Unchained · Friday, August 7, 2026
A significant vulnerability in the Coldcard hardware wallet, stemming from flawed entropy (randomness) generation, has been discovered. This issue dates back to 2021 and has potentially compromised private keys for users over the past five years, leading to ongoing fund drains.
“So, um, for those of you who are not aware, I'm going to, I'm going to hand this over to Tain in a second to give us the full, uh, full debrief here, uh, because she's been deep in in this, but, uh, cold card, uh, is a hardware wallet, uh, one of the minor hardware wallet, uh, players out there.”
“Yeah, so the most, I guess basic way I can put this is that, uh, one of the critically important jobs of the wallet is to generate a secure private key or seed phrase. And the way that you do that is with the thing called entropy, which is just randomness. It's just, but it has to be like, truly random.”
“And so, like, this is, this is not even like profanity was another one. Uh, there's been a ton of them, right? Like these things.”
“First off, it's cold card is a hardware wallet. So they screwed up this, uh, the way that they are getting randomness, they screwed it up in 2021. It, uh, that in the code base, it was used for five years before someone discovered it.”
“It's basically, like, six days ago, seven days ago now. Um, it's been a free for all since. Because there's basically five years of seeds and private keys that that the various attackers are basically mining.”