# Coldcard's RNG Bug Has Reportedly Compromised As Much As 2,000 BTC *Author: Bankless* *Published: Aug 3, 2026* *Source: https://www.bankless.com/fr/read/news/coldcards-rng-bug-has-reportedly-compromised-more-than-1-750-btc* --- A five-year-old firmware flaw in Coinkite's Coldcard hardware wallets has let attackers reconstruct Bitcoin private keys entirely offline, and the toll keeps climbing. Coinkite [confirmed the bug](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/) traces back to a March 2021 firmware error, and Galaxy Research has now estimated that 1,596 BTC (north of $100M) has been drained from roughly 7,300 addresses. Folding in a still-unconfirmed fourth wave pushes the all-in total toward 2,055 BTC, or ~$130M. > 🚨LOSSES FROM COLDCARD HACK EXCEED $100M High confidence 1,596 BTC has been stolen from ~7300 addresses across 3 confirmed waves + more 14 smaller incidents. If we add suspected (but unconfirmed), the total balloons to $130m (2k BTC).More in the thread below 👇 [pic.twitter.com/RAl3ib67qa](https://t.co/RAl3ib67qa)— Galaxy Research (@glxyresearch) [August 3, 2026](https://x.com/glxyresearch/status/2084411904924045370?ref_src=twsrc%5Etfw) ## **What's the Scoop?** - **The bug:** A 2021 build error meant Coldcard's firmware only checked whether a hardware-RNG flag existed rather than whether it was actually enabled, silently routing seed generation through MicroPython's deterministic Yasmarang fallback instead of the true hardware random number generator (RNG). - **Big problem:** Because of the RNG flaw, effective entropy collapsed from a targeted 128 bits to roughly 40 bits on Coinkite's Mk2/Mk3 devices and about 72 bits on Mk4/Mk5/Q devices. This narrowing was enough for an attacker to brute-force candidate seeds offline and match them against public blockchain addresses. - **Confirmed losses top $100M:** The [first sweep](https://x.com/glxyresearch/status/2083181683067506899) hit July 30th, draining +1,082 BTC from nearly 1,200 addresses in under an hour. The [second](https://x.com/glxyresearch/status/2083560940469981591) and [third waves](https://x.com/glxyresearch/status/2083623500183421043) followed through August 1st and 2nd. Galaxy Research has tallied losses of at least 1,596 BTC from ~7,300 addresses. A [suspected fourth wave](https://x.com/intangiblecoins/status/2084079706320646300) would add another ~449 BTC, pushing the total drained so far to 2,055 BTC (~$130M). Galaxy hasn't confirmed these additional losses yet, however. - **Recovery watch:** About 90% of all stolen funds [remain unmoved](https://x.com/glxyresearch/status/2084411918861652194), including all of the proceeds from the three confirmed waves. Galaxy is sharing attacker and victim addresses with U.S. federal law enforcement, exchanges, and compliance firms, and is asking confirmed or suspected victims to DM Galaxy's Alex Thorn ([@intangiblecoins](https://x.com/intangiblecoins)) with drained addresses and attacker TXIDs to help with tracing. - **Fix risks:** Coinkite shipped patched firmware for every model line within two days, but updating does nothing to repair a seed already generated under the flaw, so funds still have to migrate to a brand new address. Complicating that, users and Casa co-founder Jameson Lopp have reported devices [bricking during Coinkite's new update](https://x.com/lopp/status/2083958797354127631), leading Lopp to recommend moving funds off a weak seed before touching the firmware at all. - **Zooming out:** Crypto's scramble to reckon with AI as a weapon *and* a shield continues. The new paradigm means hackers can use frontier models to find years-old flaws for a couple of dollars of compute, while builders can now prep their defenses just as cheaply. Expect more cat-and-mouse dynamics as the race for supremacy here proceeds. For example, the Bitcoin bridge Boltz just [temporarily disabled swaps](https://x.com/Boltzhq/status/2084311537502630319), citing a sharp rise in AI-assisted probing that its small team couldn't keep pace with. --- *This article is brought to you by [NEAR](https://www.bankless.com/fr/sponsor/near-1785257427?ref=read/news/coldcards-rng-bug-has-reportedly-compromised-more-than-1-750-btc)*