A July 30 heist that emptied 1,196 Bitcoin addresses in 41 minutes has been traced to a seed-generation defect in Coldcard, the hardware wallet built by Canadian firm Coinkite. Blockchain sleuths at Galaxy Research connected the drain, which moved 1,082.65 BTC valued near $70.2M, to a faulty random number path in the device’s firmware.
The fault dates to a March 2021 firmware integration error that routed seed generation to MicroPython’s deterministic Yasmarang software PRNG instead of the STM32 hardware random number generator. Block’s engineering team traced the issue to a production config that defined MICROPY_HW_ENABLE_RNG as zero, so the library checked whether the macro existed rather than whether it was enabled.
Effective entropy drops to roughly 40 bits on the Mk3 and about 72 bits on the Mk4, Mk5 and Q, against 128 bits for a 12-word BIP-39 seed. An attacker who can determine or constrain the device UID, timer state and prior RNG-call history can reproduce candidate output streams offline and match derived addresses against public blockchain data.
Coinkite lists the exposed firmware as Mk2 and Mk3 releases from 4.0.0 through 4.1.9, Mk4 and Mk5 builds older than 5.6.0, and Q units before 1.5.0Q. Emergency updates went out for every model and release track on July 31, but installing them leaves already-generated seeds weak. Coinkite’s guidance is to roll a fresh seed on the patched firmware and move the coins, since carrying the old seed into an updated wallet preserves the flaw.
Coinkite says seeds built from at least 50 fair, independent, private dice rolls are not at risk from this bug alone. Multisig helps only when the quorum does not consist entirely of affected devices. No attacker has been named, and Galaxy found no prior transactions matching the sweep’s unusual 30 sat/vB, no-change signature.
