Coldcard RNG Vulnerability Update: Fourth Attack Wave Pushes Losses Above 1,800 BTC

DEVELOPMENT

The Coldcard RNG vulnerability continues to unfold as researchers track what appears to be a fourth coordinated wave of wallet sweeps linked to weak-entropy seeds generated on vulnerable firmware.

While the root cause of the vulnerability is now well understood, the on-chain impact is still growing. New findings from Galaxy Research suggest attackers remain actively identifying and draining wallets generated using affected versions of Coldcard firmware.

A Fourth Coordinated Attack Wave Emerges

In the early hours of August 3, Galaxy Research’s Head of Research, Alex Thorn, flagged what appears to be a fourth large-scale attack wave targeting vulnerable Coldcard-generated wallets.

Initial analysis identified approximately 218 transactions moving nearly 389 BTC from suspected victim wallets. As researchers refined the dataset, estimates increased to between 389 and 449 BTC moved from approximately 462 to 709 addresses during a concentrated attack window.

The activity closely resembled the previous three attack waves observed over the past several days.

Researchers noted several characteristics that strongly suggest the same underlying vulnerability is being exploited:

  • Sweep activity reached approximately 13.8 transactions per block, roughly 45 times higher than the pre-incident baseline.
  • The affected UTXOs matched patterns previously associated with vulnerable Coldcard-generated seeds.
  • Many funds originated from wallets whose inputs did not predate the March 2021 firmware regression.
  • Attackers shifted from consolidating funds into a small number of collection wallets toward sending funds to mostly fresh one-to-one destination addresses.
  • Some transactions opted into Replace-by-Fee (RBF), creating a brief opportunity for owners who still control their private keys to attempt competing higher-fee transactions.

The change in transaction topology may indicate attackers are adapting their operational security as public monitoring efforts intensify.

Total Losses Continue to Rise

When combined with the previous three attack waves, observed losses now exceed 1,800 BTC.

At current market prices, that places the value of the affected funds in the range of approximately $110 million to $114 million.

Researchers estimate that more than 5,000 addresses may have been impacted across all observed waves.

Notably, much of the bitcoin stolen during earlier sweeps remains unspent, allowing investigators to continue tracking attacker-controlled wallets and transaction flows.

Galaxy Research says it is actively monitoring known addresses, sharing intelligence with investigators, and encouraging any remaining holders of vulnerable funds to migrate immediately.

Revisiting the Root Cause

The latest attack activity does not represent a new vulnerability.

Instead, it is a continuation of the same issue first traced to a March 2021 firmware regression affecting Coldcard’s seed generation process.

As detailed in previous analyses by both Coinkite and Block’s Bitcoin Engineering and Security teams, a flawed preprocessor guard caused the firmware to fall back to Yasmarang, a deterministic software pseudo-random number generator, rather than the hardware true random number generator originally intended for seed creation.

Because seed generation depends entirely on high-quality randomness, this regression significantly weakened the security of affected wallets.

Block’s analysis highlighted the potential scope of the issue:

Mk2 and Mk3 Devices

Coldcard Mk2 and Mk3 devices running affected v4 firmware versions may have generated seeds with critically low entropy, making them substantially easier to recover than intended.

Mk4, Mk5, and Q Devices

Newer Coldcard devices introduced secure-element reseeding, but Block’s researchers concluded that only about 32 bits of effective entropy may have been added during the reseeding process.

This assessment is more conservative than Coinkite’s estimate of approximately 72 bits, but both analyses agree that entropy levels were significantly lower than expected for secure Bitcoin seed generation.

Regardless of the exact figure, researchers agree that vulnerable seeds should be considered compromised and replaced.

Firmware Updates Alone Are Not Enough

One of the most important points for users to understand is that firmware updates only protect future seed generation.

Updating a device does not strengthen a seed that was already generated on vulnerable firmware.

If a wallet was created using an affected version, the only reliable solution is migration to an entirely new seed generated on patched firmware or another trusted device.

This distinction remains critical because many users mistakenly assume installing the latest firmware automatically fixes existing wallets.

It does not.

Current Recommendations

The guidance from researchers and wallet manufacturers remains largely unchanged.

Users who generated seeds on vulnerable firmware should:

  • Generate a brand-new seed using patched firmware or another verified secure wallet.
  • Carefully verify backup procedures and recovery information.
  • Confirm receiving addresses before moving funds.
  • Send a small test transaction first.
  • Move the full balance only after confirming successful receipt.
  • Use sufficiently high transaction fees to avoid delays.

Researchers also note that certain users may face lower risk than others.

Wallets that incorporated substantial user-generated dice-roll entropy during seed creation or used a strong and unique BIP-39 passphrase have additional layers of protection.

However, experts continue to recommend migration even in those cases.

Current Status

Coinkite has released patched firmware across affected product lines and has reportedly destroyed remaining inventory containing vulnerable firmware.

Block has confirmed that none of its products, including Bitkey, are affected by this issue.

Multisignature setups remain significantly more resilient because compromising a single vulnerable key is insufficient to access funds when additional secure keys are required for signing.

What began as an isolated report of suspicious wallet drains has evolved into one of the most significant Bitcoin hardware wallet security incidents in recent years.

The technical root cause is now largely understood, thanks in large part to the detailed work of Block’s Bitcoin Engineering and Security teams and ongoing analysis from researchers across the ecosystem.

What remains uncertain is the final scale of the damage.

With a fourth coordinated attack wave now observed and total losses exceeding 1,800 BTC, the incident should be viewed as an active and ongoing threat rather than a completed event.

For anyone still holding funds secured by seeds generated on vulnerable Coldcard firmware, the safest assumption is that time is no longer on your side.

Sources

This article is based on publicly available research, on-chain analysis, and security advisories from the organizations involved in investigating the Coldcard RNG vulnerability.

  1. Galaxy Research
    • Alex Thorn’s analysis and on-chain observations regarding the fourth coordinated attack wave, transaction patterns, sweep rates, affected addresses, and total BTC impacted.
  2. Block Engineering
  3. Coinkite Security Advisories
  4. COLDCARD Firmware Repository
ENJOYED THIS ARTICLE?Support the authorSend a zap over Lightning or on-chain