COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: news report of $70 million drained in 41 minutes

reddit-70m-41-minutes-report

https://www.reddit.com/r/Bitcoin/comments/1vdt92h/a_coldcard_firmware_flaw_let_hackers_drain_70/

Latest reviewed change

source content difference between and

A comment by DonTheHolder telling victims to let professionals manage their coins was removed; author and body now show [deleted]/[removed].

seen +2 -4 full history below
 
 comment: p1e7sz9
 parent: t3_1vdt92h
-author: DonTheHolder
+author: [deleted]
 created_utc: 1785736243
 edited: false
 body:

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
1
Detected differences
1
Unreviewed
0
Copies held
2

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +2 -4

    A comment by DonTheHolder telling victims to let professionals manage their coins was removed; author and body now show [deleted]/[removed].

    seen · Captured here 7,702 chars
    What changed from the previous capture 6 lines
     
     comment: p1e7sz9
     parent: t3_1vdt92h
    -author: DonTheHolder
    +author: [deleted]
     created_utc: 1785736243
     edited: false
     body:
    -They are broken and broke. They trusted their bag with a hardware wallet creator instead of security professionals and other safety factors and switches that come into play that are secured with stocks as ETFS and CEX COINBASES.
    -
    -You're not nerd enough to protect your coin. Let a professional company manage them properly. 
    +[removed]
     
     comment: p1e9pj3
     parent: t3_1vdt92h
    
    Extracted text as captured
    post: 1vdt92h
    author: ThePrince1856
    created_utc: 1785703973
    title: A Coldcard firmware flaw let hackers drain $70 million in Bitcoin in 41 minutes, with losses now topping $88 million
    body:
    **“A hardware wallet is supposed to solve one problem: keep your Bitcoin keys somewhere no attacker can reach them. This week showed what happens when the flaw sits inside the wallet itself. A firmware bug that's been shipping in Coldcard devices since 2021 let an attacker guess supposedly random seed phrases from the outside, no physical access, no phishing, no malware required, and drain funds from thousands of addresses. The running total is already past $88 million, and it's still climbing.** 
    
    A flaw in Coldcard's firmware has put the spotlight on a basic part of wallet security: how the device generates its seed in the first place. The issue came into focus after an attacker drained 1,196 Bitcoin addresses on July 30 in a 41-minute stretch, taking 1,082.65 BTC worth about $70.2 million at the time.
    
    Galaxy Research tied the sweep to Coldcard, the Bitcoin-only hardware wallet line made by Coinkite, and said the pattern matched a firmware problem rather than a random event. Two more waves have surfaced since, and Galaxy's running total now stands at 1,367.05 BTC, worth about $88.6 million, across 4,585 addresses. The firm describes that as a preliminary observed figure that could still climb as it traces more on-chain activity.
    
    The [problem](https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html) goes back to a March 2021 firmware integration error. Instead of using the STM32 hardware random number generator, affected devices fell back to a deterministic software pseudorandom number generator when creating seeds. That matters because seed generation is supposed to produce output that cannot be guessed or reconstructed.”
    
    comment: p1bp8lt
    parent: t3_1vdt92h
    author: FastJuice3729
    created_utc: 1785704073
    edited: false
    body:
    Is this a larger heist than BITCONNEEEEEE? 
    
    comment: p1bpk26
    parent: t3_1vdt92h
    author: astro-the-creator
    created_utc: 1785704164
    edited: false
    body:
    That should be class action lawsuits 
    
    comment: p1bubay
    parent: t1_p1bpk26
    author: MycoFail
    created_utc: 1785705545
    edited: false
    body:
    Lol against whom 
    
    comment: p1bul66
    parent: t1_p1bubay
    author: astro-the-creator

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. Earliest copy held
    seen · Captured here 8,020 chars
    Extracted text as captured
    post: 1vdt92h
    author: ThePrince1856
    created_utc: 1785703973
    title: A Coldcard firmware flaw let hackers drain $70 million in Bitcoin in 41 minutes, with losses now topping $88 million
    body:
    **“A hardware wallet is supposed to solve one problem: keep your Bitcoin keys somewhere no attacker can reach them. This week showed what happens when the flaw sits inside the wallet itself. A firmware bug that's been shipping in Coldcard devices since 2021 let an attacker guess supposedly random seed phrases from the outside, no physical access, no phishing, no malware required, and drain funds from thousands of addresses. The running total is already past $88 million, and it's still climbing.** 
    
    A flaw in Coldcard's firmware has put the spotlight on a basic part of wallet security: how the device generates its seed in the first place. The issue came into focus after an attacker drained 1,196 Bitcoin addresses on July 30 in a 41-minute stretch, taking 1,082.65 BTC worth about $70.2 million at the time.
    
    Galaxy Research tied the sweep to Coldcard, the Bitcoin-only hardware wallet line made by Coinkite, and said the pattern matched a firmware problem rather than a random event. Two more waves have surfaced since, and Galaxy's running total now stands at 1,367.05 BTC, worth about $88.6 million, across 4,585 addresses. The firm describes that as a preliminary observed figure that could still climb as it traces more on-chain activity.
    
    The [problem](https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html) goes back to a March 2021 firmware integration error. Instead of using the STM32 hardware random number generator, affected devices fell back to a deterministic software pseudorandom number generator when creating seeds. That matters because seed generation is supposed to produce output that cannot be guessed or reconstructed.”
    
    comment: p1bp8lt
    parent: t3_1vdt92h
    author: FastJuice3729
    created_utc: 1785704073
    edited: false
    body:
    Is this a larger heist than BITCONNEEEEEE? 
    
    comment: p1bpk26
    parent: t3_1vdt92h
    author: astro-the-creator
    created_utc: 1785704164
    edited: false
    body:
    That should be class action lawsuits 
    
    comment: p1bubay
    parent: t1_p1bpk26
    author: MycoFail
    created_utc: 1785705545
    edited: false
    body:
    Lol against whom 
    
    comment: p1bul66
    parent: t1_p1bubay
    author: astro-the-creator

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.