The Latest Crypto News
Friday, 25 September 2026 BTC -- / --
🔍

Coldcard hardware wallet had serious security flaw in seed generation

Make The Latest Crypto News preferred on Google
Coldcard wallet device on desk with red warning symbol and scattered seed words.
Coldcard wallet device on desk with red warning symbol and scattered seed words.

A security flaw in the popular Coldcard hardware wallet meant that the generated seed phrases were nowhere near as random as they seemed. Although the words looked normal, the search space for an attacker was vastly smaller than intended.

In short:

  • A bug in Coldcard made seed phrases partially predictable through the use of device ID and timing.
  • Instead of a search space of 340 undecillion combinations, this dropped to just a few billion possibilities.
  • The seed phrases looked completely normal from the outside, so users noticed nothing suspicious.

What exactly went wrong at Coldcard

A hardware wallet such as the Coldcard generates a seed phrase of twelve words based on genuine randomness. Compare it to a lottery with 340 undecillion possible tickets, a number that is 340 followed by 36 zeros. Each combination has an equal chance of being selected, which makes guessing someone’s seed phrase practically impossible.

The fault was not in the list of 2,048 BIP-39 words used for seed phrases. That list remained fully intact. The problem lay in the way the device selected those words. Instead of genuinely choosing at random from the full range of possibilities, the wallet kept drawing from the same small corner. This was because the so-called random numbers were partly predictable on the basis of the device ID and the timing.

Why this is dangerous even though everything looks normal

Quinten François explains that the seed phrase looked perfectly normal to a user. The words simply came from the well-known list and there was nothing to indicate otherwise. That is what makes this vulnerability especially treacherous: no one could tell at first glance that something was wrong.

For an attacker, however, the picture changed drastically. Instead of having to work through trillions of trillions of combinations, the effective search space shrank to just a few billion possibilities. That still sounds like a lot, but it is astronomically smaller than what Bitcoin security requires. A targeted attack therefore became theoretically feasible, whereas it is normally completely out of reach. Users of an affected Coldcard wallet would be well advised to move their Bitcoin to a newly generated address as soon as possible.

Summarize this article with AI

Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.

Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.

More Bitcoin News

More news ›