A firmware bug introduced in Coldcard in March 2021 bypassed the hardware random number generator, silently reducing seed entropy from 128 bits to as low as 40 bits. Loss estimates vary widely — from $38 million to $130 million — because researchers discovered vulnerable addresses gradually across multiple sweeps, B...
Research answer

Create a landscape editorial hero image for this Studio Global article: What caused the massive Coldcard hardware wallet breach in 2026, how much Bitcoin was stolen and why do loss estimates vary, what was the fi. Article summary: ## The 2026 Coldcard Breach: What Happened. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence.
On July 30, 2026, an attacker began draining Bitcoin from Coldcard hardware wallets — devices marketed as one of the most secure ways to self-custody cryptocurrency. Over the following days, four waves of thefts hit more than 7,300 addresses, with total losses reaching an estimated 2,055 BTC, worth roughly $130 million at prevailing prices . The root cause was a single firmware build error introduced five years earlier, in March 2021, that silently crippled the randomness of seed-phrase generation
.
A March 2021 firmware integration error caused Coldcard devices to bypass their dedicated hardware entropy chip during seed-phrase generation and fall back to a software-based pseudo-random number generator (PRNG) instead . The bug affected firmware versions 4.0.1 through 4.1.9, with later analysis extending the scope to versions up to 5.0.3 on Mk3 units
.
On affected Mk3 devices, effective entropy collapsed from the expected 128 bits to as low as ~40 bits, making seed phrases brute-forceable offline without any physical access, phishing, or malware . Coinkite's own analysis later confirmed that some Mk3 seeds had only about 40 bits of entropy
. A firmware check meant to verify the hardware RNG was active was itself broken by the same update, allowing the bug to go undetected for over five years
.
Block (Square) researchers published a detailed technical analysis on July 31, tracing the root cause to an integration error in Coldcard's random number generation code. "COLDCARD firmware contains an RNG integration error that causes ngu.random to use MicroPython's deterministic Yasmarang fallback instead of the STM32 hardware RNG," Block's report explained . This meant seed phrases were generated using predictable values — including the microcontroller's serial number and system counter — rather than true hardware randomness
.
Loss estimates range from $38 million to $130 million, and the wide spread is not contradictory — it reflects different snapshots as the attack unfolded and researchers expanded their on-chain analysis.
Coinkite's response was rapid, though the company faced a fundamental limitation: because the vulnerability was in seed generation itself, a firmware patch could not fix seeds that had already been created .
The broader security research community mobilized quickly to map the scale of the exploit and trace its root cause.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
A firmware bug introduced in Coldcard in March 2021 bypassed the hardware random number generator, silently reducing seed entropy from 128 bits to as low as 40 bits.
A firmware bug introduced in Coldcard in March 2021 bypassed the hardware random number generator, silently reducing seed entropy from 128 bits to as low as 40 bits. Loss estimates vary widely — from $38 million to $130 million — because researchers discovered vulnerable addresses gradually across multiple sweeps, BTC prices fluctuated during the incident, and Coinkite lacked the...
Coinkite released emergency firmware on July 31, 2026, but warned that updating firmware does not repair already compromised seeds; affected users must generate new seeds and migrate funds.