Top StoriesBearish
82
BTC

Coldcard 5-Year Seed Flaw Drains $90M, Exposing Testing Gap

A five-year bug in Coldcard hardware wallets routed seed generation to a weak RNG, enabling theft of $90M in BTC. Kraken's security chief demands independent testing mandates, akin to payments and government standards, to close the verification gap in digital asset self-custody.

CointelegraphCointelegraph by Felix Ng

Quick Take

1

Coldcard’s 2021 code migration accidentally used a weak PRNG for seed generation, remaining undetected.

2

Over 4,500 addresses drained of nearly $90M in Bitcoin as attackers exploit flawed wallets.

3

Kraken CSO calls for mandatory independent testing, citing NIST and BSI standards as models.

4

Coldcard halted shipments, destroyed affected units, and will cooperate with law enforcement.

Market Impact Analysis

Bearish

The theft of $90M in BTC and exposure of a critical hardware wallet flaw undermines trust in self-custody solutions, potentially driving users away from hardware wallets in the short term.

Timeframeshort

Speculation Analysis

Factuality90/100
RumorsVerified
Speculation Trigger50/100
MinimalExtreme FOMO

Key Takeaways

  • Coldcard’s 2021 code migration accidentally routed seed generation to a weak PRNG, leaving a vulnerability undetected for five years.
  • Over 4,500 addresses were drained of nearly $90 million in Bitcoin as attackers exploited the flaw in affected hardware wallets.
  • Kraken’s chief security officer demands mandatory independent testing for hardware wallets, citing NIST and BSI standards as models.
  • Coldcard halted all device shipments, destroyed affected units, and will cooperate with law enforcement in fund recovery efforts.
Stolen Funds$90MIn Bitcoin across 4,500 addresses
Flaw Duration5 YearsUndetected since March 2021
Devices ImpactedShipments HaltedAffected units destroyed
Industry CallMandatory TestingPer NIST SP 800-90B, BSI AIS-31

What Happened

A critical software flaw in Coldcard hardware wallets went unnoticed for five years, allowing attackers to drain nearly $90 million in Bitcoin from over 4,500 addresses. The vulnerability stemmed from a code change in March 2021 that redirected seed generation to a weaker random number generator instead of the intended true random number generator. Coldcard’s maker, Coinkite, disclosed the issue and halted all device shipments, destroying affected inventory. Users are now being advised to retain devices for potential fund recovery as legal teams coordinate with law enforcement. The incident has sparked a broader reckoning over hardware wallet security and independent testing protocols.

The Numbers

The attack has been devastating in scale. Nearly $90 million in Bitcoin was siphoned from over 4,500 compromised addresses, with a suspected fourth attack wave sweeping 389 BTC in a single sweep. The flaw existed since a March 2021 firmware update, meaning wallets created in that five-year window remain at risk. Coldcard’s response was swift but reactive: all new device shipments were stopped, and affected units were destroyed to prevent further exposure. This theft now ranks among the largest hardware wallet exploits in crypto history.

Why It Happened

The root cause was an inadvertent code migration during a cryptographic library update. Coldcard’s firmware contained both a strong true random number generator (TRNG) and a weaker MicroPython PRNG. After the 2021 change, the seed-generation process mistakenly relied on the weak PRNG, while the TRNG was only used for non-critical tasks. Code reviews failed to catch this because the TRNG was present and functional—but not the one being called. Kraken CSO Nick Percoco highlighted that the industry lacks the end-to-end entropy verification standards seen in payments and government applications, where labs independently confirm the actual source of randomness in production firmware.

Broader Impact

This incident undercuts trust in hardware wallets as the gold standard for self-custody. Percoco’s call for mandatory independent testing—modeled after NIST SP 800-90B and BSI AIS-31—could accelerate regulatory or industry-led standards. Without such measures, the gap between approved entropy paths and actual implementation leaves millions of users exposed. For the crypto industry, this is a wake-up call that self-custody security must move beyond vendor-sponsored audits to rigorous, third-party verification.

What to Watch Next

  • Coldcard’s legal team and law enforcement collaboration—progress on fund recovery and attacker identification will set a precedent for future hardware wallet breaches.
  • Industry response: Will major wallet makers adopt independent entropy testing, and will regulatory bodies mandate it? Look for announcements from self-custody providers.
  • User impact: Reimbursement possibilities and new security guidelines for affected Coldcard owners could emerge, along with potential class-action lawsuits.

Source: Cointelegraph

This article is for informational purposes only and does not constitute financial advice.

SourceRead the full article on Cointelegraph
Read full article

Always late to trends?

Join for the latest news, insights & more.

Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.

© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.

Read Next

Most Read

🏛️
Institutional & Investment NewsNeutral
48

Saylor’s Strategy Tracks Bitcoin’s 200-Week Moving Average

Michael Saylor’s company Strategy is now monitoring Bitcoin’s 200-week moving average, a historically significant long-term support level. The move highlights the firm’s continued attention to Bitcoin’s technical indicators amid its massive holdings.

BTC
90% confidence
Aug 3, 2026, 5:07 AM UTC · CoinDesk
Coldcard 5-Year Seed Flaw Drains $90M, Exposing Testing Gap | Bytewit