Summary

A firmware integration error in Coldcard hardware wallets, persisting from March 2021 to July 2026, prevented the intended hardware random-number generator from contributing properly to seed creation. A MicroPython software fallback supplied predictable output, reducing effective search space from 128 bits to ~40 bits for affected Mk2/Mk3 models. Galaxy Research identified three attack waves draining 1,367.05 BTC (~$88.6M) from 4,585 addresses. The incident has triggered the largest surge in sub-1 BTC Bitcoin transfers since the FTX collapse.

Key Points

Sources

Powered by Forestry.md