Skip to content
← All posts

Why Can a Seed Phrase Be Brute-Forced If the Wallet Created It With Weak Randomness?

The $116 million Coldcard hack showed that an offline device does not help if the seed phrase was created with too little randomness. A firmware build error cut key strength from 128 to 40 bits. What entropy is, why a firmware update cannot fix it and what owners should do.

Dot matrix: a vast field of possible keys and a tiny highlighted patch that can be brute-forced when randomness is weak

A seed phrase can be brute-forced if the random number generator produced too few possibilities when it was created. Wallet security rests on keys being impossible to guess. When a firmware bug turns 128 bits of randomness into 40, the number of candidates falls to roughly a trillion, and keys can be found on ordinary computers without touching the device. That is how about $116 million was taken from Coldcard wallets, according to TRM Labs.

What happened to Coldcard wallets?

According to TRM Labs:

  • firmware 4.0.1, released in March 2021, contained a build configuration error;
  • because of it, devices generating seed phrases fell back to weak software-based random number generation instead of hardware entropy;
  • exploitation began on July 30, 2026: about 594 BTC (~$38 million) was swept from roughly 500 wallets in 25 minutes;
  • in total about 1,816 BTC (~$116 million) was stolen from more than 5,200 addresses, the third-largest hack of 2026;
  • on August 4 laundering began: 64.9 BTC went to Wasabi and 200 ETH to Tornado Cash.

TechCrunch put losses at more than $130 million in early August; TRM describes its figures as preliminary.

Why are 40 bits a disaster and 128 bits fine?

Each bit of entropy doubles the number of possible keys. The BIP-39 standard used for seed phrases specifies 128 bits for a 12-word phrase and 256 bits for 24 words.

Entropy Possibilities What it means
128 bits 2¹²⁸ ≈ 3.4 × 10³⁸ Brute force is out of reach for any existing computer
40 bits 2⁴⁰ ≈ 1.1 × 10¹² About 1.1 trillion candidates

As an illustration: at a billion checks per second, 2⁴⁰ can be exhausted in about 18 minutes. Real speed depends on hardware, but the order of magnitude is clear: this is a job for an ordinary server, not a supercomputer.

Why didn't an offline device help?

A hardware wallet protects a key from theft: malware on a computer cannot extract it. But if the key is predictable from the start, nobody needs to steal it. The attacker generates candidates, derives addresses from them and compares those with funded addresses on the blockchain. A match means the funds can be moved.

In TRM's words, such keys can be brute-forced without ever touching the physical device. For what a hardware wallet does and does not protect against, see What a Hardware Wallet Protects Against, and What It Doesn't.

What should wallet owners do?

TRM Labs recommends:

  1. Check when your seed phrase was created. Phrases generated on the vulnerable firmware between March 2021 and the fix are at risk.
  2. Generate a new phrase on updated hardware and move all funds to it.
  3. Don't treat a firmware update as the fix. It only protects future phrases; it does not strengthen an old weak one.
  4. Consider multisig with devices from different manufacturers, so a flaw in one generator cannot expose every key.

Another common practice is adding your own entropy when creating a phrase, for example with dice rolls, if the device supports it.

What are the limitations of this analysis?

  • Figures are preliminary. Funds are still moving and the final total may change; TRM and media estimates already differ.
  • The brute-force timing is illustrative. Actual speed depends on the key-derivation algorithm and the attacker's hardware.
  • The flaw concerns specific firmware. This article does not assess other models or manufacturers.
  • Users cannot easily verify entropy. An ordinary owner cannot check how random their phrase is, which is why open-source code and independent audits matter.
  • Multisig adds complexity. Mistakes in setup and backup storage create risks of their own.

Sources

  • TRM Labs — The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack
  • TechCrunch — Hackers steal over $130M by exploiting bug in offline hardware wallets — https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/
  • BIP-39 — Mnemonic code for generating deterministic keys — https://github.com/bitcoin/bips/blob/master/bip-0039.mediawiki

This article is for information only and is not individual investment advice. Trading crypto carries the risk of losing your funds; results on historical data do not guarantee future results.

Read this next

What Is a Qualified Custodian, and Why Would the SEC Let Advisers Self-Custody Crypto Only as a Last Resort?

Check the strategy against your own data

ACARO is a terminal that executes a strategy on your own exchange account. Parameter search and backtesting on history are part of the subscription.

See pricing