bleeping-computer · Crawled Aug 2, 2026
COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
1 IoCs
Read original article ↗
AI Summary
A vulnerability in COLDCARD hardware wallet firmware related to improper random number generation (RNG) has been exploited to steal approximately $88.6 million in Bitcoin from thousands of wallets. The flaw caused the device to use a deterministic software RNG instead of the intended hardware RNG, allowing attackers to predict wallet seeds offline and steal funds. The attack occurred in multiple waves, with transactions showing signs of automation, such as identical fee rates and no change outputs. Affected firmware versions span several COLDCARD models, and users are advised to generate new seeds even after updating to patched firmware.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | ngu.random | Details → |