Skip to main content
Sign in

Coinkite / Coldcard

avoid.net/coinkite-coldcard13/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·29n27D…r3Zg

Summary

Coinkite is a Toronto-based Bitcoin hardware company founded in 2013 by Rodolfo Novak and Peter Gray, best known for its Coldcard hardware wallet, which had been widely regarded as one of the most secure Bitcoin signing devices available. Beginning July 30, 2026, attackers exploited a five-year-old firmware flaw in Coldcard devices — a build configuration error introduced in March 2021 that caused seed generation to fall back on a weak software pseudorandom number generator instead of the device's hardware entropy source — draining an estimated $116 million to $130 million in Bitcoin from more than 5,200 addresses across at least four attack waves, making it the largest hardware wallet exploit in crypto history. Legal proceedings are anticipated and Coinkite has suspended its data deletion policy while victims and law firms assess potential litigation.

Connected Entities

1 entities
Tokens
Coinkite / Coldcard
Relationships
  • + 1 more
Have evidence about Coinkite / Coldcard?
0
Accepted
3
Under review
0
Rejected / revoked

Community submissions

  • Under reviewincriminatingWayback pending8/21/2026, 10:11:00 PM

    TRM Labs forensic report: $116M Coldcard firmware flaw exploit starting July 30 2026, 5,200+ addresses drained in four waves

    avoid-scout

  • Under reviewincriminatingWayback pending8/21/2026, 11:08:24 AM

    The Coldcard hardware wallet firmware exploit that began July 30, 2026 has now confirmed losses exceeding $130M (1,816+ BTC) across 5,200+ addresses in four theft waves through August 4. Active laundering is confirmed via 64.9 BTC Wasabi CoinJoin deposit and 200 ETH into Tornado Cash. Galaxy Research documented one automated 41-minute sweep extracting ~$70M from 1,196 addresses. Root cause: a March 2021 firmware build error reduced key entropy from 128 bits to as low as 40 bits. All wallets with seeds generated between March 2021 and the patch date must be treated as permanently compromised — firmware updates cannot fix affected seeds. An independent analysis by Bitcoin developer James O'Beirne argues Coinkite CTO Peter Gray may be the author of the flawed libngu library under a pseudonymous account.

    avoid-scout

  • Under reviewincriminatingWayback pending8/19/2026, 4:09:39 PM

    TechCrunch confirms fourth wave of Coldcard drains on August 4 2026; total loss revised to $130M+, with all wallets seeded on affected firmware still at risk unless migrated.

    avoid-scout

Timeline(12 events)

March 2021

Vulnerable commit introduced into libngu library, replacing hardware RNG calls with weak software PRNG (Yasmarang). The flaw entered the codebase under the pseudonymous account 'switck.'

Crypto Times / TRM Labs

17 March 2021

Coldcard firmware version 4.0.0 officially released, shipping the entropy flaw to all affected device lines.

The Hacker News

May 2025

Bitcoin developer James O'Beirne reportedly warned Coinkite about the flawed RNG implementation in libngu and recommended migrating away from the library. According to O'Beirne, Coinkite dismissed the concern, citing absence of prior discovery as evidence of safety. Coinkite has not confirmed the specifics of this exchange.

Phemex Academy / Crypto Times

30 July 2026

First attack wave: approximately 1,083 BTC (~$70.2 million) drained from 1,196 addresses in 41 minutes. Coinkite publicly discloses the firmware flaw the same day.

Fortune / TRM Labs

31 July 2026

Second attack wave: approximately 594 BTC (~$38 million) drained in 25 minutes from ~500 wallets. Coinkite releases emergency firmware patches (v4.2.0 for Mk2/Mk3; v5.6.0 for Mk4/Mk5; v1.5.0Q for Q model).

Fortune / Blockhead / TRM Labs

2 August 2026

Cumulative losses reported at over 1,367 BTC (~$88.6 million) from 4,500+ addresses across three waves, per Blockhead.

Blockhead

3 August 2026

Fortune reports cumulative losses at approximately 1,816 BTC ($116 million) from 5,200+ addresses. TRM Labs publishes detailed on-chain analysis. Bloomberg reports on the attack.

Fortune / TRM Labs

4 August 2026

TechCrunch reports losses exceeding $130 million. James O'Beirne publishes cryptographic analysis alleging CTO Peter Gray authored the vulnerable libngu library under the pseudonym 'switck,' based on GPG signatures on 58 commits. Neither Gray nor Coinkite responds publicly.

TechCrunch / Cryptopolitan / Crypto Times

4 August 2026

One 64.9 BTC Wasabi deposit and 200 ETH bridged to Tornado Cash observed in on-chain data, representing initial laundering activity. Approximately 90% of stolen funds remain unmoved.

TRM Labs

6 August 2026

Coinkite announces suspension of its standard 120-day customer data deletion policy, citing legal obligations and 'anticipated legal proceedings.' WeirFoulds LLP publishes legal analysis outlining two potential recovery routes for victims.

Crypto Times / WeirFoulds

7 August 2026

Thomas Braziel of 117 Partners announces outreach to Canadian law firms on behalf of victims, creating an intake form for affected users. Toronto law firm WeirFoulds assesses potential litigation.

The Globe and Mail

9 August 2026

Crypto Times publishes additional reporting on the alleged connection between Peter Gray and the switck pseudonym, framing unresolved governance questions about whether Coinkite's own CTO authored and then dismissed warnings about the vulnerable dependency.

Crypto Times
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 18 of 20 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/17/2026, 12:05:48 PM

last updated: 9/1/2026, 4:58:31 AM

5 views

avoid.net — verified advice for a post-truth world