Unchained · Tuesday, August 4, 2026
A systemic flaw related to entropy and key generation in Coldcard Mark 3, 4, and 5 hardware wallets has led to a significant drain of Bitcoin from over a thousand wallets. The exploit is believed to stem from a miswired random number generator in a firmware update from March 17th, 2021, which failed silently and led to the use of a weaker entropy source for key generation.
“So Coldcard was a hardware wallet, largely marketed in some places as the gold standard in the Bitcoin ecosystem, and it had a deep systemic flaw.”
“So an exploit tied to entropy, aka key generation, Coldcard Mark 3, Mark 4, Mark 5, had Bitcoin drained from, I believe, well over a thousand wallets at this point, and the reported total has been climbing throughout the week, up, up, up, up.”
“When you generate cryptographic keys, you need entropy. Um, you need a random number generator to seed the key generation with randomness, which is what makes it difficult to brute force attack.”
“And Coldcard had updated their firmware on March 17th, 2021, to add their own version of a random number generator. And it's not even that that version wasn't good, they miswired it into the firmware, um, such that it would fail.”