Random Number Generator Flaw in COLDCARD Wallets Drains $88 Million in Bitcoin

A critical vulnerability in COLDCARD hardware wallet firmware enables attackers to steal approximately 1,367 Bitcoin worth $88.6 million from 4,585 addresses. Digital asset research firm Galaxy Research identifies multiple waves of transactions beginning on July 30, with the entire attack lasting just 41 minutes and starting roughly 30 hours before Coinkite publicly discloses the flaw.

Block's Bitcoin Engineering and Security teams trace the issue to an integration error in COLDCARD's random number generation code. The firmware incorrectly falls back to MicroPython's deterministic Yasmarang generator instead of using the STM32 hardware RNG, making wallet seeds predictable and allowing attackers to reconstruct private keys for affected addresses.

Chainalysis reports that the attacker prioritizes high-value wallets, stealing $30 million within the first ten minutes and targeting specific victims in advance. Every sweep transaction uses an identical hardcoded fee rate of 30 sat/vB and leaves no change output, indicating an automated tool rather than legitimate owner activity.

Read More at the original source →