S&P 5007,489.72▲0.7% Nasdaq25,373.85▲1.0% Dow52,485.03▲0.5% Russell 2K2,931.34▼0.5% 10-Yr4.75%+8bp VIX15.99−1.10 WTI$86.80▲3.8% Gold$4,098.60▼0.0% EUR/USD1.153▲0.5% BTC$63,780▲0.5% Nikkei61,867▲0.7%
At close · Fri, Jul 31, 2026
Daily Market Updates.

Crypto

HomeCryptoMarket StructureColdcard hardware wallet bug undermines Bitcoin seed r…

Coldcard hardware wallet bug undermines Bitcoin seed randomness

The flaw stemmed from a March 1, 2021 code change, and affected firmware 4.0.0 shipped on March 17, reducing the effective search space for recovery phrases to about 40 bits on some models.

CryptoSlate reports that Coldcard’s newly disclosed random-number generator bug can leave affected Bitcoin hardware wallets vulnerable at the moment a seed recovery phrase is created, even if the wallet is air-gapped and used offline. The issue, according to the reporting, is that wallet seeds may appear to be ordinary 12- or 24-word phrases, but the underlying randomness uses a much smaller, more predictable deck than intended.

The publication says an attacker could generate candidate seeds on another machine, derive the corresponding public addresses, and then check the results against activity on Bitcoin’s public ledger. CryptoSlate’s account of the analysis points to a deterministic fallback in MicroPython that was used instead of the intended hardware random-number generator when a configuration setting, MICROPY_HW_ENABLE_RNG, was effectively disabled but only detected by whether the setting existed.

CryptoSlate also cites analysis pointing to timing and impact: a March 1, 2021 code change moved seed generation into a new library, and the affected path shipped in Coldcard firmware 4.0.0 on March 17. Coinkite’s preliminary estimate puts affected Mk2 and Mk3 seeds at roughly 40 bits of effective search space, while affected Mk4, Mk5, and Q seeds are estimated around 72 bits, with additional discussion of later device stream limits.

The outlet further notes that Block’s coordinated analysis identified another limit where, if the fallback state and call history were fixed, at most 2^32 streams could be securely distinguished. Coinkite’s figures and security advisory, as summarized by CryptoSlate, list Mk4 and Mk5 firmware prior to standard 5.6.0 or Edge 6.6.0X as within the affected range.

Latest closeBitcoin $63,780.28 ▲0.5%

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.