DEV Community

Etairos.ai
Etairos.ai

Posted on • Originally published at threat-intelligence.redeyesecurity.com

Coldcard Firmware Flaw Cut Seed Entropy to 40 Bits, Enabling a $70M Bitcoin Sweep in 41 Minutes

TL;DR

  • what: A build-configuration error in Coldcard firmware, introduced in March 2021, silently routed BIP-39 seed generation to MicroPython's deterministic Yasmarang PRNG instead of the STM32 hardware RNG.

On July 30, 2026, a single attacker drained 1,196 Bitcoin addresses in 41 minutes, moving 1,082.65 BTC worth roughly $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware defect in Coldcard, the Bitcoin-only hardware wallet built by Canadian firm Coinkite. The flaw had been shipping since March 2021.


Originally published on RedEye Threat Intelligence.

Top comments (0)