A seed generation vulnerability affecting certain older Coldcard firmware and device versions enabled the theft of approximately 594 BTC from around 500 single-signature wallets on July 30 and 31, 2026. The core issue stemmed from the hardware random number generator being replaced by a predictable software substitute, reducing entropy from 128 bits to 72 bits. Seeds generated with a BIP-39 passphrase or at least 50 dice rolls are not considered at risk according to the validated notes. Fixed firmware releases are available, including version 5.6.0 for Mk4 and Mk5 devices and 1.5.0Q for Q devices.
Source: Read the original article

