COLDCARD RNG Flaw Tied to Major Bitcoin Theft
🔒 Researchers attribute an exploit in COLDCARD hardware wallet firmware to the theft of roughly $88.6 million in Bitcoin from thousands of wallets generated with a flawed random number generator. Galaxy Research traced initial drains of about 1,083 BTC on July 30 and later identified further waves raising the total to 1,367 BTC taken from 4,585 addresses. Block and other analysts found an integration error that caused a deterministic MicroPython fallback RNG to be used instead of the STM32 hardware RNG, enabling offline seed reconstruction and address matching.
