Coldcard crisis hits $130 million – proving ‘not your keys’ is meaningless if you trust a single device to generate them

NewsTue, 04 Aug 2026 09:50:20 UTC2 hours ago
Coldcard crisis hits $130 million – proving ‘not your keys’ is meaningless if you trust a single device to generate them

Block's Bitcoin Engineering and Security team and independent Bitcoin Core developers have traced the recent batch of Coinkite Coldcard wallet losses to a specific firmware defect that exposed a hidden weakness in Bitcoin self-custody before any user touched a seed phrase.

The bug diverted the device's random-number generation from its STM32 hardware source to MicroPython's deterministic Yasmarang fallback.

Mk2 and Mk3 devices running firmware 4.0.1 through 4.1.9 produced seeds whose cryptographic randomness collapsed into a small, searchable set.

Mk4, Q, and Mk5 models were less severely affected, producing seeds with about 72 bits of entropy, still well under the 128 bits specified by the design.

Related Reading

Coldcard’s $89M wallet bug triggers the biggest Bitcoin movement since FTX and completely distorts market signals

More than 77,000 BTC moved from older wallets as users raced to secure funds, complicating bearish readings across key on-chain indicators.
Aug 2, 2026 · Oluwapelumi Adejumo

How weak seeds compromised Bitcoin self-custody

A user could write down twelve or twenty-four words, store them in a safe, keep the device offline for years, and still hold a key an attacker could reconstruct by searching the fallback generator's narrow output space.

… Continue reading the full article at the original source below.

Read from Source · cryptoslate.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (cryptoslate.com).

Related