← Back to Home News · GLOBAL

Institutional Custody Under Siege: How Coldcard’s Software Error Converted Hardware Seeds into Mempool Races

Make RegTech.com preferred on Google
Institutional Custody Under Siege: How Coldcard’s Software Error Converted Hardware Seeds into Mempool Races
How the randomness system failed — a silent software fallback collapsed Coldcard key strength from 128-bit to roughly 40-bit.
AI Summary
  • A software configuration error in Coldcard hardware wallets severely weakened private key generation, enabling off-chain theft of over $88 million across initial waves — with an active fourth wave forcing institutional treasuries into a fee-bidding race to save funds.
  • Coldcard Randomiser Flaw Triggers $114m Drain as Fourth Mempool Wave Forces RBF Race Coinkite Inc.
  • has disclosed a severe cryptographic weakness affecting Coldcard hardware wallet seeds generated since March 2021.
  • Due to a background software error, the device’s system for creating random numbers quietly switched off its hardware randomiser and relied on a predictable software formula instead.

Coldcard Randomiser Flaw Triggers $114m Drain as Fourth Mempool Wave Forces RBF Race

Coinkite Inc. has disclosed a severe cryptographic weakness affecting Coldcard hardware wallet seeds generated since March 2021. Due to a background software error, the device’s system for creating random numbers quietly switched off its hardware randomiser and relied on a predictable software formula instead. This reduced the uniqueness of generated keys from industry-standard 128 bits down to roughly 40 bits.

This weakness allows attackers to recreate wallet recovery phrases offline without needing physical access to the device, malware, or phishing credentials. As of 3 August 2026, cumulative losses across four distinct attack waves are estimated at approximately 1,816 BTC (roughly $114 million), targeting more than 5,200 addresses.

What Went Wrong: The Software Configuration Error

The issue stems from an update in March 2021 that changed how the wallet requested random numbers during initial setup.

While the device was meant to draw true randomness from its internal physical security chip, miscommunication in the software code caused the wallet to assume hardware randomness was unavailable. As a result, the device silently fell back to a basic software math formula seeded only by the device’s internal serial number and system clock. Because a device’s serial number is fixed and clock times are limited, attackers were able to systematically guess and recreate the resulting wallet addresses.

How the randomness system failed — hardware entropy bypassed by a silent software fallback, collapsing key strength from 128-bit to roughly 40-bit
How the randomness system failed — hardware entropy bypassed by a silent software fallback.

Beyond Key Rotation: Coldcard’s Weak Seed Vulnerability Exposes VASP Monitoring and RBF Defences

Table 1: Hardware Model & Device Exposure Summary

Coldcard randomness flaw — affected hardware models, impacted firmware versions, security level achieved, and the safe-criteria exceptions
Affected models, firmware and the criteria that kept a wallet safe.

Sources: Coinkite Advisories, Block Security Analysis (engineering.block.xyz)

How the Attack Unfolded: The Mempool Speed Race

The attacker’s strategy changed significantly as the theft progressed. The earliest attack waves relied on automated scripts that swept funds to centralised collection addresses, paying an abnormally high processing fee (30.0 sat/vB) to guarantee fast confirmation while leaving zero change behind.

Table 2: On-Chain Attack Waves Breakdown

Coldcard exploit timeline of attack waves — block windows, estimated BTC losses and scope, and the tactics unique to each phase
Four attack waves across the network, with block windows, BTC losses and phase tactics.

Sources: Galaxy Research, CoinDesk Analysis (coindesk.com)

The “Replace-By-Fee” (RBF) Recovery Window

Wave 4 created an urgent tactical scenario for institutional risk teams. Unlike earlier waves that were processed immediately, pending Wave 4 transactions sat unconfirmed in the public transaction queue (the “mempool”) with “Replace-By-Fee” settings turned on.

When an unconfirmed attacker sweep is spotted sitting in the queue targeting an internal address, an organisation has a brief window to rescue the funds. By broadcasting a competing transaction that offers a much higher fee rate to network validators, the organisation can override the attacker’s pending transaction and redirect the funds to a newly created, secure wallet before the attacker’s transfer gets confirmed.

The Transaction Speed Race (RBF) — outbidding an attacker's pending transfer with a higher-fee override to a safe wallet
The Transaction Speed Race (RBF) — racing the attacker with a higher-fee override.

Action Plan for Risk Officers and Compliance Teams

For Chief Compliance Officers (CCOs) and virtual asset service providers (VASPs), this incident reveals major gaps in key tracking and operational monitoring.

The Asset Tracking Problem

Standard institutional asset registers track who owns a device and its serial number, but rarely record the exact software version installed when the wallet seed was first generated. Because updating a device’s software does not fix an already compromised seed phrase, institutions cannot fix this with a simple update; they must generate completely new seed phrases and migrate all assets.

Filtering Real Threats from Customer Self-Protection

As thousands of wallet owners rush to move their funds to safety, automated exchange monitoring systems face a major challenge. Automated monitoring rules configured to flag “100% account balance transfers” risk generating huge volumes of false alarms on legitimate customers simply securing their assets.

Compliance Impact

The Coldcard vulnerability brings sharp focus to the fact that hardware security controls are only as robust as the software build configurations supporting them. As cumulative losses across four distinct attack waves exceed $114 million, institutional custodians, digital asset managers, and individual wallet holders running affected firmware without external dice entropy or custom passphrases face an immediate operational imperative.

For better security, risk and compliance teams must move beyond simple firmware updates and also focus on real-time transaction queue monitoring to exploit fund-recovery windows, conducting rigorous historical audits of wallet generation records, and recalibrating exchange monitoring logic to distinguish active exploit sweeps from legitimate customer asset migrations.

Link copied to clipboard
AI Bot
AI Bot
Hi! I'm the RegTech.com assistant. How can I help you today?
Ask me anything — top trending news, latest regulatory changes in the EU, or simply search for topics.