DATABASES Signal 126
Recovery Seeds Reportedly Breached for Coldcard Hardware Bitcoin Wallets, $75M Taken
This demonstrates how a single code change that silently degrades a security-critical component can have catastrophic and irreversible consequences—existing compromised seeds cannot be fixed by a firmware patch, requiring complete wallet migration. Engineers building systems that rely on hardware security features must ensure fallbacks are explicit and detectable rather than silent.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
A code change caused Coldcard firmware to silently fall back from a hardware random number generator to a software-based one, collapsing effective entropy from 128 bits to roughly 40 bits.
Attackers exploited the weak entropy to brute-force recovery seeds, stealing approximately $75 million across roughly 2,673 addresses.
Patching the firmware does not repair existing seeds; affected users must generate entirely new wallets and migrate their funds.
THE CLUSTER