COLDCARD's Random Numbers Weren't Random

A security flaw in COLDCARD hardware wallets allowed attackers to predict wallet seeds, leading to the theft of over 1,400 BTC. The issue stemmed from a build guard that checked for the existence of a hardware RNG macro, not whether it was enabled. From March 2021, affected devices could generate seeds from predictable inputs. Between July 30 and August 2, 2026, attackers swept 1,433.13 BTC from 5,477 addresses.
A build guard checked whether the hardware RNG macro existed, not whether it was enabled.