Fetching from the wire…
Security2026-08-06 · source-backed
Fireship walked through it August 5. ColdCard's firmware runs MicroPython, whose weak RNG was supposed to be disabled by setting a flag to 0. Both RNGs exported the same function name, and the crypto library chose between them with an if-not-defined check. The flag was defined. As zero. For five years every seed phrase came from MicroPython's RNG, which on bare metal falls back to chip serial plus a timer, both deterministic, collapsing 128 bits into brute-forceable space. Since July 30 attackers have drained 1,600+ BTC (~$400M) from 7,000+ wallets. No malware, no phishing. Victims are now bidding against attackers to buy back their own coins.
Each link below shares sources, entities, or timing with this story.
Shared entity: Fireship / Same source domain / Earlier coverage / Tension
Both cover Fireship; reported by the same outlet (youtube.com); earlier Fireship coverage from 2026-06-28.
Shared entity: August / Shared topic / Earlier coverage
Both cover August; overlapping topics (between, check); earlier August coverage from 2026-08-03.
Shared entity: Fireship / Same source domain / Earlier coverage
Both cover Fireship; reported by the same outlet (youtube.com); earlier Fireship coverage from 2026-07-30.
Both cover Fireship; reported by the same outlet (youtube.com); earlier Fireship coverage from 2026-07-16.
Shared topic / Tension / Downstream implication
Overlapping topics (against, attacker, between); pushes against this story (against); traces where this leads (implication).
Shared entity: Fireship / Same source domain / Earlier coverage
Both cover Fireship; reported by the same outlet (youtube.com); earlier Fireship coverage from 2026-06-23.
Both cover Fireship; reported by the same outlet (youtube.com); earlier Fireship coverage from 2026-05-05.
Both cover Fireship; reported by the same outlet (youtube.com); earlier Fireship coverage from 2026-04-02.