CRITICAL: Coldcard Seed Flaw Linked to $70 Million Bitcoin Theft
A firmware integration error shipped in March 2021 routed Coldcard seed generation to a deterministic software PRNG instead of the STM32 hardware RNG, cutting effective entropy to as low as 40 bits. An attacker drained 1,196 Bitcoin addresses of 1,082.65 BTC worth roughly $70.2 million in 41 minutes on July 30, 2026, without ever touching a device. Coinkite shipped emergency firmware on July 31, but updating does not repair a seed that was already generated.