Daily Security Intel

Archives
Log in
Subscribe
August 3, 2026

[SecurityIntel] 03 Aug | COLDCARD Wallet RNG Flaw Enables $88M Theft

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Monday, August 03, 2026

INTEL CONFIDENCE  64%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

COLDCARD Wallet RNG Flaw Enables $88M Theft

CRITICAL

5

C2 IPs

0

OTX IOCs

4

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by a critical cryptographic vulnerability in Coinkite COLDCARD hardware wallet firmware, where a flawed random number generator (RNG) enabled attackers to steal approximately $88.6 million in Bitcoin. Additionally, Google is developing new security controls for Chrome to block policy-installed extensions from hijacking New Tab pages and search settings. Organizations must also prepare for the security implications of next-generation AI models, such as OpenAI's newly teased Astra model, as automated capabilities continue to advance.

■ CRITICAL STORIES

CRITICAL#1

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

A critical firmware vulnerability in Coinkite COLDCARD hardware wallets allowed attackers to predict seed phrases generated by a flawed random number generator, resulting in the theft of $88.6 million from thousands of cryptocurrency wallets.

HIGH#2

Google Chrome may soon block New Tab hijacker extensions by default

Google is implementing defense-in-depth measures to prevent policy-installed extensions from hijacking user search engines and New Tab pages, addressing a common vector for adware and information-stealing campaigns.

INFO#3

OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems

OpenAI has announced Astra, a model designed for complex, long-running tasks; while a scientific breakthrough, the rapid evolution of advanced AI increases the potential for sophisticated automated exploitation and social engineering.

■ CVEs IDENTIFIED

[CVE-TBD]

Coinkite COLDCARD Firmware — Flawed random number generator (RNG) leads to predictable cryptographic seed generation and asset compromise

Critical

[CVE-TBD]

Google Chrome (Extensions) — Policy-installed extensions hijacking default search engines and New Tab pages

Medium

■ THREAT ACTORS

Unknown Threat Actors

Cybercriminals

Exploited the COLDCARD RNG vulnerability to compromise wallet seeds and steal $88.6 million in cryptocurrency

■ ATT&CK TTPs

T1600
Weak Cryptography | Attackers exploited a flawed random number generator (RNG) in COLDCARD firmware to predict private keys.
T1176
Browser Extensions | Malicious or policy-installed extensions utilized to hijack Chrome New Tab pages and default search engines.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Coinkite COLDCARD Firmware — Flawed RNG allows complete private key compromise and asset theft [CVE-TBD] — BleepingComputer

[P2 PATCH NOW]≤72h

Google Chrome — Upcoming security controls to mitigate extension-based search hijacking [CVE-TBD] — BleepingComputer

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately audit and migrate funds from any Coinkite COLDCARD hardware wallets whose cryptographic seeds were generated using vulnerable firmware versions affected by [CVE-TBD].
2[P2] Implement strict browser extension policies in Google Chrome to block unauthorized policy-installed extensions from altering default search engines or hijacking New Tab pages [CVE-TBD].
3[P2] Establish organizational governance and monitoring policies regarding the integration and use of advanced AI models like OpenAI Astra to mitigate shadow AI risks.
4[P3] Ensure all hardware security modules (HSMs) and cold storage provisioning processes utilize multi-source entropy (e.g., dice rolls) rather than relying solely on single-source hardware RNGs.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
Older → [SecurityIntel] 02 Aug | Coldcard Wallet Flaw Leads to $70M Theft
Powered by Buttondown, the easiest way to start and grow your newsletter.