LIVE · cybersecurity feed
Live wire
CVE-2026-66066 · KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)Rails patches critical Active Storage flaw with RCE potentialCVE-2026-48449 · Adobe fixed a maximum-severity vulnerability flaw in Campaign ClassicRuby on Rails Patches Critical VulnerabilityHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCVE-2026-33017 · Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability ExploitsThis month in security with Tony Anscombe – July 2026 edition
vulnerability

COLDCARD Seed Generation Flaw Linked to Nearly $89 Million Bitcoin Theft

Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds. Coinkite says updates cannot repair seeds already generated on devices.

zeroday.news · 2h ago

A recent report by Galaxy Research has linked a suspected theft of approximately 1,367.05 Bitcoin, valued at nearly $89 million, to a weakness in the seed generation process of COLDCARD hardware wallets. The research suggests that seeds generated on these devices may have been susceptible to compromise, leading to the significant loss of funds.

The core of the issue appears to be a flaw in the entropy or randomness used during the generation of cryptographic seeds on COLDCARD devices. Hardware wallets rely on robust random number generation to create unique and unpredictable seeds, which are the master keys to a user's cryptocurrency. If the randomness is insufficient or predictable, an attacker could potentially re-create or guess a seed, thereby gaining unauthorized access to the associated funds. This class of vulnerability often stems from issues in the device's true random number generator (TRNG) or pseudorandom number generator (PRNG) implementation.

Coinkite, the manufacturer of COLDCARD, has acknowledged the situation. Their statement indicates that devices that have already generated seeds using the potentially flawed process cannot be retroactively repaired through software updates. This means that users who generated their seeds on affected devices would need to migrate their funds to a new, securely generated seed on a different device or a device with a confirmed patched seed generation mechanism.

The scope of this issue would primarily affect users who generated their wallet seeds on COLDCARD devices during the period when the vulnerability was present. It underscores the critical importance of secure seed generation in hardware wallets, as the seed is the single point of failure for the entire wallet. Without a strong, unpredictable seed, the security assurances of a hardware wallet are severely undermined.

Typical mitigation advice for users of hardware wallets, particularly when a seed generation flaw is identified, includes immediately moving funds to a new wallet with a securely generated seed. Users are often advised to verify the integrity of their hardware wallet's firmware and to ensure they are using the latest, officially released versions. For new devices, it is generally recommended to generate a seed on a trusted, air-gapped computer or directly on the hardware wallet itself, ensuring no compromise during the generation process.

This incident highlights the ongoing challenges in securing digital assets, even with specialized hardware. It reinforces the industry's focus on rigorous auditing of cryptographic implementations, particularly in critical components like random number generators. The immutability of a compromised seed, as noted by Coinkite, serves as a stark reminder that foundational cryptographic weaknesses can have long-lasting and financially devastating consequences for users.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

More on the OpenAI Agent’s Attack on Hugging Face

Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or

CVE-2026-18577

N-able warns of N-central auth bypass flaw exploited in attacks

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...]

malware

Fake Roblox Xeno script launcher pushes infostealer, RAT malware

Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...]

malware

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package

ai

AI slop pollutes the CVE pipeline with fake vulns

With NIST still buried under its backlog, expect AI-generated bogus reports to continue

security

Why Bitcoin Businesses Are Moving to Dedicated VPS Infrastructure

A Bitcoin business rarely runs a simple website. Payment processors, exchanges, wallet services, blockchain analytics products and Lightning…