Approximately 1,083 BTC — roughly $70.2 million — was swept from 1,196 addresses in a single 41-minute wave on July 30, a pattern Galaxy Research says was “signature” evidence of an automated tool exploiting a vulnerability in COLDCARD hardware wallet firmware.
What Galaxy Research and Chainalysis observed
Digital asset research firm Galaxy Research identified an initial wave of transactions on July 30 that it linked to the firmware vulnerability, noting uniform transaction characteristics that pointed to automation. "Signature: every sweep paid an identical hardcoded 30.0 sat/vB — a 30-75x overpay vs the 0.4-1.0 sat/vB median that week — and left no change output," explained Galaxy, adding: "That looks like an automated tool spending keys it already held, not owners moving funds."
Galaxy later identified a second and third wave on August 1, raising its estimate of stolen Bitcoin to 1,367 BTC, worth approximately $88.6 million, taken from 4,585 addresses. Galaxy reported that the stolen Bitcoin remained in attacker-controlled addresses at the time of its report.
Chainalysis independently noted the attacker prioritized high-value wallets, taking approximately $30 million in the first ten minutes and removing $1.8 million from a single victim, an observation the company said suggested the attacker had identified and studied affected wallets before initiating the thefts.
How the COLDCARD RNG flaw operated, according to Block
Block's Bitcoin Engineering and Security teams — after examining reports of thefts tied to COLDCARD wallets — worked with other researchers to analyze COLDCARD firmware and trace the vulnerability. Block says the issue was an "RNG integration error" that caused ngu.random to use MicroPython's deterministic Yasmarang fallback instead of the STM32 hardware RNG.
COLDCARD firmware includes a separate hardware random number generator, but an incorrect check in the firmware meant the device used a deterministic software generator. Block reported that the fallback generator relied on the device's microcontroller identifier and system timing values, which it described as "not cryptographically secure sources of randomness and may be observable or reconstructable."
That weakness, Block explains, allowed attackers to generate possible wallet seeds offline, derive the corresponding Bitcoin addresses, and compare them with addresses visible on the blockchain. A match would confirm the correct seed and enable creation of the private keys needed to spend the funds.

Built by Nubivance.
OSINTSights' secure edge-first architecture, AI content pipeline, and serverless ops are designed by Nubivance. We do this for clients too.
Talk to us →Coinkite advisory, affected versions, and remediation guidance
Coinkite issued an advisory identifying affected seeds and listing firmware versions. Affected seeds include those generated on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9; Mk4 and Mk5 devices before standard version 5.6.0 or Edge version 6.6.0X; and Q devices before standard version 1.5.0Q or Edge version 6.6.0QX.
Coinkite released fixed firmware: version 4.2.0 or later for Mk2 and Mk3; 5.6.0 or later for standard Mk4 and Mk5 devices; 1.5.0Q or later for standard Q devices; and version 6.6.0X or 6.6.0QX for the corresponding Edge releases. The company emphasized that installing the fixed firmware does not repair a seed that was previously generated.
Coinkite's recommended migration steps for affected users are specific: verify the existing backup, install the fixed firmware, generate and securely record a new seed, verify the new wallet address on the device, send a small test transaction, then move the remaining funds. Coinkite also advised retaining the old backup until the migration is complete and confirmed.
The advisory notes that seeds supplemented with at least 50 fair, independent, and private dice rolls are not considered at risk from this flaw alone; a strong, unique BIP-39 passphrase "also makes it harder to exploit," but Coinkite still recommends migration because passphrases do not repair an affected seed.
Operational responses by Coinkite and immediate consequences
Coinkite said it destroyed all COLDCARD devices that were awaiting shipment with the affected firmware. Customers whose devices had already shipped were contacted by email with the security advisory and migration instructions.
Block reported that it disclosed its findings to Coinkite on July 30. Galaxy's timeline places the 41-minute attack approximately 30 hours before Coinkite publicly disclosed the flaw, underscoring the compressed window between exploitation and public advisory.
How technologists, affected customers, and investigators are likely to act
- Technologists and security teams: will weigh the Block analysis — that ngu.random used a deterministic Yasmarang fallback rather than the STM32 hardware RNG — to audit random number generation in firmware and similar integrations.
- Affected COLDCARD customers: are advised by Coinkite to follow its migration steps precisely — update firmware, create a new seed, verify addresses, and move funds after a test transaction — because installing fixed firmware alone does not remediate previously generated seeds.
- Investigators and blockchain analysts: will continue tracking the attacker-controlled outputs; Galaxy and Chainalysis reporting showed the attacker prioritized high-value wallets and left identifiable transaction signatures (30 sat/vB fee, no change outputs) consistent with automated sweeping tools.
The facts reported so far frame a narrow, high-impact exploit: a firmware integration error that produced predictable seeds, rapid automated sweeping of high-value addresses, and a remediation path that requires affected users to generate and migrate to new seeds even after applying updates. The stolen funds remained in attacker-controlled addresses at the time of reporting, and Coinkite's fixes and communications are focused on preventing new seed generation from being vulnerable while advising migration for any already-created seeds.
Source: BleepingComputer — COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft




