# Coldcard Entropy Defect, a SafePal Data Leak and a macOS Bug Widen the Custody Attack Surface

Rekt now counts roughly $130 million tied to a 2021 firmware change that routed a hardware wallet's randomness through a guessable software fallback, while attackers with root access on exposed Macs installed Monero miners.

- Published: 2026-08-17T05:44:33.122Z
- Canonical: https://polylog.news/crypto/2026-08-17/coldcard-entropy-defect-a-safepal-data-leak-and-a-macos-bug
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [Rekt News (Cold Card)](https://www.rekt.news/), [CoinDesk](https://www.coindesk.com/tech/2026/08/16/crypto-wallet-safepal-reveals-a-data-breach-exposing-nearly-40-000-customers-order-info), [crypto.news](https://crypto.news/apple-patches-macos-flaw-exploited-to-mine-monero/), [Polylog editors](https://polylog.news)

The Coldcard case remains the most instructive custody failure of the year. According to Rekt, a firmware commit dated 1 March 2021 replaced a call to the device's hardware random number generator with a software pseudorandom fallback drawn…

This story is for subscribers. Read it in full at https://polylog.news/crypto/2026-08-17/coldcard-entropy-defect-a-safepal-data-leak-and-a-macos-bug (subscription information: https://polylog.news/pricing).