Coldcard’s Five-Year Vulnerability: RNG Failure, Four Suspected Attack Waves, and the Self-Custody Debate A random number generation flaw introduced during a 2021 code migration weakened wallet seeds created by several Coldcard models and firmware versions for nearly five years.
The affected firmware used a predictable software pseudorandom number generator instead of the intended hardware source, reducing the estimated search space to roughly 40 bits on Mk2 and Mk3 devices and about 72 bits on later models
Updating the firmware or importing an affected mnemonic into another wallet cannot repair the seed; users must generate a new seed with patched firmware or another trusted environment and transfer their funds. Galaxy Research has identified four suspected attack waves involving an estimated 5,294 addresses and 1,815.75 BTC. The figures are based on on-chain transaction patterns and do not represent individually verified victims or confirmed final losses.
The incident reflects a key-generation failure in specific Coldcard firmware, rather than a compromise of Bitcoin’s underlying cryptography. — link