Crypto
Home›Crypto›Market Structure›Coldcard hardware wallet flaw routed seed generation t…
Coldcard hardware wallet flaw routed seed generation to weak randomness
A firmware bug shipped in March 2021 and kept in publicly readable code for more than five years enabled an ongoing sweep of thousands of addresses, reaching 4,585 and nearly $90 million by Galaxy Research.
Bitcoin Magazine says a Coldcard hardware wallet design flaw caused some seed generation to use a weak software pseudorandom number generator instead of the device’s hardware entropy source.
According to the article, the issue was introduced in March 2021 and remained in publicly readable firmware for more than five years, with researchers later estimating the effective entropy collapsed to around 40 bits on some models.
The outlet describes how attackers swept 500 addresses before the cause was understood, and that by the time of Galaxy Research’s tally the theft had expanded to 4,585 addresses and nearly $90 million, with the attack ongoing as of the publication date.
Bitcoin Magazine also argues that the incident is a preview of why closed-source approaches may no longer be meaningful, noting that even after a pre-attack AI-assisted audit reportedly found nothing, frontier models later located the same flaw quickly from a single prompt, and the article attributes the broader lesson to how machines can analyze code humans missed.
Latest closeBitcoin $64,346.66 ▼0.4%