Top StoriesNeutral
79
BTC

Coldcard Bug Prompts Dice Throws for Bitcoin Self-Custody

Coldcard hardware wallets suffered a low-entropy flaw allowing attackers to brute-force seeds and steal over $100M BTC. The bug, introduced in firmware 4.0.1, has led users to re-evaluate their setups, with dice throws providing physical entropy to secure funds.

CointelegraphCointelegraph by Charles Bennett

Quick Take

1

Coldcard firmware 4.0.1 used weak PRNG instead of hardware RNG, giving 40-70 bits entropy.

2

Bug allowed attackers to brute-force seeds, stealing over $100M in BTC since July 30.

3

Users now add physical dice entropy to avoid reliance on device randomness.

4

Honeypots track swept wallets; cross-checking seeds with other devices recommended.

Market Impact Analysis

Neutral

The Coldcard entropy flaw undermines confidence in hardware wallets, but mitigations like physical entropy and cross-checking preserve self-custody security; overall crypto market impact is limited but could affect wallet sales and user practices.

Timeframeshort

Speculation Analysis

Factuality85/100
RumorsVerified
Speculation Trigger30/100
MinimalExtreme FOMO

Key Takeaways

  • Coldcard firmware 4.0.1 swapped the STM32 hardware RNG for a weak PRNG, slashing seed entropy to 40–70 bits.
  • Attackers brute-forced seeds, draining over $100M in BTC from vulnerable wallets since July 30.
  • Adding physical dice entropy blocks the attack; users with dice-rolled seeds were unaffected.
  • Honeypots now track swept wallets; cross-checking seed generation across multiple devices is advised.
Stolen BTC$100M+Since July 30
Entropy Loss40–70 bitsVs. required 128 bits
Firmware Bugv4.0.1Introduced March 2021
Attack MethodBrute‑forceOngoing sweeps

What Happened

Coldcard hardware wallets suffered a catastrophic seed-generation flaw after a firmware rewrite shipped in version 4.0.1 (March 2021). The device defaulted to MicroPython’s Yasmarang pseudo‑random number generator instead of the STM32’s proper hardware RNG. That swap gutted seed phrase entropy—down to 40 bits on Mk2/Mk3 and roughly 70 bits on Mk4/Mk5/Q—far below the 128‑bit minimum needed for a secure 12‑word seed. Beginning July 30, attackers started brute‑forcing the predictable seeds, quickly siphoning over $100 million in BTC. Wallets protected by supplementary dice‑roll entropy or BIP‑39 passphrases escaped the attack, underscoring the risk of trusting a single device for randomness.

The Numbers

The breach already exceeds $100 million in stolen Bitcoin, with funds moving to mixers. Mk2 and Mk3 devices yielded only 40 bits of entropy—effectively guessable with moderate computing power. Later Mk4, Mk5, and Q models managed about 70 bits, still trivial to brute‑force. The bug lingered for over two years before public exploitation surfaced. Honeypot wallets deployed by researcher James O’Beirne confirm attackers are actively sweeping vulnerable seeds, leaving low‑balance wallets untouched while draining richer ones.

Why It Happened

The flaw traces back to a firmware overhaul that moved from a GPL‑licensed codebase to a proprietary model. During that transition, the hardware RNG was accidentally replaced with a software fallback that is not cryptographically secure. The incident lays bare a single point of failure in hardware‑wallet design: users assume the device generates true randomness without verification. The Bitcoin community’s “don’t trust, verify” axiom proved decisive—those who added manual dice entropy suffered no loss. Coldcard’s oversight shows that even battle‑tested vendors can introduce critical bugs in routine updates.

Broader Impact

The exploit will likely accelerate multi‑source entropy practices. Hardware wallets remain a cornerstone of self‑custody, but users are now combining them with physical dice rolls or cross‑checking seeds on separate devices. The episode may push manufacturers to offer transparent entropy generation and audit trails. While Coldcard’s reputation has taken a short‑term hit, the long‑term lesson could harden self‑custody security across the industry.

What to Watch Next

  • Additional drained wallets as attackers refine brute‑force heuristics.
  • Coldcard’s official response and any hardware or firmware mitigations.
  • Industry movement toward entropy‑verification tools and best practices.

Source: Cointelegraph

This article is for informational purposes only and does not constitute financial advice.

SourceRead the full article on Cointelegraph
Read full article

Always late to trends?

Join for the latest news, insights & more.

Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.

© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.

Read Next

Most Read

Top StoriesBearish
78

Ethereum’s EIP-8363 Staking Reward Cut Sparks Fierce Backlash

Ethereum’s EIP-8363 proposal to slash staking rewards ignites fierce backlash from DeFi builders, staking providers, and institutions. Supporters claim the network is over-secured and overpaying validators, while critics warn of damage to decentralization and investor confidence, raising fundamental questions about Ethereum’s monetary policy.

ETH
80% confidence
Aug 7, 2026, 1:30 PM UTC · Cointelegraph
Coldcard Flaw Drains $100M BTC, Dice Entropy Now Essential | Bytewit