Coldcard PRNG Flaw Lets Attackers Reconstruct Private Keys: 1,367 BTC Drained
A crypto hack targeting a firmware flaw in the Coldcard Bitcoin hardware wallet has drained at least 1,367 BTC, worth approximately $86M at current prices, from more than 4,500 cold storage addresses across three waves of attacks.
The exploit never required physical access to a single device; it rebuilt private keys from scratch using mathematics.
Galaxy Research: Three Suspected Attacks on Coldcard-Generated Addresses Drain 1,367 BTC Galaxy Research said its Bitcoin on-chain analysis identified three suspected attack waves targeting addresses generated by Coldcard, involving 4,585 addresses and a total of 1,367.05 BTC… pic.twitter.com/JdSz4W1TIk — Wu Blockchain (@WuBlockchain) August 1, 2026 The central problem: Bitcoin self-custody promises that a key stored offline is unreachable.
This attack proved that an unreachable key can still be unguessable, or not.
This page shows the RSS-provided summary/preview. Full publisher content remains available at the original source.