Cold Card Airgapped Hardware Wallet Hacked: Critical RNG Flaw Leads to 1,800 BTC Drain

On July 30th, 2026, the perceived impenetrability of Cold Card, a widely-trusted airgapped Bitcoin hardware wallet manufactured by Coin Kite, was shattered when a severe vulnerability led to the draining of approximately 1,800 Bitcoin from over 7,000 wallets. This substantial loss, valued at hundreds of millions of dollars, targeted users who conscientiously adopted advanced security practices, starkly contrasting typical phishing or malware attacks. The attackers exploited a core cryptographic weakness without requiring any direct user interaction or social engineering, shaking the foundations of hardware wallet security and the ‘not your keys, not your crypto’ ethos.

The vulnerability stemmed from a critical oversight in Cold Card’s firmware, which runs on MicroPython. While Coin Kite had implemented its own robust random number generator (RNG) to ensure secure seed phrase creation, a firmware bug prevented its activation. Specifically, an if not defined conditional check was bypassed because a flag, though set to zero, was technically defined. This caused the less secure, basic MicroPython RNG to be inadvertently used. Crucially, on a bare-metal chip environment lacking an operating system, this default MicroPython RNG was starved of true entropy sources. It compensated by deriving ‘randomness’ from deterministic inputs like the chip serial number and a timer. This design flaw rendered the generated 12-word seed phrases highly predictable, allowing attackers to systematically enumerate possible combinations and reconstruct private keys. Once compromised, victims attempting to move funds found themselves in a race against the attackers, who leveraged the public mempool to front-run rescue transactions by offering higher mining fees. The only viable, albeit centralized, workaround identified was direct submission of rescue transactions to mining pools, bypassing the public mempool. Coin Kite has acknowledged the flaw, halting all shipments and taking full accountability, though a simple firmware update cannot remediate already-compromised keys, necessitating victims to generate new seeds.