{
  "id": 1247470,
  "title": "Coldcard’s Entropy Bug Exposed a Hidden Weakness in Hardware Wallet Security",
  "url": "https://urgent.news/2026/08/16/coldcards-entropy-bug-exposed-a-hidden-weakness-in-hardware-wallet",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-16T09:24:13.000Z",
  "source": {
    "name": "HackerNoon",
    "slug": "hackernoon",
    "url": "https://hackernoon.com/coldcards-entropy-bug-exposed-a-hidden-weakness-in-hardware-wallet-security?source=rss"
  },
  "original_language": "en",
  "account": "Coldcard is a hardware wallet renowned for its security, but a bug in its firmware exposed a hidden vulnerability. The bug, introduced on March 1, 2021, caused the device to use a software pseudorandom number generator instead of its hardware RNG for seed generation. This flaw allowed attackers to drain $89 million from 4,585 wallets without physical access. The issue was due to a single code change that overlooked verification of a configuration macro, leading to a silent link to the wrong implementation. Attackers exploited this by reconstructing seeds offline and deriving addresses, bypassing the need to physically access devices. Coinkite, Coldcard's manufacturer, released emergency firmware to fix the issue, but it's important to note that updating existing firmware won't restore security for seeds already generated. The incident highlights that self-custody security isn't solely determined by the device itself, but also by the firmware, libraries, and code review processes. As a result, hardware wallet users must consider not just the device but the entire code stack that generates their keys.",
  "summary": "A 2021 firmware bug collapsed Coldcard's seed entropy from 128 bits to 40. Five years later, an attacker drained $89M in Bitcoin across 4,585",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}