CoinWorld reported:
A code flaw in the Coldcard hardware wallet has recently been linked to a large-scale Bitcoin theft. According to CoinDesk, Galaxy Research estimates that attackers have stolen 1,596 Bitcoins from approximately 7,300 addresses, amounting to over $100 million at the time of the incident.
The incident has drawn attention because Coldcard has always marketed itself on the basis of offline signing and open-source code. Several users believe that even if the device was never connected to the internet and the mnemonic phrases were stored separately, funds could still be at risk due to flaws in the seed generation process.
Impact Exceeds a Thousand Bitcoins
Reports indicate that one of the victims, Jonathan Goodman, stated he lost all his wallet assets on July 29, totaling 18.25 Bitcoins, worth about $1.17 million. Alex Thorn, research director at Galaxy Research, mentioned on August 4 that at least 15 attackers were exploiting this flaw without needing to access the users' devices directly.
The security of hardware wallets relies on the randomness of the private key or mnemonic phrase generation process, ensuring that secrets do not leave the chip. If randomness is insufficient, attackers can narrow down their guesses and deduce wallet seeds in bulk.
The Issue Lies in the Seed Random Number Source
Reports indicate that the vulnerability does not lie in Coldcard's offline signing process itself, but in the random number generation during wallet creation. Coldcard was supposed to call the device's built-in hardware random number generator, but a configuration error caused the system to use a weaker software random number source instead.
This software source relies on inputs like device information and time data, resulting in significantly weaker randomness compared to dedicated hardware solutions. As a result, the seed space, which should be nearly impossible to exhaustively search, was greatly compressed, allowing attackers to attempt and recover wallet seeds within a smaller range.
Vulnerability Allegedly Entered the System After 2021 Code Changes
CoinDesk cites Bitcoin developer James O'Beirne, who claims this issue may have arisen after a major firmware rewrite of Coldcard in 2021. At that time, Coinkite released version 4.0.0, calling it "new code" and introducing a new source library, libngu.
O'Beirne stated that during a code audit in May 2025, he raised concerns about the random number generation process and reported potential flaws to Coinkite. Reports indicate that the company responded at the time by stating that if the issue were real, it would have been discovered long ago.
Subsequently, researchers continued to trace the code path and believed that Coldcard encountered a software communication error when reading the relevant settings, causing the weaker random source, which should have been disabled, to continue being called. Given that Coldcard's code is public, this incident has reignited discussions in the market about "open source does not equal audited."
From an industry perspective, this incident undermines users' perception of hardware wallets as being "naturally insulated from network risks." Even if the device remains offline, if there are flaws in the key generation process, attackers may still launch attacks without accessing the device.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























