Coldcard Made Guessable Keys for Five Years With the Code Public
Coldcard shipped five years of hardware wallets that made guessable keys, with the source code open the whole time. People read it. Nobody tested it on a schedule.
The Box That Makes the Number
Bitcoin has no accounts, no bank, and no ID check. Every stash of coins is controlled by a key, and a key is just a very long secret number. Whoever knows that number can spend the coins. There is no undo and nobody to call.
Here is how a wallet builds that key. On the day you set the box up, it creates one master secret at random, called the seed. The box shows you the seed as a list of ordinary words, usually 12 or 24 of them. That word list is the seed phrase you copied onto paper and hid. Every key the wallet ever uses is calculated from that one seed. So the words on that paper are the money. Anybody who gets the words, or can guess them, gets everything.
A hardware wallet is a small box built to create that seed and keep it off the internet. That is the whole product. You pay for it so you never have to trust anybody else with the secret.
Coldcard is one of the best-known hardware wallets, made by a company called Coinkite. Firmware is the software that lives inside the box. On 30 Jul 26 Coinkite disclosed that Coldcards built since a 2021 firmware update were creating weak seeds. The box has a chip in it whose only job is producing true randomness, the raw material the seed gets built from. A wiring mistake in the software meant the box quietly used a plain software substitute instead. The substitute ran mostly off predictable inputs, like the device's own clock. Predictable inputs make a predictable seed. An attacker who knows how the seed got built can run through the possibilities until a funded wallet falls out. Nobody stole a single paper backup. The thieves rebuilt the seed phrases from the other end.
Thefts started the same day. Galaxy Research, a crypto research firm, counted more than $130 million gone from over 5,200 addresses by 07 Aug 26, in four separate waves.
Somebody Looked, Nobody Checked
Coldcard's source code has been public the whole time. Anybody could read it. People did read it. Five years of releases went out the door, and the flaw went with every one of them.
That is the part worth sitting with. Openness is supposed to be the safeguard here, and for five years it did not work. Coinkite ran its own review pass over that code a few weeks before this broke and missed it too.
Reading is not testing. The device handed back a working wallet every single time. It never threw an error and it never failed to start up, so nobody had a reason to look twice. A weak seed and a strong seed look exactly alike from the outside, and no inspection can tell them apart.
The reviews have to be systematic. Somebody reading the code when they get around to it is not a review.
Systematic means the check runs on a schedule whether anybody feels like it that day or not. It covers the same ground the same way every time. And it has to be able to come back with a bad answer. A check that can only pass is not doing anything.
Test It Before It Ships
The fix Coinkite shipped makes the case better than any argument I could write. The patch adds a check to the build process itself. If the random number wiring is wrong, the build fails. Nobody has to remember or notice anything. The product cannot get out the door in the broken state.
That is what security testing before shipping looks like. A gate the product cannot pass through broken.
Where the Machine Helps
Coinkite says an automated tool most likely found this flaw. Five years of human eyes on public code did not. That is a real result. Machines are good at combing old code for the exact kind of quiet mistake a person skims past at two in the afternoon.
Now the other half of it. A research team at 1Password called Off-By-1 Labs presented at Black Hat, a large security conference, this month. They studied patches written by artificial intelligence (AI) tools and found 54 percent did not fix the flaw they were aimed at.
So put the machine on finding and keep a person on fixing, and verify either way. Run the scans against your own code on a schedule you do not get to skip. For a small shop that costs almost nothing, which makes it hard to justify skipping.
If You Own One
Updating the firmware does not save you. A seed generated under the old software stays weak forever, and so does every key that comes from it. Generate a brand new seed on the fixed firmware and build a new wallet. Write down the new word list and retire the old paper. Move the funds over, with a small test transaction first.
Coldcard lets an owner add his own randomness at setup by entering dice rolls. If you did 50 or more rolls, or put a passphrase on top of the seed, you came through fine.
And if you ship code or firmware to anybody, go find the one silent failure in your build that nobody would catch. Put a check on it this week that fails loud.
Next: this week's report, The Water Attacks Reached 12 States, and Controllers Are Still Exposed, where the same lesson runs through public water systems.
Works Cited
- Technical Deep Dive into the Entropy Issue (Coinkite)
- Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware (Block Engineering)
- A five-year-old Coldcard bug let hackers guess bitcoin wallet keys, Coinkite confirms (Blockhead)
- Coldcard Losses Climb Past $130 Million as a Fourth Wave of Thefts Hits Self-Custody Wallets (Blockhead)
- AI-Generated Patches Fail Half the Time (Dark Reading)