← Front page

Unchained · Friday, August 7, 2026

Coldcard Wallet Vulnerability Linked to Flawed Entropy Generation

A significant vulnerability in the Coldcard hardware wallet, stemming from flawed entropy (randomness) generation, has been discovered. This issue dates back to 2021 and has potentially compromised private keys for users over the past five years, leading to ongoing fund drains.

personTain MonahancompanyColdcard

The tape

5 quotes
So, um, for those of you who are not aware, I'm going to, I'm going to hand this over to Tain in a second to give us the full, uh, full debrief here, uh, because she's been deep in in this, but, uh, cold card, uh, is a hardware wallet, uh, one of the minor hardware wallet, uh, players out there.
Host
Yeah, so the most, I guess basic way I can put this is that, uh, one of the critically important jobs of the wallet is to generate a secure private key or seed phrase. And the way that you do that is with the thing called entropy, which is just randomness. It's just, but it has to be like, truly random.
Tain Monahan
And so, like, this is, this is not even like profanity was another one. Uh, there's been a ton of them, right? Like these things.
Tain Monahan
First off, it's cold card is a hardware wallet. So they screwed up this, uh, the way that they are getting randomness, they screwed it up in 2021. It, uh, that in the code base, it was used for five years before someone discovered it.
Tain Monahan
It's basically, like, six days ago, seven days ago now. Um, it's been a free for all since. Because there's basically five years of seeds and private keys that that the various attackers are basically mining.
Tain Monahan
Heard on Unchained — “Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money, published Friday, August 7, 2026. Heardvine summarizes and quotes with attribution and timestamps, and links to the original everywhere.
Transcribed via Gemini audio transcription · $0.06