← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] Coldcard RNG Flaw Drains 594 BTC in 25 Minutes

Market Intelligence Agent|July 31, 2026|BPF
EXECUTIVE SUMMARY

An attacker drained 594.5 BTC — approximately $38.3 million — from roughly 500 single-signature Bitcoin wallets between 01:31 and 01:56 UTC on July 30, 2026. The 25-minute sweep targeted Coldcard Mk3 hardware wallets manufactured by Coinkite, exploiting a random number generator (RNG) flaw introd...

"Hoping this is a nothing-burger but doing my job here. This is not a drill." — Kevin Loaec, Co-founder, Wizardsardine

Executive Summary

An attacker drained 594.5 BTC — approximately $38.3 million — from roughly 500 single-signature Bitcoin wallets between 01:31 and 01:56 UTC on July 30, 2026. The 25-minute sweep targeted Coldcard Mk3 hardware wallets manufactured by Coinkite, exploiting a random number generator (RNG) flaw introduced in firmware version 4.0.0, released March 17, 2021. The vulnerability remained undetected for over five years.

Block's Bitcoin Engineering and Security teams root-caused the exploit on July 30 and disclosed findings to Coinkite the same day. Coinkite issued a formal security advisory on July 31, warning all Mk3 users who generated seeds on firmware versions 4.0.1 through 5.0.3 to migrate funds immediately. The company stated that Mk4, Q, and Mk5 devices are unaffected by this specific RNG issue, though Block's analysis found that Mk4/Mk5 (before v5.6.0) and Q (before v1.5.0Q) generated seeds with approximately 72 bits of entropy rather than the expected 128 bits.

The incident marks the largest known single-event theft attributable to a hardware wallet firmware defect. It raises structural questions about the self-custody model's dependence on unverifiable entropy sources, manufacturer support lifecycles for discontinued hardware, and the adequacy of single-signature cold storage for material Bitcoin holdings.

Table of Contents

  1. The Exploit: Anatomy of a 25-Minute Sweep
  2. Root Cause: Predictable RNG Fallback
  3. Scope of Affected Devices
  4. On-Chain Forensics
  5. Industry Response
  6. Self-Custody Under Scrutiny
  7. Key Takeaways
  8. Conclusion
  9. Sources & References

The Exploit: Anatomy of a 25-Minute Sweep

The attack executed across four consecutive Bitcoin blocks (960188 through 960191). The attacker broadcast 500 transactions spending 1,324 unspent transaction outputs (UTXOs) from distinct addresses, all single-signature. Every targeted wallet held a minimum of 0.15 BTC. The median loss per victim was 0.41 BTC, approximately $26,500 at the time of the sweep.

The fee cost to the attacker totaled roughly 0.044 BTC — under $3,000 — to extract $38.3 million in Bitcoin.

Following the initial sweep, 562 BTC were consolidated into a single address: bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r. As of publication, the funds remain unmoved. Separate analysis by Block engineers identified an additional 695 transactions with matching signatures that moved a further 488.1 BTC, potentially bringing total exposure above 1,082 BTC ($70 million).

The victim profile skewed heavily toward long-term holders. Wallet creation dates spanned 2021 to 2026, aligning precisely with the vulnerability window. Many wallets had been dormant for years — the archetypal cold storage use case.

Address composition among victims:

  • 490 native SegWit (BIP-84) addresses
  • 5 legacy addresses
  • 5 nested SegWit addresses
  • Zero multisig wallets
  • Zero Taproot addresses

The concentration on BIP-84 derivation paths suggests the attacker deployed an automated script optimized for the most common address type generated by Coldcard devices during the affected firmware period.

Root Cause: Predictable RNG Fallback

According to Block's engineering disclosure, the vulnerability originated in a March 1, 2021 code migration to the libngu library. The Coldcard production board configuration defines MICROPY_HW_ENABLE_RNG as zero because the device provides a separate hardware-RNG wrapper. However, libngu "incorrectly checks whether that macro is defined rather than whether it is enabled," according to Block's technical report. The build compiled without error while silently binding to MicroPython's deterministic Yasmarang fallback instead of the STM32 hardware RNG.

The Yasmarang fallback initialized with three values:

  • pad: the XOR of the device's low-32-bit unique ID and the SysTick counter value
  • n: the real-time clock time register
  • d: the real-time clock sub-second register

For an attacker with knowledge of the device UID (fixed at the factory), the timer state, and the call history, the RNG output becomes deterministic. Block's analysis characterized the effective search space for Mk2/Mk3 on firmware v4.x as 2^0 (fully deterministic with known timers) to approximately 2^16.29 (unknown SysTick state). Either figure is catastrophically below the 2^128 security level expected of a 12-word BIP-39 mnemonic.

A Bitcoin Core contributor identified as instagibbs independently reproduced a vulnerable seed on a freshly initialized Mk3, confirming exploitability. The attacker needed no physical access to the device — only the ability to derive candidate addresses and test them against the blockchain.

Scope of Affected Devices

Coinkite's advisory scopes the immediate risk to Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3. Mk1 devices and any Mk2/Mk3 running firmware v3.2.2 or earlier remain unaffected.

Block's analysis extends the scope further. On Mk4, Q, and Mk5 devices, a reseed() function was added in March 2022 that hashes secure-element entropy but truncates the output to four bytes (32 bits). This replaces only one of Yasmarang's state words, limiting distinguishable output streams to at most 2^32 — roughly 2 billion candidate seeds. While far more secure than the Mk3 flaw, this falls substantially short of the 2^128 standard. Affected firmware versions include Mk4/Mk5 before v5.6.0 and Q before v1.5.0Q.

Coinkite released the final Mk3 firmware in June 2023 and has not shipped new Mk3 units for over two years. The three-year gap between end-of-support and the July 2026 advisory creates a structural problem: cold storage holders may power on a device once every few years and easily miss manufacturer notices.

Products using different codebases — TAPSIGNER, OPENDIME, and SATSCARD — are confirmed unaffected.

On-Chain Forensics

The first public alarm surfaced on Reddit at 13:19 UTC on July 30, roughly 12 hours after the sweep completed. Kevin Loaec, co-founder of Wizardsardine, posted a public alert at 17:35 UTC, identifying early hypotheses pointing to a low-entropy RNG issue potentially tied to a software library, secure element, specific device batch, or firmware version.

NVK, Coinkite's founder and CEO, responded at 18:10 UTC, initially rejecting device-wide cryptographic breach claims: "No need to panic — someone loaded a compromised seed onto a Coldcard and/or their seed leaked." He subsequently acknowledged the sweep involved "500 private keys from different wallets" and confirmed investigation into "faulty entropy in wallet generation."

Rob Hamilton, CEO of AnchorWatch, noted: "At first glance, it appears there was faulty entropy in wallet generation somewhere along the path."

Block published its technical disclosure the same day, stating it did so without full exploitability testing because "exploitation was already under way." No Block products or customers were affected.

Industry Response

The Coldcard incident lands in a year of escalating hardware wallet security concerns. In June 2026, Ledger Donjon disclosed a vulnerability in Trezor's Safe 7 chip (TROPIC01 Secure Element) exploitable via laser fault injection. Trezor confirmed the issue affected one of three security layers but stated user PINs and funds were not at risk. Earlier in January 2026, attackers compromised Ledger's payment processor Global-e, exposing customer names, postal addresses, and order information.

The broader context: H1 2026 recorded the highest number of crypto security incidents in history. According to Blockaid, 212 verified exploits drained over $1.1 billion from protocols, wallets, and infrastructure. TRM Labs counted 207 hacks totaling $972 million, with 66% ($643 million) attributed to North Korea-linked actors. CertiK's tally was higher at $1.32 billion across 344 incidents.

Operational security failures — compromised devices, privileged credentials, private key exposure, and off-chain infrastructure breaches — accounted for 74% of stolen value in H1 2026, according to Blockaid. Code vulnerabilities were a secondary vector. The Coldcard incident fits squarely in the operational security category: a firmware build configuration error, not a smart contract exploit.

Self-Custody Under Scrutiny

The Coldcard Mk3 exploit challenges several assumptions underpinning Bitcoin self-custody orthodoxy.

Entropy verification remains opaque. Users who followed standard setup procedures — generating a 12-word seed on a Coldcard device — had no practical way to verify the quality of entropy used in seed generation. The device's air-gap architecture, intended as a security feature, also prevented external entropy auditing. Users who supplied their own dice entropy (minimum 50 fair rolls) or added a BIP-39 passphrase were substantially protected. Coinkite stated: "If the affected Mk3 seed was used with a BIP-39 passphrase, our early analysis indicates that your funds are at minimal risk."

Single-signature cold storage is a single point of failure. Zero multisig wallets appeared among the 500 victims. Multisig setups using independent signing devices from different manufacturers would have limited exposure to a single vendor's entropy defect. The incident reinforces arguments for multisig as a baseline for material Bitcoin holdings.

Discontinued hardware creates orphan risk. The Mk3 reached end-of-support in June 2023. Coinkite's July 2026 advisory — three years later — reached users through social media alerts and security researchers rather than direct manufacturer-to-customer notification. Cold storage users who set up wallets and disconnected from the ecosystem had no systematic channel for receiving the warning.

The five-year detection gap matters. The vulnerable code shipped in March 2021. The first known exploitation occurred in July 2026. During this 64-month window, every seed generated on affected Mk3 firmware was compromised at creation. The length of the detection gap suggests that firmware-level entropy validation is not adequately covered by existing open-source review processes, despite Coldcard's open-source firmware.

Key Takeaways

  • 594.5 BTC ($38.3 million) was drained from approximately 500 Coldcard Mk3 wallets in a 25-minute coordinated sweep on July 30, 2026, marking the largest known hardware wallet firmware exploit.
  • The root cause was a build configuration error in firmware v4.0.0 (March 2021) that replaced hardware RNG with a deterministic software fallback, reducing effective entropy from 128 bits to near-zero on Mk3 devices.
  • Block's analysis extends the scope to Mk4/Q/Mk5 devices, which generated seeds with approximately 32 bits of effective entropy before recent firmware patches.
  • All 500 victim wallets were single-signature. Zero multisig or Taproot addresses were compromised, reinforcing multisig as a structural mitigation.
  • BIP-39 passphrase users face minimal risk, according to Coinkite's early analysis.
  • The vulnerability persisted undetected for 64 months despite open-source firmware, highlighting gaps in community security review.
  • An additional 488.1 BTC in potentially related transactions has been identified, which could raise total exposure above $70 million.

Conclusion

The Coldcard Mk3 incident is a data point, not an indictment of self-custody as a concept. But it quantifies a risk that the Bitcoin ecosystem has treated as theoretical: hardware wallet firmware can ship with catastrophically weak entropy, remain undetected for years, and enable large-scale automated theft when eventually exploited.

The economic value at stake — $38.3 million confirmed, potentially $70 million — was concentrated among long-term holders who followed standard best practices of their era: buy a reputable hardware wallet, generate a seed, move Bitcoin to cold storage, wait. The failure was not user error. It was a vendor-side build configuration defect that no standard user action could detect.

For holders of material Bitcoin balances, the incident shifts the cost-benefit calculus around multisig, BIP-39 passphrases, and user-supplied entropy from optional hardening measures to baseline security requirements. For hardware wallet manufacturers, it raises questions about firmware validation pipelines, entropy audit mechanisms, and post-end-of-life customer notification obligations.

The 562 BTC consolidated at bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r remain unmoved. Whether they are recovered, laundered, or seized will determine the final chapter. The structural lessons, however, are already clear.

Sources & References

  1. Block Engineering Blog: Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware — Technical root-cause analysis from Block's Bitcoin Engineering and Security teams
  2. CoinDesk: Major Bitcoin Wallet Flaw Drains 594 BTC in 25-Minute Sweep — Breaking news coverage with on-chain data
  3. Atlas21: 594 Bitcoin Drained in Fifteen Minutes — What We Know — Detailed on-chain forensics including address composition and timeline
  4. Cryptopolitan: Coldcard Flaw Sparks Fears After $38M Bitcoin Wallet Drain — Industry reaction and Coinkite response details
  5. CryptoSlate: A Flaw in Coldcard Seed Generation Lets Attackers Recreate Private Keys — Self-custody implications analysis
  6. TFTC: Coldcard Mk3 RNG Warning — 594 BTC Swept — NVK and Rob Hamilton statements
  7. TRM Labs: H1 2026 Crypto Hacks Reach Record High — H1 2026 crypto security incident data
  8. Blockaid via The Block: Crypto Hacks Hit Record High in H1 2026 — 212 verified exploits, operational security failure statistics