A separate earlier wave of the same exploit swept 594 BTC (~$38 million) from about 500 single-signature wallets in a 25-minute burst around 01:31 UTC . Galaxy Research, Chainalysis, and Block's engineering team all independently linked the thefts to the same Coldcard vulnerability .
Block's Bitcoin Engineering and Security team, led by engineer Clay Garrett, identified that the attacker used a paid account at a well-known blockchain-services provider to efficiently identify and query vulnerable addresses . The attacker's on-chain pattern — unusually rapid, sequential sweeps of addresses sharing the same weakness — tipped off investigators. Block confirmed trace evidence connecting the operator's activity directly to that provider's infrastructure .
Block's investigation found what Garrett described as "extraordinary specificity, down to the account level" . The analytics service effectively served as a reconnaissance tool, letting the attacker quickly map which addresses were generated on vulnerable firmware and prioritize the richest targets .
The bug was introduced in a March 2021 firmware commit (beginning with Mk3 firmware version 4.0.1) during a migration to Bitcoin Core's libsecp256k1 library . A build-configuration macro error caused the firmware to bypass the device's dedicated STM32 hardware random number generator (TRNG) and instead fall back to MicroPython's deterministic Yasmarang software RNG .
The production board configuration set MICROPY_HW_ENABLE_RNG to zero because Coldcard had a separate hardware-RNG wrapper. But the libngu library failed to call that wrapper correctly: its guard condition (#ifndef MICROPY_HW_ENABLE_RNG) tested only whether the macro was defined, not whether its value was non-zero . Because the macro was defined (set to zero), libngu silently concluded the hardware path was available and bound to MicroPython's software-based rng_get() function .
This reduced effective entropy to roughly 32–40 bits (down from the intended 128+ bits), meaning only about 4 billion possible seed values — trivially brute-forceable with modern hardware . Seeds generated without user-added dice rolls or a BIP 39 passphrase were fully exposed .
Coinkite CEO Rodolfo Novak (NVK) later acknowledged the error: "I explicitly set MICROPY_HW_ENABLE_RNG to zero, thinking we didn't need either version, but that's not what it does" .
| Affected | Unaffected |
|---|---|
| Coldcard Mk3, firmware 4.0.1 through 5.0.3 | Mk4, Q, Mk5 (per initial Coinkite analysis) |
| Seeds generated without user dice rolls or BIP 39 passphrase | Seeds generated with user-supplied dice rolls or passphrase |
Coinkite later expanded its advisory to include certain Mk4, Mk5, and Q firmware versions after further analysis, and released emergency firmware updates for all affected models .
This exploit has shaken one of the core promises of self-custody — that a hardware wallet's secure element guarantees cryptographic safety regardless of software bugs .
For a detailed technical breakdown, see Block's engineering report and Coinkite's technical backgrounder .