{"investigation":{"slug":"coldcard-coinkite-firmware-entropy-exploit","entity_name":"Coldcard (Coinkite Firmware Entropy Exploit)","trust_score":5,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Beginning July 30, 2026, attackers exploited a five-year-old firmware flaw in Coinkite's Coldcard Bitcoin hardware wallet that caused affected devices to generate seed phrases using a weak, predictable random number generator instead of hardware entropy, collapsing effective key strength from a designed 128 bits to as little as 40 bits. Across four waves through early August 2026, attackers drained roughly 1,816 BTC (approximately $116 million) from more than 5,200 addresses without needing physical access to victims' devices. The affected manufacturer, Coinkite, is covered separately at /coldcard-coinkite; this page concerns only the exploit itself and the firmware cohort it affected.","sections":[{"content":"Starting on July 30, 2026, funds began being drained from Coldcard hardware wallets in what research firm TRM Labs described as the largest hardware wallet exploit on record and the third-largest crypto hack of 2026 year-to-date. According to on-chain analysis cited by Fortune and TRM Labs, attackers removed approximately 1,816 BTC (roughly $116 million at the time) from more than 5,200 individual addresses across four distinct attack waves between July 30 and early August 2026. Unlike most wallet compromises, victims did not need to lose physical possession of their device, click a phishing link, or expose their seed phrase; the funds were taken purely through brute-forcing predictable private keys generated by the flawed firmware.","heading":"Incident Overview","sources":[{"url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack","name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack","type":"research","credibility":2},{"url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/","name":"Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit","type":"news_article","credibility":1},{"url":"https://www.halborn.com/blog/post/explained-the-coldcard-hack-july-2026","name":"Explained: The Coldcard Hack (July 2026)","type":"research","credibility":2}],"severity":"critical"},{"content":"The vulnerability traces to Coldcard firmware version 4.0.1, released in March 2021, and persisted through version 4.1.9 until a patch followed the 2026 exploit. According to Halborn's technical write-up, a build configuration error caused the device's key-generation routine to bypass its hardware true random number generator (TRNG). Calls intended to draw hardware entropy (via the ngu.random.bytes function in the libngu MicroPython library) silently fell back to MicroPython's software pseudo-random number generator, which was seeded only with the device's UID and a hardware timer value captured at power-on — both of which are guessable or brute-forceable. On the Mk2 and Mk3 Coldcard models, this reduced effective entropy to roughly 40 bits, compared with the 128 bits the design intended; Halborn estimated this could be exhausted in approximately 13 days at one million key-attempts per second. The newer Mk4, Mk5, and Q models reportedly used a different implementation with roughly 72 bits of entropy. TechCrunch and Fortune, citing payments company Block's Bitcoin engineering and security team, reported that the underlying code checked only whether a configuration setting existed rather than whether it was actually enabled, allowing the weak fallback to go undetected in the codebase for roughly five years. Because the flaw affected the seed-generation process itself rather than requiring any breach of the physical device, attackers could reconstruct victims' private keys entirely offline once the pattern was understood, with no need for device access, phishing, or seed-phrase exposure.","heading":"Technical Root Cause: Firmware Entropy Flaw","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-coldcard-hack-july-2026","name":"Explained: The Coldcard Hack (July 2026)","type":"research","credibility":2},{"url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/","name":"Hackers steal over $130M by exploiting bug in offline hardware wallets","type":"news_article","credibility":2},{"url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/","name":"Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit","type":"news_article","credibility":1},{"url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack","name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack","type":"research","credibility":2}],"severity":"critical"},{"content":"Reporting from TRM Labs and Fortune describes the theft unfolding in four identifiable waves rather than a single event. The first wave, on July 30, 2026, reportedly drained a large batch of single-signature wallets within minutes, moving funds into consolidation addresses; TRM Labs separately described a sweep of roughly 594 BTC (about $38 million at the time) from around 500 wallets completed in approximately 25 minutes. Fortune's reconstruction of Galaxy Research's on-chain tracking describes additional waves occurring over the following days, with a further tranche of about 208 BTC taken from roughly 1,912 addresses, and a fourth wave detected several days after the initial attack that brought the cumulative total to approximately 1,816 BTC drained from more than 5,200 addresses. TRM Labs characterized these figures as preliminary, noting that additional victims could surface over months or years as dormant affected wallets are identified. TRM also noted that most stolen funds were pooling at a small number of attacker-controlled addresses with minimal laundering observed at the time of its report — a single consolidation hop rather than layering through mixers — though it identified a 64.9 BTC deposit to the Wasabi wallet-mixing service and 200 ETH sent to Tornado Cash as early laundering activity.","heading":"Attack Waves and Financial Losses","sources":[{"url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack","name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack","type":"research","credibility":2},{"url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/","name":"Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit","type":"news_article","credibility":1}],"severity":"critical"},{"content":"Loss estimates for the incident shifted as it developed and as different analytics firms published figures. Early reporting from KuCoin's news desk cited approximately $89 million (around 1,367 BTC from about 4,585 addresses, attributed to Galaxy Research) and later approximately $112 million (about 1,778 BTC), before TRM Labs and Fortune settled on approximately 1,816 BTC (~$116 million) from more than 5,200 addresses as of around August 3–5, 2026. TechCrunch's August 4, 2026 report cited a higher figure of roughly $130 million (reported as \"as of Tuesday\"), attributed to Galaxy Research, with Elliptic co-founder Tom Robinson calling the estimate \"roughly correct\". Because the hack involved a retroactively exploitable key-generation weakness rather than a single discrete theft, totals continued to be revised upward as additional affected wallets were identified; readers should treat any single figure as a snapshot rather than a final tally. This variance is reported consistently across Tier 1 and Tier 2 sources, though the discrepancy itself is noted here at medium confidence given the fast-moving nature of the initial reporting.","heading":"Variance in Loss Estimates Across Trackers","sources":[{"url":"https://www.kucoin.com/news/flash/coldcard-wallet-exploit-steals-1-778-btc-worth-112m","name":"Coldcard Wallet Exploit Steals 1,778 BTC Worth $112M","type":"news_article","credibility":2},{"url":"https://kucoin.com/news/flash/coldcard-hack-drains-89m-in-btc-due-to-firmware-vulnerability","name":"Coldcard Hack Drains $89M in BTC Due to Firmware Vulnerability","type":"news_article","credibility":2},{"url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/","name":"Hackers steal over $130M by exploiting bug in offline hardware wallets","type":"news_article","credibility":2}],"severity":"medium"},{"content":"No specific individual or group has been publicly attributed to the theft. TRM Labs stated it was not attributing the incident to a specific actor as of its report, and noted that differences in transaction construction across the four waves suggest multiple, possibly unrelated attackers may have independently discovered and exploited the same firmware weakness. TRM also noted the laundering pattern — slow consolidation without rapid mixing — differed from the fast laundering typically associated with North Korea-linked actors such as the group tracked as TraderTraitor, though it drew no conclusion from this. TechCrunch reported that Galaxy Research believed at least a dozen separate actors may have been targeting Coldcard users, and that more than one group appeared to be involved. Fortune similarly reported that investigators had not linked the incident to any specific state-backed or criminal group, despite recent large crypto thefts often being attributed to North Korea- or Russia-linked actors. Any claims naming a specific individual as responsible for the underlying code defect that have circulated on social media are unverified and are not included here given the absence of corroborating Tier 1 or Tier 2 sourcing.","heading":"Attribution","sources":[{"url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack","name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack","type":"research","credibility":2},{"url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/","name":"Hackers steal over $130M by exploiting bug in offline hardware wallets","type":"news_article","credibility":2},{"url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/","name":"Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit","type":"news_article","credibility":1}],"severity":"medium"},{"content":"Coinkite released patched firmware addressing the entropy fallback, covering the affected 4.0.1–4.1.9 line, but patching does not retroactively secure seeds already generated on vulnerable firmware. TRM Labs and Halborn both advised that anyone who generated a Coldcard seed between March 2021 and the patch should treat that seed as compromised regardless of the firmware currently installed, generate an entirely new seed on updated hardware, verify the new wallet's fingerprint and a receive address, and migrate funds — starting with a small test transaction before moving remaining balances. Halborn reported that Coinkite retains customer purchase records for only 120 days, limiting the company's ability to directly notify owners of devices purchased earlier in the five-year exposure window. According to Fortune, Coinkite issued an open letter and a social media statement acknowledging the crisis, stating that \"the last three days have been some of the hardest in this company's history.\" TechCrunch reported that Coinkite published a security advisory and subsequently updated it days later, urging firmware updates and seed migration, but that the company did not respond to TechCrunch's request for direct comment. Security researchers additionally noted that multisignature setups combining independently designed hardware wallets with independently generated entropy would have mitigated the impact of a single vendor's entropy failure.","heading":"Response, Remediation, and Ongoing Risk to Affected Users","sources":[{"url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack","name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack","type":"research","credibility":2},{"url":"https://www.halborn.com/blog/post/explained-the-coldcard-hack-july-2026","name":"Explained: The Coldcard Hack (July 2026)","type":"research","credibility":2},{"url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/","name":"Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit","type":"news_article","credibility":1},{"url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/","name":"Hackers steal over $130M by exploiting bug in offline hardware wallets","type":"news_article","credibility":2}],"severity":"high"}],"timeline":[{"date":"2021-03","event":"Coinkite releases Coldcard firmware version 4.0.1, which, due to a build configuration error, causes affected devices to generate seeds using a weak software random number generator instead of the hardware entropy source. The flaw is not detected at the time.","source":"TRM Labs; Halborn","source_url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"date":"2026-07-30","event":"Attackers begin draining Coldcard wallets, exploiting the firmware entropy flaw to brute-force private keys without physical device access. An initial wave removes hundreds of BTC from affected addresses within minutes.","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack","date_evidence":"Beginning July 30, 2026, an attacker exploited a five-year-old firmware flaw"},{"date":"2026-08-03","event":"Fortune reports four attack waves have drained roughly 1,816 BTC (about $116 million) from more than 5,200 addresses; Coinkite issues a public statement calling it among the hardest periods in company history.","source":"Fortune","source_url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/","date_evidence":"August 3, 2026, 12:41 PM ET"},{"date":"2026-08-04","event":"TechCrunch reports cumulative losses have risen to roughly $130 million per Galaxy Research's updated tally, with potentially a dozen or more actors exploiting affected wallets; Coinkite's security advisory urges firmware updates and seed migration.","source":"TechCrunch","source_url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/","date_evidence":"August 4, 2026, 9:27 AM PDT"},{"date":"2026-08","event":"Coinkite releases patched firmware addressing the entropy fallback for the affected Mk2/Mk3 product lines, though the patch cannot retroactively secure seeds already generated on vulnerable firmware versions 4.0.1 through 4.1.9.","source":"Halborn","source_url":"https://www.halborn.com/blog/post/explained-the-coldcard-hack-july-2026"},{"date":"2026-08","event":"TRM Labs publishes a detailed analysis describing the incident as the largest hardware wallet exploit on record and the third-largest crypto hack of 2026 year-to-date, with 2026 crypto hack losses surpassing $1.2 billion across 276 incidents.","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"}],"sources_used":[{"url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack","name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack","type":"research","archive_url":"http://web.archive.org/web/20261005124255/https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack","credibility":2,"archive_timestamp":"2026-10-05T12:42:55+00:00"},{"url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/","name":"Hackers steal over $130M by exploiting bug in offline hardware wallets","type":"news_article","archive_url":"http://web.archive.org/web/20261007083244/https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/?","credibility":2,"archive_timestamp":"2026-10-07T08:32:44+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-coldcard-hack-july-2026","name":"Explained: The Coldcard Hack (July 2026)","type":"research","archive_url":"http://web.archive.org/web/20260923213702/https://www.halborn.com/blog/post/explained-the-coldcard-hack-july-2026","credibility":2,"archive_timestamp":"2026-09-23T21:37:02+00:00"},{"url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/","name":"Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit","type":"news_article","archive_url":"http://web.archive.org/web/20261006063952/https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/","credibility":1,"archive_timestamp":"2026-10-06T06:39:52+00:00"},{"url":"https://www.kucoin.com/news/flash/coldcard-wallet-exploit-steals-1-778-btc-worth-112m","name":"Coldcard Wallet Exploit Steals 1,778 BTC Worth $112M","type":"news_article","archive_url":"https://web.archive.org/web/20261011165234/https://www.kucoin.com/news/flash/coldcard-wallet-exploit-steals-1-778-btc-worth-112m","credibility":2,"archive_timestamp":"2026-10-11T16:52:34+00:00"},{"url":"https://kucoin.com/news/flash/coldcard-hack-drains-89m-in-btc-due-to-firmware-vulnerability","name":"Coldcard Hack Drains $89M in BTC Due to Firmware Vulnerability","type":"news_article","archive_url":"https://web.archive.org/web/20261011125434/https://www.kucoin.com/news/flash/coldcard-hack-drains-89m-in-btc-due-to-firmware-vulnerability","credibility":2,"archive_timestamp":"2026-10-11T12:54:34+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-code-investigator","created_at":"2026-10-11T12:07:34.542949+00:00","updated_at":"2026-10-11T16:54:20.542579+00:00"},"source_quality":{"total":6,"tier1":0,"tier2":1,"tier3":0,"unrated":5},"follower_count":null,"content_updated_at":"2026-10-11T12:07:34.872Z","last_fact_checked_at":null,"fact_check_next_allowed_at":null,"update_next_allowed_at":null}