How Hackers Swept $38 Million Using a “Seed Lottery” Tool: In‑Depth Coldcard RNG Vulnerability Analysis
A detailed technical investigation reveals that a simple macro‑comparison bug in Coldcard firmware reduced entropy to about 40 bits, enabling attackers to enumerate seed space, derive vulnerable addresses, and steal roughly $38 million in Bitcoin within minutes, while the hardware TRNG remained unused.
