In what is shaping up to be one of the most consequential security failures in self-custody Bitcoin history, a firmware vulnerability in Coldcard hardware wallets allowed attackers to sweep more than 1,359 BTC — worth roughly $85 million — in a targeted theft that unfolded last week. The root cause was not a sophisticated zero-day exploit or a supply chain interdiction. It was something far more embarrassing and far more instructive: the wallet's firmware was not properly utilizing its own true random number generator (TRNG), leaving the cryptographic foundations of affected wallets structurally compromised.

What Went Wrong

Hardware wallets like Coldcard exist for a single, non-negotiable purpose: to generate and store private keys in a manner that is physically and mathematically isolated from adversarial reach. The TRNG is the bedrock of that promise. When a wallet generates a private key, that key must be drawn from a source of entropy that is genuinely unpredictable — a sequence that no attacker, regardless of computing power, can feasibly replicate or anticipate. A TRNG, embedded in the secure element or microcontroller of a hardware wallet, is supposed to guarantee that unpredictability at the hardware level.

The Coldcard firmware flaw meant that the device was not correctly drawing from that hardware entropy source. Whether the TRNG output was being ignored, improperly seeded, or inadequately mixed into the key derivation process remains a subject of ongoing technical analysis. But the practical consequence is unambiguous: private keys generated or managed by affected firmware were cryptographically weaker than users had any reason to suspect. Wallets that appeared secure — sealed in steel, air-gapped, and protected by passphrases — were silently vulnerable at the mathematical layer.

The Scale of the Damage

Over 1,359 BTC, valued at approximately $85 million at the time of the sweep, were drained from affected wallets. The use of the word "sweep" is deliberate: this was not a series of phishing incidents or individual social-engineering attacks. It suggests that whoever identified the vulnerability had developed a systematic method to derive or reconstruct affected private keys and then drain the associated balances in a coordinated, automated fashion. Sweeps of this kind require both knowledge of the flaw and the computational or algorithmic capacity to exploit it at scale — pointing to a sophisticated threat actor or a well-resourced research operation that turned offensive.

The timing also matters. Hardware wallet vulnerabilities of this class do not typically remain in private circulation indefinitely. The week in which funds were drained suggests either that the attack window was narrow and the actors moved quickly before any patch could be distributed, or that intelligence about the flaw had leaked and prompted a race between defenders and attackers that the defenders lost.

Self-Custody's Uncomfortable Reckoning

Coldcard has long occupied a position of particular trust within the Bitcoin self-custody community. It is marketed primarily at technically sophisticated users — those who have deliberately chosen to move beyond exchange custody and accept full personal responsibility for key management. The device's reputation for security rigor made it a default recommendation in circles where hardware wallet quality is scrutinized seriously. That reputation now carries a significant asterisk.

The incident forces an uncomfortable question onto the self-custody thesis: when the firmware of a trusted device silently undermines the entropy guarantees that private key security depends on, no amount of operational discipline — no air-gap, no passphrase, no metal backup — is sufficient protection. Security is only as strong as its weakest cryptographic assumption, and this flaw attacked that assumption at its base.

It also raises systemic questions about firmware auditing practices across the hardware wallet industry. Code that interacts with TRNGs is well-understood territory. The failure to correctly implement it points either to a gap in the testing and review pipeline or to a regression introduced in a subsequent firmware update that escaped detection. Either scenario is troubling for an industry whose entire value proposition rests on the claim that its devices can be trusted with irreplaceable assets.

What This Means Going Forward

For current Coldcard users, the immediate priority is establishing whether their device's firmware version falls within the affected range and whether keys generated during the vulnerable period need to be considered compromised. Funds should be migrated to wallets with keys generated on verified, patched firmware — or on separate devices entirely — until a full technical disclosure clarifies the scope of affected key material.

More broadly, this event is a reminder that hardware wallet security cannot be treated as a solved problem delegated entirely to manufacturers. Independent firmware audits, reproducible builds, and transparent disclosure of entropy-handling logic are not optional features for devices that safeguard hundreds of millions of dollars in bearer assets. The $85 million swept from Coldcard users last week is a hard-dollar cost attached to a gap in that oversight infrastructure — and the industry should treat it accordingly.

Written by the editorial team — independent journalism powered by Bitcoin News.