logo
  • menu
  • Markets
  • ETFs
  • Live
  • Spot
  • Futures
  • Bots
  • Learn
  • Sign In
  • Sign Up
  • Downloads
  • English
  • |
  • USD
  • |
Sign Up
Crypto PricesLearnLatest NewsDownloadsMarketsSpotAnnouncements
Home/
Latest News/
Live

Coldcard Bitcoin Exploit Explained: Entropy, How Keys Are Generated, and Why Bits Matter

By Decrypt
Aug 5, 2026
4.5 
★
★
★
★
★
★
★
★
★
★
 291 User Rating
Share

Somebody has been emptying Bitcoin wallets that were never supposed to be reachable.

The coins sat on Coldcard devices—hardware wallets from Canadian manufacturer Coinkite, the kind that never touch the internet. No phishing link. No malware. No stolen laptop. The attackers simply worked out what the private keys were.

Galaxy Research has now tracked more than 1,596 BTC stolen across three confirmed waves, with a suspected fourth wave that would lift the total to roughly 2,055 BTC—about $130 million at current prices. One sweep moved $70 million in 41 minutes. Coinkite says at least 15 separate attackers have piled in.

Zero is still something

In 2021, Coinkite moved Coldcard's cryptography onto libsecp256k1, the same library Bitcoin Core uses. Sound decision. The integration is where it fell apart.

The migration quietly rerouted seed generation away from Coldcard's own hardware random number generator and onto MicroPython's software fallback—a small algorithm called Yasmarang that exists for devices with no randomness chip at all.

LOSSES FROM COLDCARD HACK EXCEED $100M

High confidence 1,596 BTC has been stolen from ~7300 addresses across 3 confirmed waves + more 14 smaller incidents.

If we add suspected (but unconfirmed), the total balloons to $130m (2k BTC).

Coldcard has a randomness chip. It just stopped being asked.

The reason is almost too small to believe. A build guard used #ifndef, which checks whether a setting exists rather than whether it's switched on. Coinkite had defined that setting as zero, meaning "off." Because zero still counts as defined, the safety check passed and the build completed. Both versions of the function had identical signatures, so nothing looked wrong.

"The bulk of randomness on the COLDCARD was coming from a PRNG that I didn't know was actually in the source code base," Coinkite wrote, referring to a pseudo-random number generator—software that produces numbers that look random but follow a fixed recipe from a starting value.

Feed the recipe the same starting value and you get the same output. Every time.

On Mk2 and Mk3 devices running firmware 4.0.1 through 4.1.9, that starting value came from the chip's serial number and its clock. Coinkite estimates the resulting search space at about 40 bits. Newer models mixed in a little secure-element entropy, lifting them to roughly 72 bits.

Neither is 128, the target.

The gap matters more than it looks. Bits are exponents. A 128-bit search space holds more combinations than there are atoms in the observable universe, and nobody is searching it. Forty bits is about a trillion—a number a decent laptop can chew through. Each bit you lose halves the work.

And deterministic is the opposite of random, which is essential to cryptography.

Not "weak." Predictable.

Coinkite suspects it was found by machine. "We have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue," the company wrote, adding that it had recently run one of the best available AI models over the same code and turned up nothing. "Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys."

What entropy actually is

Entropy is the measure of how much an attacker doesn't know.

In other words, it's basically uncertainty, counted in bits. One bit is one coin flip: two outcomes, and a guesser gets it right half the time. Ten bits is 1,024 outcomes. Each bit doubles the guesser's workload.

A Bitcoin wallet is a very large number kept secret. The address people send coins to is derived from it mathematically, and the derivation runs one way only—you can go from key to address, but never back.

So the security of every wallet rests on one question: How many numbers would an attacker have to try?

If the number was picked with 128 bits of entropy, the answer is "more than physics permits." If it was picked with 40, the answer is "give me some time."

This is where the vocabulary gets slippery. A pseudo-random generator produces output that passes statistical tests for randomness, so basically nothing a spreadsheet would flag. That output is still fully determined by its seed value. It looks random but isn't.

Statistical randomness and cryptographic unpredictability are different properties, and Coldcard's output would have sailed through the first test while failing the second completely.

True randomness has to come from physical noise: electrical jitter in a circuit, thermal fluctuation, radioactive decay. That's what the hardware chip on the Coldcard was for. That's the chip the build flag disconnected.

Then Luke Dashjr brought up the dice

As users scrambled to regenerate seeds, many reached for the obvious low-tech fix. Coldcards let you roll physical dice and feed the results in as entropy. Coinkite's own guidance treats seeds made with at least 50 independent, private dice rolls as not at risk from the bug.

Bitcoin Twitter did not take it calmly.

should I hire someone with parkinsons to throw the dice?

"Overkill. A perfect d6 gives 2.585 bits per roll. A noticeably biased die, e.g. with one face landing 20% of the time instead of 16.7%, still gives about 2.55 bits. Across 99 rolls that's the difference between ~256 bits and ~252 bits of entropy."

Four bits out of 256. That's the whole penalty for a visibly unfair die.

Dashjr isn't wrong that cheap dice have measurable bias—injection-molded pips remove slightly different amounts of plastic from each face, which is precisely why casinos use flush-filled precision dice. He's right about the physics and wrong about the stakes. Losing four bits from 256 leaves you at 252. Coldcard's bug left users at 40.

There's a sharper argument buried in his advice, though, and it isn't about manufacturing tolerance. It's about not trusting any single source. Coldcard's failure wasn't that its entropy was slightly biased—it was that one component silently stopped contributing and nothing caught it.

What to do about it

If you generated a seed on an affected Coldcard without dice rolls (really) or a strong BIP-39 passphrase, that seed is compromised.

Update the firmware, generate a new seed, verify the fingerprint, send a test transaction, then move everything. Coinkite's advisory walks through it model by model. Exported seeds carry the flaw with them—moving a bad seed into a different wallet app doesn't solve anything.

For everyone else, the takeaway isn't that hardware wallets are broken or that dice are a trap.

It's that "random" is a claim, and claims need checking. Coldcard's source code was public the entire time. The intended hardware RNG was sitting right there in the binary. Reviewers confirmed it existed and never confirmed the seed generator actually called it.

Eight years of audits looked at the right code. Nobody checked whether it ran.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of BitKan. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. BitKan shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. Products mentioned in this article may not be available in your region.

Latest News

Industry

Cryptocurrency

Airdrop

Markets

  • Brazil’s CVM Launches 60-Day Sprint to Tokenize Securities

    Brazil’s CVM Launches 60-Day Sprint to Tokenize Securities

    The Brazilian Securities and Exchange Commission (CVM) has officially established a dedicated task force to develop an experimental regulatory framework for tokenized securities, providing a fast-tracked timeline for the digital capital market.
    Martha Grizzard
    Jul 21, 2026
  • Hyperliquid Enables Permissionless Markets With HIP-4 Plan

    Hyperliquid Enables Permissionless Markets With HIP-4 Plan

    Hyperliquid has announced a forthcoming enhancement to its HIP-4 upgrade that will allow for the permissionless deployment of decentralized prediction markets.
    Christopher Smith
    Jul 21, 2026
  • DTCC Launches Live Tokenized Asset Trading for Wall Street

    DTCC Launches Live Tokenized Asset Trading for Wall Street

    The DTCC successfully transitioned from pilot testing to live production trades on July 15, 2026, marking the largest-scale institutional tokenization initiative to date.
    Cornell Rachel
    Jul 16, 2026
  • South Korea Updates Asset Law to Include Cryptocurrency

    South Korea Updates Asset Law to Include Cryptocurrency

    The South Korean Ministry of Economy and Finance announced a transition from the 1950 State Property Act to a new National Asset Basic Act to better reflect modern digital resources.
    Martha Grizzard
    Jul 16, 2026
  • New SEC Crypto Rule to Cut Red Tape for Startup Fundraising

    New SEC Crypto Rule to Cut Red Tape for Startup Fundraising

    The U.S. Securities and Exchange Commission plans to introduce a major regulatory framework this month to simplify capital formation and reduce operational hurdles for cryptocurrency businesses.
    Martha Grizzard
    Jul 8, 2026
View more data 
BTCBTC(BTC)
$0
--(Last 24h)
SpotFutures

Top

View more
  1. 1S&P 500 Reclaims 200-Day Moving Average, Bitcoin Gains
  2. 2Trump Softens His Stance on Reciprocal Tariffs, US Stocks and Crypto Markets Rise
  3. 3Vitalik Buterin : The current price of ETH has not been affected by the merger event
  4. 4Vibhu Norby : Solana Spaces store to bring 100K people to Solana per month
  5. 5CZ: compared with the record high nine months ago, the current situation of the industry is much better

Top Gainers

View more
Squid
SquidQUID

$0.1012

+237.37%
Heima
HeimaHEI

$0.1810

+104.75%
Bless
BlessBLESS

$0.0194

+84.58%
Seeker
SeekerSKR

$0.009111

+38.97%
Synapse
SynapseSYN

$0.1217

+38.20%

Top Trending

View more
SpaceX
SpaceXSPCXB

$110.500

-4.86%
Sui Network
Sui NetworkSUI

$0.6914

-0.07%
DeXe
DeXeDEXE

$2.2940

+3.89%
Binance Coin
Binance CoinBNB

$597.230

+1.38%
Solana
SolanaSOL

$73.8600

+0.75%

Recently added

View more
Squid
SquidQUID

$0.1012

+237.37%
Qualcomm
QualcommQCOMB

$161.370

+5.31%
Corning
CorningGLWB

$157.930

+4.05%
Roundhill Memory ETF
Roundhill Memory ETFDRAMB

$53.0500

+2.02%
Grvt
GrvtGRVT

$0.3417

+29.64%

Learn

View more
  1. 1What Are ARC-20 Tokens? How Do ARC-20 Tokens Work?
  2. 2What Is the Usual Protocol? How Does Its Tokenomics Work?
  3. 3What Are AI Agent Frameworks? How Do They Power Cryptocurrency?
  4. 4What Is JPYSC? How Japan’s Regulated Stablecoin Works
  5. 5Are AI Agents Safe for Crypto? How to Secure Your Assets
About Us
  • About BitKan
  • Contact Us
  • Announcements
  • VIP Program
  • BitKan Ambassador
  • Institutional Services
Products
  • Spot
  • Futures
  • Crypto Prices
  • Learn
  • News
  • Markets
  • How to Buy Crypto
  • BTC to USD Calculator
  • Reward
Help
  • Help Center
  • Email Us
  • Live Chat
  • Download APP
  • Listing Application
  • Buy Bitcoin
  • Buy Ethereum
  • Buy Dogecoin
  • Buy Altcoins
Terms
  • Terms of Use
  • Privacy Policy
  • Trading Rules
  • Fee
K-Site
English
About Us
+
  • About BitKan
  • Contact Us
  • Announcements
  • VIP Program
  • BitKan Ambassador
  • Institutional Services
Products
+
  • Spot
  • Futures
  • Crypto Prices
  • Learn
  • News
  • Markets
  • How to Buy Crypto
  • BTC to USD Calculator
  • Reward
Help
+
  • Help Center
  • Email Us
  • Live Chat
  • Download APP
  • Listing Application
  • Buy Bitcoin
  • Buy Ethereum
  • Buy Dogecoin
  • Buy Altcoins
Terms
+
  • Terms of Use
  • Privacy Policy
  • Trading Rules
  • Fee
K-Site
+
  • Twitter
  • Facebook
  • Telegram
  • YouTube
  • Instagram
  • Medium
  • Linkedin
@2012-2026 BITKAN.com