Loading market data...

Coldcard Wallet Flaw Drains Over $100M in Bitcoin, Reignites Dice-Randomness Debate

Coldcard Wallet Flaw Drains Over $100M in Bitcoin, Reignites Dice-Randomness Debate

A flaw in Coldcard wallets has cost Bitcoin holders more than $100 million, the company confirmed this week. The bug stems from how the hardware wallet generates cryptographic keys — specifically, a problem with entropy that can arise when users rely on dice rolls for randomness. The incident has reopened a long-running debate in the Bitcoin community about whether dice-based key generation is safe enough for serious storage.

How the flaw works

The vulnerability is in the entropy source used during wallet setup. Coldcard wallets allow users to generate seed phrases by rolling physical dice, a method meant to avoid trusting software randomness. But the flaw means that under certain conditions, the dice-roll process produces keys with far less entropy than expected. That makes the wallets vulnerable to brute-force attacks. The company says the issue affects a specific batch of devices and firmware versions, though it hasn't released exact numbers.

The $100 million toll

Bitcoin holders who used the affected wallets have lost more than $100 million in total, according to estimates from blockchain analytics firms. The losses have been mounting over several months as attackers systematically targeted weak keys. Some victims reported their funds vanishing from addresses they believed were secure. The timing isn't great — Bitcoin's price has been volatile, and the losses add to a sense of unease in the self-custody space.

Dice randomness under fire again

The flaw has revived a debate that's as old as hardware wallets: can you really trust dice for generating randomness? Proponents argue that physical dice, if properly rolled and recorded, offer true randomness. Critics say the process is error-prone and that even small biases in dice or rolling technique can reduce entropy. Coldcard's issue appears to be a software-side failure to properly handle the dice input, not a problem with the dice themselves. Still, the incident is giving ammunition to those who argue that users should stick to software-generated entropy from trusted sources.

What Coldcard is doing

Coldcard has released a firmware update that patches the entropy-handling bug. The company is urging all users of the affected models to update immediately and to generate new seed phrases. It's also offering a tool to check whether a wallet's keys were generated during the vulnerable period. But for those who already lost funds, the fix comes too late. The company hasn't said whether it will offer compensation.

Unresolved questions

The biggest open question is how many wallets are still at risk. Coldcard hasn't disclosed the total number of devices affected, and many users may not know their keys were generated with insufficient entropy. The broader Bitcoin community is now watching to see whether other hardware wallet makers will audit their own dice-based key generation methods. For now, the message from security researchers is clear: if you used dice with a Coldcard, check your wallet — and maybe don't roll again.