Executive Summary
In July 2026, a critical vulnerability in Coldcard hardware wallets led to the theft of approximately $70.2 million in Bitcoin. The flaw, introduced in a March 2021 firmware update, caused the devices to use a deterministic software pseudorandom number generator (PRNG) instead of the intended hardware random number generator (RNG) for seed generation. This oversight allowed attackers to predict wallet seeds by analyzing device-specific information and prior RNG states, enabling unauthorized access to funds. Coinkite, the manufacturer, released emergency firmware updates on July 31, 2026, but emphasized that updating the firmware does not secure existing seeds. Users were advised to generate new seeds using the patched firmware and transfer their assets accordingly. This incident underscores the critical importance of robust entropy sources in cryptographic systems and highlights the potential risks associated with firmware updates that inadvertently introduce vulnerabilities.
Why This Matters Now
The Coldcard hardware wallet vulnerability highlights the ongoing challenges in ensuring the security of cryptocurrency storage solutions. As digital assets become more mainstream, the sophistication of attacks targeting them increases. This incident serves as a stark reminder for both manufacturers and users to prioritize security in firmware development and to remain vigilant about potential vulnerabilities that could compromise asset safety.
Attack Path Analysis
An attacker exploited a firmware flaw in Coldcard hardware wallets, allowing them to predict wallet seed phrases and gain unauthorized access to Bitcoin addresses. This led to the unauthorized transfer of approximately $70.2 million worth of Bitcoin from 1,196 addresses within 41 minutes.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited a firmware flaw in Coldcard hardware wallets, which used a deterministic software pseudorandom number generator (PRNG) instead of the hardware random number generator (RNG), allowing prediction of wallet seed phrases.
MITRE ATT&CK® Techniques
Modify System Firmware
Data Encrypted for Impact
Valid Accounts
Exploitation for Client Execution
Credential Dumping: Credential API Hooking
OS Credential Dumping: LSASS Memory
Command and Scripting Interpreter: PowerShell
Impair Defenses: Disable or Modify Tools
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Cryptographic vulnerability in hardware wallets threatens institutional Bitcoin custody operations, requiring enhanced entropy validation and immediate firmware updates for secure asset management.
Investment Banking/Venture
Predictable random number generation in Coldcard wallets exposes cryptocurrency investment portfolios to seed prediction attacks, demanding stronger custody security protocols and compliance measures.
Investment Management/Hedge Fund/Private Equity
Hardware wallet firmware flaws create deterministic seed vulnerabilities affecting cryptocurrency asset protection, necessitating multi-signature implementations and enhanced due diligence on custody solutions.
Capital Markets/Hedge Fund/Private Equity
Weak pseudorandom number generation in Bitcoin hardware wallets enables mass address sweeping attacks, requiring immediate assessment of cryptocurrency custody infrastructure and security controls.
Sources
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minuteshttps://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.htmlVerified
- Coldcard Security Advisoryhttps://blog.coinkite.com/coldcard-mk3-seed-generation-warning/Verified
- Predictable RNG Fallback and 32-bit Reseed in Coldcard Firmwarehttps://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmwareVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to predict wallet seed phrases and access Bitcoin addresses, thereby reducing the scope of unauthorized transfers.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit the firmware flaw may have been limited, reducing the likelihood of predicting wallet seed phrases.
Control: Zero Trust Segmentation
Mitigation: The attacker's unauthorized access to private keys could have been constrained, limiting their ability to escalate privileges.
Control: East-West Traffic Security
Mitigation: The attacker's ability to access multiple Bitcoin addresses could have been limited, reducing the scope of lateral movement.
Control: Multicloud Visibility & Control
Mitigation: The attacker's control over compromised wallets could have been constrained, limiting their ability to prepare unauthorized transactions.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to transfer large amounts of Bitcoin could have been limited, reducing the extent of unauthorized transfers.
The financial loss experienced by Bitcoin holders could have been reduced, limiting the overall impact of the attack.
Impact at a Glance
Affected Business Functions
- Cryptocurrency Storage
- Transaction Security
Estimated downtime: N/A
Estimated loss: $70,200,000
Private keys and seed phrases of affected Coldcard hardware wallet users
Recommended Actions
Key Takeaways & Next Steps
- • Implement robust random number generation mechanisms to ensure the unpredictability of cryptographic keys.
- • Regularly audit and update firmware to identify and remediate vulnerabilities promptly.
- • Educate users on the importance of generating new seed phrases when vulnerabilities are discovered.
- • Enhance monitoring systems to detect and respond to unauthorized access attempts swiftly.
- • Develop and enforce policies for secure key management and storage practices.



