COLDCARD’s random numbers weren’t.
Summary
A deep-dive into a hardware RNG flaw in COLDCARD devices where a build guard checked for the RNG macro rather than enabling it, potentially allowing wallet seeds to be generated from predictable inputs. The report links this to on-chain activity in late July to early August 2026, documenting substantial BTC movements from hundreds of addresses with on-chain tracing. The piece frames the issue as a security vulnerability with real financial impact and ongoing forensic context.