# Coldcard's RNG Bug Has Reportedly Compromised More Than 1,750 BTC *Author: Bankless* *Published: Aug 3, 2026* *Source: https://www.bankless.com/es/read/news/coldcards-rng-bug-has-reportedly-compromised-more-than-1-750-btc* --- A five-year-old firmware flaw in Coinkite's Coldcard hardware wallets has let attackers reconstruct Bitcoin private keys entirely offline, and the toll keeps climbing. Coinkite [confirmed the bug](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/) traces back to a March 2021 firmware error, and Galaxy Research has estimated that the vector has led to +1,750 BTC (well over $100M) drained from ~5,000 addresses across multiple attack waves since July 30th. ## **What's the Scoop?** - **The bug:** A 2021 build error meant Coldcard's firmware only checked whether a hardware-RNG flag existed rather than whether it was actually enabled, silently routing seed generation through MicroPython's deterministic Yasmarang fallback instead of the true hardware random number generator (RNG). - **Big problem:** Because of the RNG flaw, effective entropy collapsed from a targeted 128 bits to roughly 40 bits on Coinkite's Mk2/Mk3 devices and about 72 bits on Mk4/Mk5/Q devices. This narrowing was enough for an attacker to brute-force candidate seeds offline and match them against public blockchain addresses. - **Four waves & counting:** The [first sweep](https://x.com/glxyresearch/status/2083181683067506899) hit July 30th, draining +1,082 BTC from nearly 1,200 addresses in under an hour. The [second](https://x.com/glxyresearch/status/2083560940469981591) and [third waves](https://x.com/glxyresearch/status/2083623500183421043) followed through August 1st, pushing the confirmed total to 1,367 BTC (~$89M) from 4,585 addresses. A [suspected fourth wave](https://x.com/intangiblecoins/status/2084079706320646300) began yesterday, August 2nd, and added roughly 449 more BTC from about 700 addresses. That is Galaxy Research's running tally, though, and unconfirmed by Coinkite for now. - **Fix risks:** Coinkite shipped patched firmware for every model line within two days, but updating does nothing to repair a seed already generated under the flaw, so funds still have to migrate to a brand new address. Complicating that, users and Casa co-founder Jameson Lopp have reported devices [bricking during Coinkite's new update](https://x.com/lopp/status/2083958797354127631), leading Lopp to recommend moving funds off a weak seed before touching the firmware at all. - **Zooming out:** Crypto's scramble to reckon with AI as a weapon *and *a shield continues. The new paradigm means hackers can use frontier models to find years-old flaws for a couple of dollars of compute, while builders can now prep their defenses just as cheaply. Expect more cat-and-mouse dynamics as the race for supremacy here continues. For example, the Bitcoin bridge Boltz just [temporarily disabled swaps](https://x.com/Boltzhq/status/2084311537502630319), citing a sharp rise in AI-assisted probing that its small team couldn't keep pace with. --- *This article is brought to you by [NEAR](https://www.bankless.com/es/sponsor/near-1785257427?ref=read/news/coldcards-rng-bug-has-reportedly-compromised-more-than-1-750-btc)*