Public AML

Critical Entropy Vulnerability in Coldcard Wallet Leads to $70.2 Million Loss

A vulnerability in Coldcard Mk3 firmware allowed attackers to exploit weak entropy during seed generation, leading to significant losses. The incident resulted in the draining of 1,196 addresses of Bitcoin within a short timeframe.

On July 30, 2026, a critical vulnerability was identified in the firmware of Coldcard Mk3 hardware wallets, specifically in versions 4.0.1 to 4.1.9. This flaw caused the wallets to utilize a weak software pseudo-random number generator (PRNG) instead of the intended hardware true random number generator during seed generation, resulting in insufficient entropy of approximately 40 to 72 bits.

As a consequence, attackers were able to derive private keys and drain a total of 1,196 addresses, amounting to 1,082.65 BTC, which is roughly $70.2 million. The stolen funds were quickly consolidated into four addresses and have not been moved since. Coinkite issued a security advisory about 30 hours after the incident, confirming the vulnerability, releasing a fixed firmware version, and urging affected users to migrate their funds.

Sources

Share:XTelegramLinkedIn