A code bug in Coldcard hardware wallets reportedly went unnoticed for years and has been linked to roughly $100 million in hacked funds, raising fresh questions about how self-custody Bitcoin devices are audited and disclosed.
The flaw traces to how affected Coldcard firmware generated randomness for seed creation, according to research from Block’s engineering team, which described a predictable random-number-generator fallback and a 32-bit reseed in the device’s firmware. A weak or predictable seed matters because it is the root of a wallet’s private keys, meaning an attacker who can reproduce the randomness could reconstruct keys and drain funds. For related coverage, see Harvard University Reports $101.3M Stake in BlackRock Bitcoin ETF.
Coldkite, the maker of Coldcard, has published a seed generation warning for the Coldcard Mk3, flagging the affected devices and urging users to take precautions. The scale of the alleged losses was detailed in reporting that described how the bug went undetected before being tied to the hacked funds.
Why the flaw stayed hidden for years
The defining feature of the story is duration: the issue reportedly persisted across firmware versions without being caught in routine review or testing. A predictable seed does not produce visible symptoms for a user, so wallets created on affected devices would have looked and worked normally. For related coverage, see Treasury GENIUS Act Rule Targets Offshore Stablecoins.
That invisibility is precisely why late discovery is troubling. It suggests the weakness escaped both internal checks and external scrutiny for an extended period, which is the point Block’s researchers documented when they traced the RNG fallback behavior in the firmware.
The reports of stolen coins align with a string of thefts already documented among Coldcard holders, including accounts of Coldcard users reporting 594 BTC stolen and subsequent claims that more Coldcard hacks left 1,596 BTC allegedly taken.
What it means for Bitcoin self-custody users
Coldcard is closely associated with Bitcoin self-custody, so a flaw tied to a nine-figure loss carries outsized weight for how holders judge hardware trust. The severity is measured less by any single theft than by the aggregate figure now attached to the bug.
For affected users, the immediate concern is whether their seed was generated on vulnerable firmware, which is the specific scenario Coinkite’s warning addresses. The episode has also fed a broader push toward tighter safeguards, reflected in the self-custody security overhaul that the Coldcard hack has sparked.
The wider takeaway concerns auditing and disclosure. As NYDIG research on what the Coldcard exploit means for Bitcoin custody frames it, incidents rooted in seed generation strike at the foundation of key security, where trust in the device is the whole proposition.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
