Coldcard seed-generation PRNG actively exploited security flaw
Vulnerability
Updated: 01.08.2026 20:17
· First: 01.08.2026 20:17
· 📰 1 src / 1 articles
· H score: 35
Coldcard hardware wallet firmware carried a seed-generation flaw that used a deterministic software PRNG instead of the STM32 hardware RNG, enabling offline reconstruction of candidate seeds for affected wallets. The flaw was linked to a July 30 Bitcoin sweep that drained 1,196 addresses and about 1,082.65 BTC. Coinkite shipped emergency firmware on July 31, but existing seeds created on vulnerable builds still need to be replaced.