Coldcard Bug Prompts Dice Throws for Bitcoin Self-Custody
Coldcard hardware wallets suffered a low-entropy flaw allowing attackers to brute-force seeds and steal over $100M BTC. The bug, introduced in firmware 4.0.1, has led users to re-evaluate their setups, with dice throws providing physical entropy to secure funds.
Quick Take
Coldcard firmware 4.0.1 used weak PRNG instead of hardware RNG, giving 40-70 bits entropy.
Bug allowed attackers to brute-force seeds, stealing over $100M in BTC since July 30.
Users now add physical dice entropy to avoid reliance on device randomness.
Honeypots track swept wallets; cross-checking seeds with other devices recommended.
Market Impact Analysis
NeutralThe Coldcard entropy flaw undermines confidence in hardware wallets, but mitigations like physical entropy and cross-checking preserve self-custody security; overall crypto market impact is limited but could affect wallet sales and user practices.
Speculation Analysis
Key Takeaways
- Coldcard firmware 4.0.1 swapped the STM32 hardware RNG for a weak PRNG, slashing seed entropy to 40–70 bits.
- Attackers brute-forced seeds, draining over $100M in BTC from vulnerable wallets since July 30.
- Adding physical dice entropy blocks the attack; users with dice-rolled seeds were unaffected.
- Honeypots now track swept wallets; cross-checking seed generation across multiple devices is advised.
What Happened
Coldcard hardware wallets suffered a catastrophic seed-generation flaw after a firmware rewrite shipped in version 4.0.1 (March 2021). The device defaulted to MicroPython’s Yasmarang pseudo‑random number generator instead of the STM32’s proper hardware RNG. That swap gutted seed phrase entropy—down to 40 bits on Mk2/Mk3 and roughly 70 bits on Mk4/Mk5/Q—far below the 128‑bit minimum needed for a secure 12‑word seed. Beginning July 30, attackers started brute‑forcing the predictable seeds, quickly siphoning over $100 million in BTC. Wallets protected by supplementary dice‑roll entropy or BIP‑39 passphrases escaped the attack, underscoring the risk of trusting a single device for randomness.
The Numbers
The breach already exceeds $100 million in stolen Bitcoin, with funds moving to mixers. Mk2 and Mk3 devices yielded only 40 bits of entropy—effectively guessable with moderate computing power. Later Mk4, Mk5, and Q models managed about 70 bits, still trivial to brute‑force. The bug lingered for over two years before public exploitation surfaced. Honeypot wallets deployed by researcher James O’Beirne confirm attackers are actively sweeping vulnerable seeds, leaving low‑balance wallets untouched while draining richer ones.
Why It Happened
The flaw traces back to a firmware overhaul that moved from a GPL‑licensed codebase to a proprietary model. During that transition, the hardware RNG was accidentally replaced with a software fallback that is not cryptographically secure. The incident lays bare a single point of failure in hardware‑wallet design: users assume the device generates true randomness without verification. The Bitcoin community’s “don’t trust, verify” axiom proved decisive—those who added manual dice entropy suffered no loss. Coldcard’s oversight shows that even battle‑tested vendors can introduce critical bugs in routine updates.
Broader Impact
The exploit will likely accelerate multi‑source entropy practices. Hardware wallets remain a cornerstone of self‑custody, but users are now combining them with physical dice rolls or cross‑checking seeds on separate devices. The episode may push manufacturers to offer transparent entropy generation and audit trails. While Coldcard’s reputation has taken a short‑term hit, the long‑term lesson could harden self‑custody security across the industry.
What to Watch Next
- Additional drained wallets as attackers refine brute‑force heuristics.
- Coldcard’s official response and any hardware or firmware mitigations.
- Industry movement toward entropy‑verification tools and best practices.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.