Foundation Devices Founder Zach Herbert Details the Origin of the Cold Card Entropy Bug

Foundation Devices founder and CEO Zach Herbert joined the show to walk through what he believes set the stage for the Cold Card entropy bug, a firmware flaw that let attackers reconstruct private keys without ever touching the physical device.
THE BUG ITSELF
A build configuration error in Coldcard firmware version 4.0.1, shipped in March 2021, routed seed generation to a deterministic software pseudorandom number generator instead of the device's hardware random number generator, reducing effective entropy from 128 bits to roughly 40 bits on older devices and 72 bits on newer Mk4, Mk5 and Q models. Starting July 30, 2026, attackers began draining wallets that used the weakened randomness, an estimated $130 million or more in Bitcoin across roughly 7,300 affected addresses. Updating firmware does not fix a seed that was already generated under the flawed code.
WHY HERBERT SAYS THIS HAPPENED
Herbert's account starts in 2020, when Foundation announced its first Passport hardware wallet, built in part on Coinkite's Cold Card firmware, which was licensed under GPLv3 at the time, an open source license that lets anyone build on the code as long as they keep it open. According to Herbert, Coinkite CEO Rodolfo Novak, known as NVK, publicly said he regretted choosing GPL because Coldcard now had a clone, and said the company would change the license going forward.
Herbert said that reaction kicked off an effort inside Coinkite to strip GPL licensed code, most notably the transaction signing libraries originally taken from the Trezor project, out of the Cold Card codebase and replace it with a new library. According to Herbert, that rewrite is where the random number generator flaw was introduced. He was careful to say the license change was not the only driver of the rewrite, noting Coinkite was also working on unrelated library upgrades at the same time.
THE IRONY HERBERT POINTS TO
Herbert argued the response to Foundation's 2020 announcement cut against the open source principles the Bitcoin hardware community says it values. He noted that Cold Card's own crypto libraries originally came from the Trezor project, and that he had publicly defended Coinkite's right to reuse that code years earlier. His point on the show was that open code sharing is supposed to be treated as a strength, not a threat, because more auditors on a shared codebase means more security for everyone building on it.
WHERE THINGS STAND NOW
Herbert said Foundation has run its own random number generator through an internal audit since the incident came to light and found no equivalent flaw in the Passport codebase. He also addressed the AI angle Coinkite has raised publicly, saying he believes it is highly likely the exploit was assisted by an open weight AI model capable of writing code to grind through potential seeds, something he said current US based models are typically restricted from doing.
Asked whether the incident is a knock against self custody as a whole, Herbert said no. He described it as a case of specific negligence at one company rather than evidence that single signature hardware wallets are broken, pointing to how few developers reviewed Cold Card's crypto libraries and how customer bug reports were reportedly dismissed for years before the flaw surfaced publicly.
This story comes from the Simply Bitcoin Live show. Watch the full episode.


