces output that is statistically indistinguishable from true randomness and passes casual inspection ('a bad RNG is silent'), so discovery depends on independent or adversarial audit rather than routine testing. Commentary accompanying disclosure also observed that, industry-wide, LLM-assisted vulnerability research is compressing the general window between a patch's disclosure and its weaponization, a contextual risk factor for firmware/cryptographic defects of this class even though the confirmed exploitation of this specific flaw began before Coinkite's public disclosure.
No CVE has been assigned to this issue by any source reviewed. Coinkite's remediation guidance: update to patched firmware (4.2.0+ for Mk2/Mk3; 5.6.0+ standard / 6.6.0X+ Edge for Mk4/Mk5; 1.5.0Q+ standard / 6.6.0QX+ Edge for Q), then generate and migrate to an entirely new seed — firmware updates do not retroactively repair a seed already generated on vulnerable firmware. Seeds supplemented with 50+ fair, independent, private dice rolls, or protected by a strong unique BIP-39 passphrase, are treated as lower-risk, though full seed replacement remains the recommended path. Coinkite's TAPSIGNER, OPENDIME, and SATSCARD products use separate codebases and are not affected. The vulnerable `ngu.random` code path also fed paper-wallet private keys, ephemeral ECDH keys (device cloning, USB encryption, Key Teleport, Web2FA), seed XOR masks, and Secure Notes passwords, all of which inherit the same weakness; functions that instead call `ckcc.rng_bytes` reach the hardware RNG directly and are unaffected.
MITRE ATT&CK techniques used in TL-2026-1835
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal
Execution
T1059 Command and Scripting Interpreter; T1059.006 Python
Credential Access
T1110.002 Password Cracking; T1552.004 Private Keys
Collection
Resource Development
T1583.006 Web Services; T1587.004 Exploits; T1588.002 Tool; T1588.006 Vulnerabilities
Reconnaissance
T1592.004 Client Configurations; T1593.003 Code Repositories; T1596.005 Scan Databases
defense-impairment
Impact
Affected products and versions in Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned)
- Coinkite — COLDCARD Mk2/Mk3
Vulnerable versions: 4.0.1 - 4.1.9
Fixed in: 4.2.0 and later - Coinkite — COLDCARD Mk4/Mk5 (standard)
Vulnerable versions: earlier than 5.6.0
Fixed in: 5.6.0 and later - Coinkite — COLDCARD Q (standard)
Vulnerable versions: earlier than 1.5.0Q
Fixed in: 1.5.0Q and later - Coinkite — COLDCARD Mk4/Mk5 (Edge)
Vulnerable versions: earlier than 6.6.0X
Fixed in: 6.6.0X and later - Coinkite — COLDCARD Q (Edge)
Vulnerable versions: earlier than 6.6.0QX
Fixed in: 6.6.0QX and later
Remediation for Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned)
Patches
- COLDCARD Mk2/Mk3 firmware 4.2.0
- COLDCARD Mk4/Mk5 standard firmware 5.6.0
- COLDCARD Q standard firmware 1.5.0Q
- COLDCARD Mk4/Mk5 Edge firmware 6.6.0X
- COLDCARD Q Edge firmware 6.6.0QX
Immediate actions
- Immediately migrate any BTC held on COLDCARD Mk2/Mk3 firmware 4.0.1-4.1.9 (or any unpatched Mk4/Mk5/Q firmware) to a newly generated seed on patched firmware
- Update all COLDCARD devices to fixed firmware first: 4.2.0+ (Mk2/Mk3), 5.6.0+ (Mk4/Mk5 standard), 1.5.0Q+ (Q standard), 6.6.0X+ (Mk4/Mk5 Edge), 6.6.0QX+ (Q Edge)
- Do not generate a replacement seed on unpatched firmware — update firmware FIRST, then generate the new seed
- Verify the new seed's backup and receive address on-device before moving funds, then execute a small test transaction before migrating the remaining balance
- Retain the original (compromised) seed backup only until the fund migration is fully confirmed complete
Workarounds
- Seeds created using 50+ fair, independent, private dice rolls to supplement device entropy are not considered at-risk
- A strong, unique BIP-39 passphrase mitigates exposure, though Coinkite still recommends full seed replacement
Longer-term hardening
- Treat any seed generated on affected firmware as permanently compromised regardless of current firmware-update status — updates do not retroactively repair already-generated seeds
- For high-value or multisig cold storage, prefer devices with certified hardware TRNGs (e.g. AIS-31 / Common Criteria EAL5+ / CSPN-certified) rather than software-fallback RNG designs
- Supplement device-generated entropy with an independent source (50+ fair, independent, private dice rolls) instead of relying solely on on-device RNG
- Adopt a strong, unique BIP-39 passphrase as defense-in-depth so a compromised base seed alone cannot derive spendable funds
- Hardware-wallet vendors should add build-time CI verification asserting hardware-RNG enable macros are truly non-zero, not merely defined, to prevent regression of this defect class
Weaknesses (CWE) in Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned)
Timeline of Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned)
- The flawed libngu RNG-availability guard (`#ifndef MICROPY_HW_ENABLE_RNG`, checking macro existence rather than value) is merged.
- COLDCARD wallet seed generation is migrated to use the libngu library's `ngu.random` path (commit b18723dd), replacing `rng_bytes(seed)` with `seed = random.bytes(32)`.
- The RNG regression ships in production COLDCARD Mk2/Mk3 firmware v4.0.0, silently binding seed generation to MicroPython's deterministic Yasmarang fallback instead of the STM32 hardware RNG.
- COLDCARD Mk4 firmware v5.0.0 adds a secure-element-based 32-bit reseed step (commit 01cb43f7 in shared/mk4.py) intended to mitigate the flaw, though it caps effective entropy at roughly 2^32 (~2^31 average enumeration) rather than restoring 128-bit security.
- Wave 1: an attacker drains approximately 1,082.65-1,083 BTC (~$70.2M) from 1,196 COLDCARD-generated addresses in a 41-minute window using single-input, no-change-output sweep transactions at a uniform above-market fee; Chainalysis later assesses the attacker extracted ~$30M in the first ten minutes and $1.8M from a single victim, indicating pre-attack targeting of high-value wallets.
- Coinkite ships emergency patched firmware (4.2.0 and equivalent fixed versions for Mk4/Mk5/Q), publishes a public security advisory confirming the RNG flaw and urging affected users to migrate to new seeds, and destroys its remaining device stock awaiting shipment that still carried the affected firmware.
- Galaxy Research identifies a second and third attack wave (the latter running Friday midday through Saturday morning UTC); cumulative theft rises to approximately 1,367 BTC (~$88.6M). Wave 3 shifts tactics to batched multi-victim sweeps (~6 inputs), scans only the default derivation path, moves to Pay-to-Witness-Script-Hash outputs, and routes funds to per-victim unique destinations instead of the shared collector addresses used in Waves 1-2, while targeting smaller-balance addresses.
- Chainalysis's transaction-timing analysis of Wave 1, and Ledger's public comparison of the incident to Ledger Donjon's 2022 discovery of a comparable RNG-derivable-wallet flaw in the Trust Wallet browser extension, are reported in security press coverage.
- Galaxy Research reports roughly 600 suspected attacker-controlled addresses to federal investigators and compliance firms; Block Inc. Engineering publishes an independent technical root-cause report detailing the MICROPY_HW_ENABLE_RNG guard defect, computing precise keyspace bounds (2^0-2^40.7 for Mk2/Mk3, ≤2^32 for Mk4/Q/Mk5), and documenting the 32-bit reseed limitation.
- Cumulative theft figures (~1,367 BTC / ~$88.6M from 4,385+ addresses) and vendor remediation guidance are confirmed in wide security-press reporting.
Sources cited for Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned)
- Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked
- Coldcard Security Advisory
- Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
- COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
- Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million
- The Coldcard Incident: How Did This Happen?
- Hackers exploit Coldcard firmware flaw, stealing $89 million in Bitcoin from thousands of wallets
- Galaxy Research: Coldcard exploit ongoing, ~600 suspected attacker addresses reported to investigators
- Coldcard hardware wallets shipped with broken randomness for five years, Coinkite confirms
Detection coverage for TL-2026-1835
As of 2026-08-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1835 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.