Coldcard Firmware Flaw Cut Seed Entropy to 40 Bits, Enabling a $70M Bitcoin Sweep in 41 Minutes
TL;DR what: A build-configuration error in Coldcard firmware, introduced in March 2021, silently routed BIP-39 seed generation to MicroPython's deterministic Yasmarang PRNG instead of the STM32 hardware RNG. On Jul
TL;DR
- what: A build-configuration error in Coldcard firmware, introduced in March 2021, silently routed BIP-39 seed generation to MicroPython's deterministic Yasmarang PRNG instead of the STM32 hardware RNG.
On July 30, 2026, a single attacker drained 1,196 Bitcoin addresses in 41 minutes, moving 1,082.65 BTC worth roughly $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware defect in Coldcard, the Bitcoin-only hardware wallet built by Canadian firm Coinkite. The flaw had been shipping since March 2021.
Originally published on RedEye Threat Intelligence.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.