MultiversX Tracker is Live!

[SERIOUS] I reconstructed the Coldcard RNG losses on-chain and it came out bigger than the public numbers (2,052 seeds, 35,189 drained addresses)

All Cryptocurrencies

by COINS NEWS 9 Views

[SERIOUS] I reconstructed the Coldcard RNG losses on-chain and it came out bigger than the public numbers (2,052 seeds, 35,189 drained addresses)

So I spent the last few weeks digging into the Coldcard RNG bug on-chain, and the numbers came out worse than what has been reported so far.

Background for anyone who missed it: a batch of firmware shipped with the hardware RNG switched off for seed generation (the MICROPY_HW_ENABLE_RNG=0 thing). So instead of the real TRNG, seeds were coming out of a small software PRNG, and the actual entropy was only around 19 to 20 bits. That is crackable on a single GPU.
I brute-forced the affected seeds up to the practical ceiling, roughly 2,052 wallets, and from those derived 35,189 unique addresses that are all drained now. That is about 5 times what the address-list writeups found, because I went after the change and deeper derivation addresses too, not just the final sweep everyone screenshots.
Then I pulled the full transaction graph to tell apart internal change-cycling from money that actually left. Net theft comes to roughly 5,080 BTC, about 406 million dollars at today's price. The gross figure, meaning everything that ever passed through the bad keys, is around 10,950 BTC, but that is not the loss, a lot of it is just change bouncing around between the attacker's own addresses.
Two things worth flagging. Following the money forward, something like 2,918 BTC is still sitting on-chain and could in principle be frozen, and about 991 BTC made it to exchanges. And the sweeper is still running: the most recent automated drain I could find was on 2026-08-19, and it has been going since at least 2021, so years before this ever became public.
What I am not posting: the recovered seed phrases, the PRNG constants, the exact brute-force parameters, or anyone's name. The first would just hand copycats a way to hit wallets that are not drained yet, and the blame question is for proper investigators, not a reddit thread.
I will drop the link to the full writeup, the victim address list and the hub map in a comment, so the post does not get auto-filtered.
If anyone wants to dig into how the net-versus-gross split or the derivation was done, I am around in the comments.

Mikhail, independent security researcher. Telegram MadMike178, email izautrin at gmail dot com.

submitted by /u/Izautrin
[link] [comments]

Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
πŸ’° Install these recommended apps:
πŸ’² SocialGood - 100% Crypto Back on Everyday Shopping
πŸ’² xPortal - The DeFi For The Next Billion
πŸ’² CryptoTab Browser - Lightweight, fast, and ready to mine!
πŸ’° Register on these recommended exchanges:
🟑 Binance🟑 Bitfinex🟑 Bitmart🟑 Bittrex🟑 Bitget
🟑 CoinEx🟑 Crypto.com🟑 Gate.io🟑 Huobi🟑 Kucoin.



Comments