The production configuration defined the hardware-RNG macro as zero, while the underlying libngu library checked whether the macro existed rather than whether it was enabled, binding the build to MicroPython's Yasmarang fallback.
The MicroPython fallback was initialized from chip unique identifiers and timer registers and did not collect fresh entropy after initialization. Block said an attacker able to determine or sufficiently constrain the device UID, timer state and prior RNG-call history could reproduce candidate output streams offline, then derive addresses and compare them with public blockchain data.
Coinkite estimated effective entropy for affected seeds at roughly 40 bits on Mk3 hardware and about 72 bits on Mk4, Mk5 and Q models, compared with 128 bits for a 12-word BIP-39 seed. The practical cost of reproducing seeds depends on available UID information, boot timing, prior RNG calls and derivation cost, according to Block.
The incident highlights the importance of seed-generation security and auditing critical flaws in open-source repositories used by cryptographic hardware. Coinkite shipped emergency firmware for affected models and release tracks on July 31, but installing updated firmware does not repair an existing weak seed. The company advises owners with exposed seeds to generate a new seed on patched firmware and move their coins; restoring the old seed carries the weakness forward.
DISCOVER: Best Meme Coins to Buy in 2026
On-Chain Analysis of Suspected Sweep Waves
Detailed on-chain analysis of the Coldcard PRNG vulnerability identified an initial July 30 sweep that drained 1,082.65 BTC from 1,196 addresses in 41 minutes. That opening wave averaged close to one BTC per address.
Subsequent tracking documented by CoinDesk reporting identified a third suspected wave that drained roughly 208 BTC from 1,912 addresses, or just over one-tenth of a BTC per victim.
In that later wave, transactions batched an average of six victims per sweep, sent each victim's coins to a separate destination and used pay-to-witness-script-hash (P2WSH) outputs rather than the plain single-key outputs used in earlier waves.
Galaxy Research said it was confident that each wave was internally the work of one operator, but cautioned that on-chain data could not determine whether the same attacker was responsible for all three waves.
The firm also said it had not computationally confirmed that every identified address was generated with weak Coldcard entropy. Galaxy reported roughly 600 suspected attacker-controlled addresses to federal investigators, compliance firms and cybersecurity investigators.
Read original story Coldcard Seed Flaw Exposes Bitcoin Held by Thousands of Addresses by Daniel Francis at Coinspeaker.com