In the latest Bitcoin news today, Analytical estimates from Galaxy Research, cited by analytics account Lookonchain, indicate that total losses tied to the Coldcard hack have reached approximately 2,055 Bitcoin (BTC), worth $130 million, across more than 7,700 victim addresses.
The estimate follows reports of multiple suspected on-chain sweep waves linked to a seed-generation flaw in devices made by Canadian firm Coinkite.
The flaw affected how seeds were generated on vulnerable firmware, allowing attackers to derive and test candidate keys offline when they could determine or sufficiently constrain relevant device information.
EXPLORE: Best Meme Coins to Buy for August
Bitcoin News Today: Coldcard Firmware Flaw and Weak Randomness
March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG) rather than the STM32 hardware random number generator (RNG).
The production configuration defined the hardware-RNG macro as zero, while the underlying libngu library checked whether the macro existed rather than whether it was enabled, binding the build to MicroPython's Yasmarang fallback.
The MicroPython fallback was initialized from chip unique identifiers and timer registers and did not collect fresh entropy after initialization. Block said an attacker able to determine or sufficiently constrain the device UID, timer state and prior RNG-call history could reproduce candidate output streams offline, then derive addresses and compare them with public blockchain data.
Coinkite estimated effective entropy for affected seeds at roughly 40 bits on Mk3 hardware and about 72 bits on Mk4, Mk5 and Q models, compared with 128 bits for a 12-word BIP-39 seed. The practical cost of reproducing seeds depends on available UID information, boot timing, prior RNG calls and derivation cost, according to Block.
The incident highlights the importance of seed-generation security and auditing critical flaws in open-source repositories used by cryptographic hardware. Coinkite shipped emergency firmware for affected models and release tracks on July 31, but installing updated firmware does not repair an existing weak seed. The company advises owners with exposed seeds to generate a new seed on patched firmware and move their coins; restoring the old seed carries the weakness forward.



