A firmware flaw in COLDCARD hardware wallets caused the device to use a deterministic software random number generator (Yasmarang fallback) instead of the STM32 hardware RNG. This allowed attackers to reconstruct wallet seeds offline, identify matching Bitcoin addresses on the blockchain, and drain funds. An estimated $88.6 million in Bitcoin was stolen from 4,585 addresses across multiple attack waves. Affected firmware spans Mk2/Mk3 versions 4.0.1–4.1.9 and various Mk4, Mk5, and Q versions before recent patches. Firmware updates are available but do not repair previously generated seeds — affected users must generate new seeds and migrate funds. Seeds supplemented with at least 50 dice rolls are not considered at risk from this flaw alone.
10.4K Impressions1 Comment