TL;DR
- What: A build-configuration error in Coldcard firmware, introduced in March 2021, silently routed BIP-39 seed generation to MicroPython's deterministic Yasmarang PRNG instead of the STM32 hardware RNG.
On July 30, 2026, a single attacker drained 1,196 Bitcoin addresses in 41 minutes, moving 1,082.65 BTC worth roughly $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware defect in Coldcard, the Bitcoin-only hardware wallet built by Canadian firm Coinkite. The flaw had been shipping since March 2021.
Questions about your exposure?
RedEye Security provides assessments for organizations that need to understand their real risk.
Talk to us