An attacker depleted 1,196 Bitcoin addresses in just 41 minutes on July 30th, siphoning off approximately $70.2 million worth of cryptocurrency at that time This article explores device coinkite calculates. . A March 2021 update to the firmware included an error that redirected seed generation to a deterministic software pseudorandom number generator (PRNG) rather than utilizing the secure STM32 hardware random number generator (RNG).

The block suggests that an attacker, capable of deducing or controlling the device's Unique ID (UID), time state, and previous Random Number Generator (RNG) calls, can reproduce candidate output streams offline without needing to interact with the actual device.

Coinkite calculates an effective entropy level ranging from about 40 bits for the Mk3 to around 72 bits for the Mk4, Mk5, and Q variants compared to 128 bits for a BIP-39 seed. The reseed feature increases the number of candidates, though Block notes practical cost factors such as available UID information, boot timing, prior RNG calls, and derivation costs. The company warned that this pattern identifies the operator rather than the theft since "a sweep appears identical to if an owner chose to move coins."

This disclosure follows Coinspect's Ill Bloom research in July, which revealed a separate weak-PRNG flaw affecting older software wallets, leading to over $5 million being drained from addresses across Bitcoin, Ethereum, Tron, Rootstock, and Polygon since May.