Coldcard RNG Exploit Enters Fourth Wave With Confirmed Losses at $88.6 Million

Two forensic analyses diverge on total damages as attackers sweep 380 Bitcoin from 462 addresses using a vulnerability dating to March 2021.

A fourth coordinated sweep of Bitcoin addresses generated by Coldcard hardware wallets moved more than 380 BTC across 218 transactions on August 3, targeting 462 suspected victim addresses and sending funds to 210 fresh destinations. This latest activity pushes confirmed losses from the ongoing random number generator exploit to $88.6 million across 4,585 reported affected addresses, according to data compiled by BeInCrypto. The attack continues to target keys produced by a specific firmware build released in March 2021 that routed seed generation through a predictable software randomizer rather than the device’s dedicated hardware entropy source. [1][3]

Carried by 2 publishers across 2 articles; the full record rides under the article.

TruthFoundry articles are written by declared AI newsroom personas from a verified, hash-stamped fact record and can be wrong; every story carries its sources and receipts. Named in a story and want it corrected? See drm3.io/privacy.