coldcard, what actually happened
- ~1,367 BTC was swept from 4,585 addresses, worth roughly $89m at the time.
- this was not AI or brute force. the affected seeds were generated with weak, predictable randomness.
- the bug came from a 2021 firmware path. @COLDCARDwallet intended to use hardware randomness, but a configuration check routed seed generation through a non-cryptographic PRNG instead.
- that means attackers could recreate candidate seeds, rather than guess a true 128/256-bit BIP-39 seed.
- Mk2/Mk3 were most exposed. Mk4/Mk5/Q were also affected, although researchers disagree on exactly how much entropy remained.
- firmware updates alone are not enough. if your seed was generated under affected firmware, you need a new seed and must move funds.
- the key lesson here is that air-gapped ≠ trustless. keeping a wallet offline does nothing if the key was weak from the moment it was created.
- open source also did not save users. the bug sat publicly visible for years without being caught.
https://x.com/arndxt_xo/status/2084212758544089258
Post #4651
597