Threat Brief — 2026-08-02 — Coldcard RNG Losses Revised Upward
Executive summary: The COLDCARD hardware wallet RNG flaw — first reported yesterday at $70.2 million in stolen Bitcoin — has been revised sharply upward to an estimated $88.6 million, affecting thousands of wallets whose seeds were generated with the flawed random number generator. No other fresh findings were ingested in the last four hours; all other ongoing stories remain unchanged.
Top items
- COLDCARD wallet RNG theft estimate jumps to $88.6M — BleepingComputer now reports the total loss from the COLDCARD firmware RNG flaw at approximately $88.6 million across thousands of wallets, a significant upward revision from the $70.2M / 1,196-address figure first reported on 2026-08-01 by Xakep. The core vulnerability remains the same: seeds generated via a flawed RNG are trivially predictable, allowing attackers to sweep funds at scale. Any organisation or individual holding Bitcoin in a COLDCARD wallet that generated its seed on affected firmware should treat keys as compromised and migrate funds immediately. (src: BleepingComputer)
Themes
Cryptographic supply-chain risk: The COLDCARD incident underscores that hardware wallets are only as trustworthy as their firmware's entropy sources. A single RNG flaw cascaded into nine-figure losses across thousands of independent wallets — a reminder that deterministic or low-entropy key generation in any security-critical device can be catastrophically exploitable at scale.
