Coldcard RNG Flaw Leads to Over $110 Million Bitcoin Theft
Coldcard RNG Flaw Leads to Over $110 Million Bitcoin Theft
At the end of last week, Coinkite warned users about a critical vulnerability in Coldcard hardware wallets affecting seed generation.
Vulnerability and scope
Coinkite reported that a flaw in the device’s random number generator undermined the process used to create seed phrases and private keys.
As a result, attackers were able to derive users’ private keys and access funds without interacting with the devices over the internet.
Scale of the theft
According to analysts at Galaxy Research, by Monday attackers had emptied around 5000 wallets and withdrawn 1755 bitcoins, exceeding $110 million.
The research group also noted that the operation remained active at the time of reporting, with additional losses possible if devices remain uncompensated.
Why cold storage did not help
Cold storage typically protects keys by keeping them offline, but this incident shows that compromised cryptographic entropy defeats that offline isolation.
When key generation itself is predictable or flawed, the physical security of the device does not prevent private key reconstruction by attackers.
Recommendations for users
Coinkite has advised Coldcard owners to follow its remediation steps, including generating new seed phrases using patched or alternative hardware and moving funds promptly.
Users are urged to verify instructions from Coinkite before transferring assets and to avoid reusing potentially compromised seeds or devices.
Related posts

