Find notable cyber news and cases, enriched with sources, timelines, and signals.

Coldcard seed-generation PRNG actively exploited security flaw

Vulnerability
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

Coldcard hardware wallet firmware carried a seed-generation flaw that used a deterministic software PRNG instead of the STM32 hardware RNG, enabling offline reconstruction of candidate seeds for affected wallets. The flaw was linked to a July 30 Bitcoin sweep that drained 1,196 addresses and about 1,082.65 BTC. Coinkite shipped emergency firmware on July 31, but existing seeds created on vulnerable builds still need to be replaced.

Related Happenings

Wallet software weak recovery-phrase generation actively exploited security flaw

Vulnerability
H score31 First: 10.07.2026 12:00 Last: 10.07.2026 12:00 Sources 1

About this happening: Coinspect disclosed Ill Bloom, a weak-randomness recovery-phrase flaw in crypto wallet software that is actively exploited and can let attackers derive wallet addresse...

FatFs seven vulnerabilities (CVE-2026-6682)

Vulnerability
H score28 First: 03.07.2026 23:19 Last: 03.07.2026 23:19 Sources 1

About this happening: runZero disclosed seven vulnerabilities in FatFs, including CVE-2026-6682, exposing embedded devices to memory corruption, code execution, crashes, data leakag...

Timeline

  1. 01.08.2026 20:17 1 articles · 1h ago

    1,196 Bitcoin addresses are drained in a 41-minute sweep

    Victim Impact Update

    An attacker drains 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. The sweep is tied to Coldcard seed generation exposure and represents the direct financial impact on affected wallet holders.

    Show sources
  2. 01.08.2026 20:17 1 articles · 1h ago

    Coinkite ships emergency firmware for affected Coldcard models

    Mitigation Patch Update

    Coinkite ships emergency firmware for every affected model and release track on July 31, but installing it does not repair an existing seed. Owners with exposed seeds are told to generate a new one on patched firmware and move their coins, because the old seed can carry the weakness forward.

    Show sources
  3. 01.08.2026 20:17 2 articles · 1h ago

    Galaxy Research ties the Bitcoin sweep to a Coldcard seed-generation flaw

    Initial Disclosure

    Galaxy Research maps the sweep to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Coinkite, and Block explains that an attacker who can constrain device UID, timer state, and prior RNG-call history can reproduce candidate output streams offline. The analysis says libngu bound the build to MicroPython's Yasmarang fallback, the fallback was seeded from the chip's unique ID and timer registers, and candidate seeds can be checked against public blockchain data.

    Show sources