Loading market data...

Coldcard RNG Exploit Tied to $88.6M in Bitcoin Losses Across Thousands of Addresses

Coldcard RNG Exploit Tied to $88.6M in Bitcoin Losses Across Thousands of Addresses

A random number generator flaw in Coldcard hardware wallets has been linked to confirmed losses of 1,367.05 bitcoin — roughly $88.6 million — spread across 4,585 addresses in three distinct attack waves. A fourth wave is suspected, with 462 new victim addresses and 380 BTC moved, according to Alex Thorn of Galaxy Research. The exploit, which targets devices with flawed firmware, has prompted Coldcard to halt shipments and destroy all remaining affected units.

The scale of the exploit

Onchain Lens confirmed the loss of 1,367.05 BTC across three waves. The fourth wave, identified by Thorn, involved 218 transactions between blocks 960,778 and 960,792. During that period, the transaction rate hit 13.8 per block — 45 times the pre-incident rate of 0.3. Earlier waves included a Canadian victim who lost $1.6 million. Some transactions have replace-by-fee (RBF) enabled, meaning victims can outbid attackers to recover funds, though success is not guaranteed.

How the attack worked

The vulnerability stems from a weak random number generator in certain Coldcard firmware versions. Attackers were able to predict or reproduce the seeds generated by affected devices, giving them access to the private keys and the ability to sweep funds. Coldcard has not disclosed the exact firmware versions involved, but the company confirmed that Satscard, Opendime, and Tapsigner products are unaffected by the exploit.

Coldcard's response and the patch

Coldcard halted shipments and destroyed all remaining devices with the flawed firmware. The company released a patched firmware, but it only protects newly generated seeds. Users who already have funds on affected devices must create a fresh seed and migrate their bitcoin to a new wallet. Coldcard's legal team is coordinating with law enforcement and the wider self-custody community. Changpeng Zhao (CZ) issued a warning about hardware wallet risk, though he did not specifically name Coldcard.

What users should do

Anyone using a Coldcard device should check whether their firmware is affected. If it is, they need to generate a new seed on the patched firmware and move all funds to that new wallet. Simply updating the firmware does not protect existing seeds — only new ones. The company advises users to treat any funds held on an affected device as compromised.

Uncertainty over a fourth wave

The final toll may depend on whether the fourth wave is confirmed and whether pending RBF fee races can rescue funds. Thorn's analysis points to 462 new victim addresses and 380 BTC moved, but the status of those funds remains unclear. Coldcard and law enforcement are still investigating, and the self-custody community is watching closely for any further developments.