Threat Brief — 2026-08-01 — Predictable seed phrases drain hardware wallets
A critical key-generation flaw in Coldcard hardware Bitcoin wallets rendered supposedly random seed phrases predictable, enabling an attacker to steal approximately 594 BTC (~$38M) in just 25 minutes. This is the only fresh finding in the last four hours; all other tracked stories remain unchanged from prior reporting. The incident underscores that even air-gapped, purpose-built security hardware is only as trustworthy as its entropy source.
Top items
- Coldcard hardware wallet key-generation flaw — 594 BTC stolen. A bug in Coldcard's seed-generation logic produced predictable seed phrases, defeating the wallet's core security guarantee. An attacker exploited this to steal roughly 594 BTC (~$38M) within 25 minutes. Any Coldcard device that generated a seed while the vulnerable firmware was active should be treated as compromised; users should regenerate keys on patched firmware and migrate funds. Affected product: Coldcard hardware wallet. (src: xakep)
Themes
Trust in entropy sources. The Coldcard failure is a reminder that hardware security modules and air-gapped wallets depend entirely on the quality of their random number generation. A single flaw in entropy collection collapses the entire security model — the same architectural lesson seen in past incidents like the Android SecureRandom PRNG bug and Ledger's entropy concerns. Organisations building or relying on HSMs and key-management systems should verify entropy sources through independent audit rather than trusting vendor claims.
