
Coldcard Hardware Wallet Flaw Exposed Private Keys, 1,367 BTC Drained
A firmware bug in Coldcard's random-number generator allowed attackers to reconstruct private keys, resulting in 1,367 BTC stolen across 4,585 addresses in three separate attack waves. The vulnerability exposed a critical weakness in how the hardware wallet generated cryptographic material.
Key Takeaways
- 1## The Vulnerability and Attack Pattern A flaw in Coldcard's PRNG (pseudo-random number generator) firmware permitted attackers to derive private keys from wallets using the affected hardware.
- 2According to reports, 1,367 BTC was stolen from 4,585 addresses over three distinct attack campaigns.
- 3The vulnerability appears to have allowed reconstruction of the cryptographic seeds that underpin private key generation, bypassing the isolation that hardware wallets are designed to provide.
- 4## Scope of Impact The breach touched a substantial segment of Coldcard users.
- 5The three-wave attack pattern suggests either progressive discovery of the flaw by malicious actors or systematic exploitation over time.
The Vulnerability and Attack Pattern
A flaw in Coldcard's PRNG (pseudo-random number generator) firmware permitted attackers to derive private keys from wallets using the affected hardware. According to reports, 1,367 BTC was stolen from 4,585 addresses over three distinct attack campaigns. The vulnerability appears to have allowed reconstruction of the cryptographic seeds that underpin private key generation, bypassing the isolation that hardware wallets are designed to provide.
Scope of Impact
The breach touched a substantial segment of Coldcard users. The three-wave attack pattern suggests either progressive discovery of the flaw by malicious actors or systematic exploitation over time. Each address drained represents a complete compromise of that wallet's security model — the attacker gained full access to move funds without the owner's authorization or knowledge.
Industry Context
Hardware wallets are marketed as air-gapped security tools that isolate private keys from internet-connected machines. A PRNG flaw that permits key reconstruction strikes at the core of that value proposition. Users who believed their Coldcard protected them from exchange hacks, malware, and phishing attacks were exposed to a vulnerability originating in the device firmware itself.
Why It Matters
For Traders
Stolen Bitcoin from compromised Coldcard wallets may surface on exchanges in coming weeks, adding downward pressure on spot price if dumped in volume.
For Investors
Hardware wallet trust is foundational to crypto custody; a PRNG flaw affecting thousands of wallets signals broader supply-chain security risks in consumer hardware.
For Builders
Projects integrating with Coldcard or similar HSM-based key derivation should audit their entropy assumptions and consider firmware verification checkpoints in their workflows.





