A firmware vulnerability in Coldcard hardware wallets has led to the theft of roughly $88.6 million in Bitcoin This article explores firmware vulnerability coldcard. . Hackers exploited an insecure random number generator, enabling them to recover victims' private keys without ever accessing their devices.

Digital asset research firm Galaxy Research flagged unusual activity on July 30, when a thief drained about 1,082.65 BTC from 1,196 addresses within a brief period of just 41 minutes. Unlike most hardware wallet attacks, which usually involve phishing, malicious firmware installation, or physical access to the device, this exploit targeted the wallet creation process itself.

The payments firm Block’s Bitcoin Engineering and Security teams traced the issue back to a code change made on March 1, 2021, that caused Coldcard's production configuration to disable the STM32 hardware random number generator. A faulty check in the libngu library only verified whether a configuration macro was defined without checking if it was enabled, leading the system to default to MicroPython’s deterministic Yasmarang software generator, which was seeded with the device’s unique ID and timer state. Affected users are advised to install the patched firmware, generate a new seed, verify the new address on their device, send a small test transaction, and then immediately migrate their remaining funds.

Enhance your Security Operations Center (SOC) by accelerating threat detection and rapid investigation with ANY.RUN integration.