S&P 5007,600.50▲1.5% Nasdaq25,913.90▲2.1% Dow53,178.41▲1.3% Russell 2K2,981.91▲1.7% 10-Yr4.69%−6bp VIX15.86−0.13 WTI$80.00▼5.5% Gold$4,106.70▲1.4% EUR/USD1.151▼0.1% BTC$64,256▲1.2% Nikkei64,362▲4.0%
At close · Mon, Aug 3, 2026
Daily Market Updates.

Crypto

HomeCryptoMarket StructureColdcard wallet firmware bug cut Bitcoin seed randomne…

Coldcard wallet firmware bug cut Bitcoin seed randomness space

The flaw shrank the effective seed search space to about 40 bits on older models and helped attackers steal at least 1,596 BTC across multiple waves.

A firmware issue in Coldcard hardware wallets caused the devices to generate Bitcoin seed values using a software pseudo-random generator instead of the hardware random number chip meant to supply entropy, according to Decrypt. The change reduced the effective seed search space from 128 bits to roughly 40 on older models, making it easier for attackers to work out private keys.

Decrypt reports that the coins were stolen from Coldcard devices despite there being no phishing links, malware, or compromised computers involved, because the attacker did not need internet access to the wallets. Galaxy Research tracked more than 1,596 BTC stolen across three confirmed waves, with a suspected fourth wave that could lift the total to about 2,055 BTC, roughly $130 million at current prices.

Decrypt also said one of the theft sweeps moved $70 million in 41 minutes, and Coinkite indicated at least 15 separate attackers were involved. Coinkite published a technical backgrounder on August 1 describing how the problem stemmed from cryptography migration, which rerouted seed generation away from the hardware RNG to a MicroPython software fallback for devices without a randomness chip.

The underlying cause, Decrypt reports, was a build guard that used #ifndef to check whether a setting was defined rather than whether it was enabled, with the relevant setting defined as zero. Coinkite said the bulk of randomness had been coming from a pseudo-random number generator it did not realize was included in the source code base, and on Mk2 and Mk3 devices the PRNG seed came from the chip serial number and its clock.

Latest closeBitcoin $64,255.96 ▲1.2%

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.