TL;DR
- what: A build-configuration error in Coldcard firmware, introduced in March 2021, silently routed BIP-39 seed generation to MicroPython's deterministic Yasmarang PRNG instead of the STM32 hardware RNG.
On July 30, 2026, a single attacker drained 1,196 Bitcoin addresses in 41 minutes, moving 1,082.65 BTC worth roughly $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware defect in Coldcard, the Bitcoin-only hardware wallet built by Canadian firm Coinkite. The flaw had been shipping since March 2021.
Originally published on RedEye Threat Intelligence.
Top comments (0)