Skip to main content
Sign in

Audit log

Every state-changing event for Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-05 23:06:39Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    BMC3R4ePWtKW…bHeuoa8Rsha256 → base58
    verifying row…
    canonical bytes (30224 B) ▸
    {"actor":"system:backfill","investigation_id":"1432a256-9098-4bcb-8698-a7e4ea73c243","kind":"publish","page_slug":"coldcard-coinkite-august-2026-multi-actor-attacker-cluster","published_at":"2026-08-05T23:06:38.985Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster","sections":[{"content":"Galaxy Research, led by Head of Research Alex Thorn, identified at least 15 distinct attacking entities through on-chain behavioral fingerprinting. Each attacker cluster was catalogued alphabetically as a 'Footprint,' running from Footprint A through Footprint O as of August 4, 2026. The fifteenth footprint (O) was identified only after a victim reported a loss of under 1 BTC, which allowed Galaxy to trace a previously uncatalogued attacker who had moved approximately 12 BTC across 126 addresses. Galaxy cautioned that the 15 clusters do not necessarily represent 15 individuals — some addresses may be controlled by the same person or group, and additional attackers may remain unidentified. The firm assessed that early waves were likely attributable to single coordinated operators per wave, while later smaller footprints indicate numerous independent actors exploiting the now-public vulnerability. The attack evolved from coordinated large sweeps into what Galaxy described as an open free-for-all after technical details became publicly accessible.","heading":"Attacker Cluster Identification and Scale","severity":"critical","sources":[{"credibility":2,"name":"15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/coldcard-exploit-15-attackers-130m-losses-galaxy/"},{"credibility":2,"name":"15 attackers now draining vulnerable Coldcard wallets, report — Protos","type":"news_article","url":"https://protos.com/15-attackers-now-draining-vulnerable-coldcard-wallets-report/"},{"credibility":2,"name":"At least 15 attackers exploited Coldcard vulnerability: Galaxy — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/15-attackers-exploited-coldcard-vulnerability-galaxy"},{"credibility":2,"name":"COLDCARD Bitcoin Theft Tops $102M as Investigators Track at Least 15 Attacker Patterns — AlexaBlockchain","type":"news_article","url":"https://alexablockchain.com/coldcard-bitcoin-theft-tops-102m-as-investigators-track-at-least-15-attacker-patterns/"},{"credibility":2,"name":"Coldcard Hack Update: At Least 15 Attackers Exploited Wallet Flaw — CoinPaper","type":"news_article","url":"https://coinpaper.com/33908/coldcard-hack-update-at-least-15-attackers-exploited-wallet-flaw"}]},{"content":"Galaxy Research's confirmed tally as of August 4, 2026 stands at 1,596 BTC (valued at approximately $102.2 million at prevailing prices) drained from roughly 7,300 victim addresses across three major attack waves plus 14 smaller footprints. A suspected fourth wave, assessed by Galaxy at 'medium-high confidence' but not yet confirmed through victim reports, would raise the aggregate to approximately 2,055 BTC, or roughly $130 million, across more than 7,700 victim addresses. Wave 1, occurring July 31, 2026 between 01:31 and 01:56 UTC, swept 1,082.65 BTC from approximately 1,196 addresses in roughly 41 minutes, with 562 BTC subsequently consolidated into a single address. Waves 2 and 3 brought the confirmed total to 1,367.05 BTC across 4,585 addresses. Wave 4 was observed live on August 3, 2026, sweeping an estimated 388.9–448.7 BTC across 462–709 victim addresses within approximately 2.5 hours. Loss estimates escalated from approximately $38 million at initial discovery, to $88.6 million by the weekend, to over $100 million confirmed by August 4, 2026.","heading":"Stolen Funds: Confirmed Amounts and Wave Breakdown","severity":"critical","sources":[{"credibility":2,"name":"Bitcoin losses from Coldcard hack could swell to $130 million, Galaxy Research says — The Block","type":"news_article","url":"https://www.theblock.co/post/410533/coldcard-hack-130-million-galaxy-research"},{"credibility":2,"name":"Coldcard Hack Losses Hit $100M With 1,596 BTC Stolen in Ongoing Attack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/coldcard-hack-losses-hit-100m-with-1596-btc-stolen/"},{"credibility":2,"name":"Coldcard Hack Enters Wave 4: 449 BTC Swept Live as Victims Race to Save Funds — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/03/coldcard-hack-enters-wave-4-449-btc-swept-live-as-victims-race-to-save-funds/"},{"credibility":1,"name":"Hackers steal over $130M by exploiting bug in offline hardware wallets — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"credibility":1,"name":"Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep"}]},{"content":"Galaxy Research attributed attacker clusters primarily through on-chain behavioral signatures rather than off-chain identity information. The fingerprinting methodology included analysis of consistent fee rates — notably a recurring 30 sat/vB no-change signature — as well as batching patterns, sweep timing relative to block confirmations, and the aggregation behavior of receiving addresses. Galaxy Research measured Wave 1's sweep rate at approximately 13.8 transfers per block against a pre-incident baseline of 0.3 per block, which Thorn described as 'the fingerprint of an automated pipeline chewing through a pre-computed list of vulnerable keys against a live mempool.' Galaxy also noted that the sweeps were assessed as 'probably orchestrated with a large language model,' though this characterization was not independently confirmed. One confirmed consolidation address from Wave 1 is bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r, verified by both Galaxy Research and Arkham Intelligence. Wave 1's funds were further consolidated to address bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0 (594.47 BTC from 501 outputs). Additional cluster addresses include bc1qx76cae2706qd5q576feh7xq8rfcsjpf2htfhe3 (approximately 398.48 BTC from 491 inputs) and bc1q8jy96fe5lf8vfugydnte3cguk92gpev7kwtp3q (approximately 89.62 BTC from 204 inputs). Galaxy cautioned that transaction-sweep patterns are not uniquely distinguishable from a legitimate wallet owner voluntarily moving funds, which complicates definitive on-chain attribution.","heading":"Transaction Fingerprinting and On-Chain Attribution Methodology","severity":"high","sources":[{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"credibility":1,"name":"Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep"},{"credibility":2,"name":"Coldcard Hacker's Wallet Turns Into On-Chain Public Bulletin Board — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/05/coldcard-hacker-wallet-turns-into-on-chain-public-bulletin-board/"},{"credibility":2,"name":"Coldcard Attack Widens: 15 Hackers Drain $130M in Bitcoin — DailyCoin","type":"news_article","url":"https://dailycoin.com/coldcard-wallet-attack-hackers-drain-130m-in-bitcoin/"}]},{"content":"As of August 4–5, 2026, Galaxy Research reported that approximately 90% of all confirmed stolen BTC remains unmoved in attacker-controlled addresses. Furthermore, 100% of funds from the first three confirmed attack waves have not moved from their identified attacker wallet destinations. The average targeted wallet had been dormant for approximately 3.18 years before being swept, indicating the victim population consisted disproportionately of long-term Bitcoin holders. The concentration of funds in identified, static on-chain addresses creates a narrow window for potential intervention by law enforcement or exchange compliance teams; however, Galaxy Research offered no guarantees of recovery. The dormancy pattern is consistent with attackers timing movements to allow exchange monitoring alerts — which often use recently flagged addresses — to lapse or degrade. A subset of attackers has reportedly begun cross-chain conversion, with some BTC alleged to have been swapped to Ethereum via THORChain and routed through Tornado Cash, though the scale of these movements relative to total stolen funds is not independently confirmed at the time of this investigation.","heading":"Dormant Fund Status and Liquidation Risk","severity":"critical","sources":[{"credibility":2,"name":"15 attackers now draining vulnerable Coldcard wallets, report — Protos","type":"news_article","url":"https://protos.com/15-attackers-now-draining-vulnerable-coldcard-wallets-report/"},{"credibility":2,"name":"Coldcard Hack Losses Hit $100M With 1,596 BTC Stolen in Ongoing Attack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/coldcard-hack-losses-hit-100m-with-1596-btc-stolen/"},{"credibility":2,"name":"Coldcard Hacker's Wallet Turns Into On-Chain Public Bulletin Board — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/05/coldcard-hacker-wallet-turns-into-on-chain-public-bulletin-board/"},{"credibility":2,"name":"15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/coldcard-exploit-15-attackers-130m-losses-galaxy/"}]},{"content":"The underlying vulnerability exploited by the attacker cluster originated in Coldcard firmware version 4.0.0, released March 1, 2021. A firmware integration error caused affected devices to route wallet seed generation through MicroPython's Yasmarang software pseudorandom number generator (PRNG) — initialized only from the chip's UID and timer registers, neither of which is secret — rather than the intended STM32 hardware random number generator (RNG). This reduced effective entropy to approximately 40 bits on Mk2/Mk3 devices and approximately 72 bits on Mk4/Mk5/Q devices, versus the 128-bit standard for a 12-word BIP-39 seed. Attackers did not require physical access to the hardware device; instead, they precomputed candidate seed phrases offline and monitored associated Bitcoin addresses on the public blockchain for balances. The exploit method became accessible to actors with basic Python skills after technical details entered public discourse. Dragonfly managing partner Haseeb Qureshi stated that AI models reportedly rediscovered the vulnerability in under 20 minutes, though crypto analytics firm Tokenomist disputed the source of that claim as deriving from a pseudonymous Reddit user who scanned code after the vulnerability was already public. Affected firmware versions include Mk2/Mk3 versions 4.0.0 through 4.1.9, Mk4/Mk5 versions prior to 5.6.0, and Q model versions prior to 1.5.0Q. Wallets generated using the dice-roll option with 50 or more manual rolls are not considered affected.","heading":"Exploitation Method and Open-Market Entry","severity":"critical","sources":[{"credibility":2,"name":"A five-year-old Coldcard bug let hackers guess bitcoin wallet keys, Coinkite confirms — Blockhead","type":"news_article","url":"https://www.blockhead.co/2026/08/03/coldcard-hardware-wallets-shipped-with-broken-randomness-for-five-years-coinkite-confirms/"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"credibility":2,"name":"At least 15 attackers exploited Coldcard vulnerability: Galaxy — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/15-attackers-exploited-coldcard-vulnerability-galaxy"},{"credibility":3,"name":"Exploiting Coinkite's RNG Egregious Problem — AkitaOnRails","type":"research","url":"https://akitaonrails.com/en/2026/08/01/exploiting-coinkites-rng-egregious-problem/"},{"credibility":1,"name":"Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"}]},{"content":"Galaxy Research supplied approximately 600 suspected attacker-controlled addresses to U.S. federal law enforcement, major cryptocurrency exchanges, compliance firms, cyber investigators, and the Security Alliance (SEAL), a non-profit providing 24/7 incident response coordination for the crypto industry. Coinkite stated that its legal team 'will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible.' At least 73 individual victims had engaged directly with Galaxy Research as of August 4, 2026, and victim reports were instrumental in identifying previously unknown attacker footprints, including the discovery of Footprint O. No public arrests, indictments, or fund seizures had been announced as of August 5, 2026. On-chain messaging activity has been documented at the primary Wave 1 consolidation address bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r, where users have sent OP_RETURN-embedded messages appealing for fund returns; one such embedded message constituted an alleged money-laundering solicitation offering a 10% fee for KYC bypass services. The identity of the actors behind any specific footprint has not been publicly confirmed by law enforcement or Galaxy Research.","heading":"Law Enforcement Cooperation and Exchange Monitoring","severity":"high","sources":[{"credibility":2,"name":"Coldcard Hack Losses Hit $100M With 1,596 BTC Stolen in Ongoing Attack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/coldcard-hack-losses-hit-100m-with-1596-btc-stolen/"},{"credibility":1,"name":"Update, Sunday — Coinkite Official Blog","type":"official","url":"https://blog.coinkite.com/update-sunday/"},{"credibility":2,"name":"Coldcard Hacker's Wallet Turns Into On-Chain Public Bulletin Board — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/05/coldcard-hacker-wallet-turns-into-on-chain-public-bulletin-board/"},{"credibility":2,"name":"Coldcard Hacker Gets Brazen Bitcoin Laundering Offer Onchain — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/crypto-news/coldcard-hacker-gets-brazen-bitcoin-laundering-offer-onchain/"},{"credibility":1,"name":"What we know about ongoing Coldcard hack that's stolen over $100M worth of bitcoin — CBC News","type":"news_article","url":"https://www.cbc.ca/news/world/bitcoin-coinkite-security-hack-9.7295582"}]},{"content":"A subset of the identified attacker cluster is alleged to have begun converting stolen BTC to other assets using cross-chain infrastructure. Reporting as of August 5, 2026 indicates that some stolen Bitcoin was allegedly swapped to Ethereum via THORChain and subsequently routed through Tornado Cash. The scale of these alleged movements has not been independently confirmed relative to the total stolen pool of approximately 1,596–2,055 BTC. The COLDCARD Bitcoin Theft investigation by AlexaBlockchain also identified attacker use of peel chains, routing through offshore gambling platforms (including a platform identified as 'Duel,' where funds were reportedly withdrawn before account-level freezes could be applied), and cross-chain conversion strategies. These laundering vectors, if confirmed at scale, would significantly complicate recovery efforts. The large majority of funds — approximately 90% per Galaxy Research — remain on-chain and unspent as of August 4–5, 2026, and traceable by on-chain analytics firms and law enforcement.","heading":"Alleged Laundering Activity and Cross-Chain Movement","severity":"high","sources":[{"credibility":2,"name":"Coldcard Hacker's Wallet Turns Into On-Chain Public Bulletin Board — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/05/coldcard-hacker-wallet-turns-into-on-chain-public-bulletin-board/"},{"credibility":2,"name":"COLDCARD Bitcoin Theft Tops $102M as Investigators Track at Least 15 Attacker Patterns — AlexaBlockchain","type":"news_article","url":"https://alexablockchain.com/coldcard-bitcoin-theft-tops-102m-as-investigators-track-at-least-15-attacker-patterns/"},{"credibility":2,"name":"15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/coldcard-exploit-15-attackers-130m-losses-galaxy/"}]},{"content":"No confirmed off-chain identities have been attributed to any of the 15 attacker footprints as of August 5, 2026. Galaxy Research noted that the cluster count may understate the true number of actors, and that some identified addresses may be controlled by the same individual or group across multiple footprints. Investigators have not linked the incident to any known state-sponsored threat group, including those previously associated with North Korea or Russia, though such attribution has not been publicly ruled out. The public availability of the exploit methodology — now accessible to actors with basic Python skills — means additional unidentified actors may continue to drain remaining vulnerable wallets. Galaxy Research characterized the threat as 'still ongoing' as of August 4, 2026, and Coinkite's emergency firmware update does not remediate seeds already generated under the vulnerable firmware, meaning funds in legacy wallets remain at risk until moved.","heading":"Attribution Gaps and Unknown Actor Risk","severity":"high","sources":[{"credibility":1,"name":"Coldcard Hack: $116 Million Bitcoin Stolen Via Firmware Flaw — Forbes","type":"news_article","url":"https://www.forbes.com/sites/boazsobrado/2026/08/04/i-did-everything-right-ai-warning-after-116-million-bitcoin-hack/"},{"credibility":2,"name":"15 attackers now draining vulnerable Coldcard wallets, report — Protos","type":"news_article","url":"https://protos.com/15-attackers-now-draining-vulnerable-coldcard-wallets-report/"},{"credibility":2,"name":"Bitcoin's $88M ColdCard Hack Isn't Over: Experts Warn All Vulnerable Wallets Will Eventually Be Drained — IBTimes UK","type":"news_article","url":"https://www.ibtimes.co.uk/cryptocurrency-theft-coldcard-wallets-users-urged-act-1811991"},{"credibility":1,"name":"What we know about ongoing Coldcard hack that's stolen over $100M worth of bitcoin — CBC News","type":"news_article","url":"https://www.cbc.ca/news/world/bitcoin-coinkite-security-hack-9.7295582"}]}],"sources_used":[{"credibility":2,"name":"15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/coldcard-exploit-15-attackers-130m-losses-galaxy/"},{"credibility":2,"name":"15 attackers now draining vulnerable Coldcard wallets, report — Protos","type":"news_article","url":"https://protos.com/15-attackers-now-draining-vulnerable-coldcard-wallets-report/"},{"credibility":2,"name":"At least 15 attackers exploited Coldcard vulnerability: Galaxy — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/15-attackers-exploited-coldcard-vulnerability-galaxy"},{"credibility":2,"name":"Bitcoin losses from Coldcard hack could swell to $130 million, Galaxy Research says — The Block","type":"news_article","url":"https://www.theblock.co/post/410533/coldcard-hack-130-million-galaxy-research"},{"credibility":2,"name":"Coldcard Hack Update: At Least 15 Attackers Exploited Wallet Flaw — CoinPaper","type":"news_article","url":"https://coinpaper.com/33908/coldcard-hack-update-at-least-15-attackers-exploited-wallet-flaw"},{"credibility":2,"name":"Coldcard Hack Losses Hit $100M With 1,596 BTC Stolen in Ongoing Attack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/coldcard-hack-losses-hit-100m-with-1596-btc-stolen/"},{"credibility":2,"name":"Coldcard Hack Enters Wave 4: 449 BTC Swept Live as Victims Race to Save Funds — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/03/coldcard-hack-enters-wave-4-449-btc-swept-live-as-victims-race-to-save-funds/"},{"credibility":2,"name":"Coldcard Hack Hits $75M After Alleged Second Attack Wave: Galaxy Research — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/01/coldcard-hack-hits-75m-after-alleged-second-attack-wave-galaxy-research/"},{"credibility":2,"name":"Coldcard Hack Tops $88.6M as Galaxy Finds Third Attack Wave — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/02/coldcard-hack-tops-88-6m-as-galaxy-finds-third-attack-wave/"},{"credibility":2,"name":"Coldcard Hacker's Wallet Turns Into On-Chain Public Bulletin Board — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/05/coldcard-hacker-wallet-turns-into-on-chain-public-bulletin-board/"},{"credibility":2,"name":"COLDCARD Bitcoin Theft Tops $102M as Investigators Track at Least 15 Attacker Patterns — AlexaBlockchain","type":"news_article","url":"https://alexablockchain.com/coldcard-bitcoin-theft-tops-102m-as-investigators-track-at-least-15-attacker-patterns/"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"credibility":1,"name":"Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep"},{"credibility":1,"name":"Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million"},{"credibility":1,"name":"BTC news: Coldcard urges users to move bitcoin as active wallet exploit continues — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/04/coldcard-urges-users-to-move-bitcoin-as-active-wallet-exploit-continues"},{"credibility":1,"name":"Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"credibility":1,"name":"Hackers steal over $130M by exploiting bug in offline hardware wallets — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"credibility":1,"name":"Coldcard Hack: $116 Million Bitcoin Stolen Via Firmware Flaw — Forbes","type":"news_article","url":"https://www.forbes.com/sites/boazsobrado/2026/08/04/i-did-everything-right-ai-warning-after-116-million-bitcoin-hack/"},{"credibility":1,"name":"Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit — Fortune","type":"news_article","url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/"},{"credibility":1,"name":"What we know about ongoing Coldcard hack that's stolen over $100M worth of bitcoin — CBC News","type":"news_article","url":"https://www.cbc.ca/news/world/bitcoin-coinkite-security-hack-9.7295582"},{"credibility":1,"name":"Update, Sunday — Coinkite Official Blog","type":"official","url":"https://blog.coinkite.com/update-sunday/"},{"credibility":2,"name":"A five-year-old Coldcard bug let hackers guess bitcoin wallet keys, Coinkite confirms — Blockhead","type":"news_article","url":"https://www.blockhead.co/2026/08/03/coldcard-hardware-wallets-shipped-with-broken-randomness-for-five-years-coinkite-confirms/"},{"credibility":2,"name":"Coldcard Hardware Wallet Hack Drains $89m: What It Means — IG UK","type":"news_article","url":"https://www.ig.com/uk/trading-strategies/coldcard-hardware-wallet-hack-self-custody-260803"},{"credibility":2,"name":"Coldcard Attack Widens: 15 Hackers Drain $130M in Bitcoin — DailyCoin","type":"news_article","url":"https://dailycoin.com/coldcard-wallet-attack-hackers-drain-130m-in-bitcoin/"},{"credibility":2,"name":"Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets — Decrypt","type":"news_article","url":"https://decrypt.co/374817/coldcard-bitcoin-exploit-88-million-attackers-draining-wallets"},{"credibility":2,"name":"Coldcard Hacker Gets Brazen Bitcoin Laundering Offer Onchain — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/crypto-news/coldcard-hacker-gets-brazen-bitcoin-laundering-offer-onchain/"},{"credibility":2,"name":"Coldcard's $130 million crisis is pushing Bitcoin back into Wall Street's hands — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/coldcards-130-million-crisis-is-pushing-bitcoin-back-into-wall-streets-hands/"},{"credibility":2,"name":"Coldcard exploit now hits 4,585 wallets - Attacker still holds $88.6M stolen BTC — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/coldcard-exploit-now-hits-4585-wallets-attacker-still-holds-88-6m-stolen-btc/"},{"credibility":2,"name":"Bitcoin's $88M ColdCard Hack Isn't Over: Experts Warn All Vulnerable Wallets Will Eventually Be Drained — IBTimes UK","type":"news_article","url":"https://www.ibtimes.co.uk/cryptocurrency-theft-coldcard-wallets-users-urged-act-1811991"},{"credibility":2,"name":"Alex Thorn Warns Of Fourth Apparent BTC Theft Wave Targeting Coldcard Users — BitcoinWorld","type":"news_article","url":"https://bitcoinworld.co.in/alex-thorn-coldcard-btc-theft-wave/"},{"credibility":3,"name":"Exploiting Coinkite's RNG Egregious Problem — AkitaOnRails","type":"research","url":"https://akitaonrails.com/en/2026/08/01/exploiting-coinkites-rng-egregious-problem/"}],"summary":"Beginning July 31, 2026, at least 15 distinct threat actors exploited a five-year-old firmware vulnerability in Coldcard hardware wallets to drain an estimated 1,596–2,055 BTC (approximately $100–130 million) from over 7,300 victim addresses. Galaxy Research identified each actor by behavioral fingerprints — labeling them Footprints A through O — and shared roughly 600 suspected attacker-controlled addresses with U.S. federal law enforcement, crypto exchanges, and compliance firms. As of August 4–5, 2026, approximately 90% of confirmed stolen funds remain dormant in identified on-chain addresses, with 100% of funds from the first three attack waves unmoved, suggesting actors are timing exchange-monitoring windows before attempting liquidation.","timeline":[{"date":"2021-03-01","event":"Coldcard firmware 4.0.0 released containing an integration error that routed seed generation to a software PRNG instead of the hardware RNG, introducing the vulnerability.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"date":"2026-07-31","event":"Wave 1: Approximately 1,082.65 BTC swept from 1,196 addresses between 01:31 and 01:56 UTC in roughly 41 minutes. 562 BTC consolidated to address bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.","source":"CoinDesk / The Hacker News","source_url":"https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep"},{"date":"2026-08-01","event":"Wave 2 identified. Galaxy Research reports total losses reached approximately $75 million. Coinkite issues advisory urging users to move funds.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/01/coldcard-hack-hits-75m-after-alleged-second-attack-wave-galaxy-research/"},{"date":"2026-08-02","event":"Wave 3 identified. Galaxy Research confirms losses have reached approximately $88.6 million across 4,585 addresses (1,367.05 BTC). Coinkite publishes official blog update confirming the vulnerability and emergency firmware patches.","source":"CryptoTimes / Coinkite Blog","source_url":"https://www.cryptotimes.io/2026/08/02/coldcard-hack-tops-88-6m-as-galaxy-finds-third-attack-wave/"},{"date":"2026-08-03","event":"Wave 4 observed live. Approximately 388.9–448.7 BTC swept from 462–709 victim addresses within 2.5 hours. Galaxy Research puts total losses at approximately $114 million.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/03/coldcard-hack-enters-wave-4-449-btc-swept-live-as-victims-race-to-save-funds/"},{"date":"2026-08-04","event":"Galaxy Research confirms at least 15 distinct attacking entities (Footprints A through O), with confirmed losses of 1,596 BTC (~$100M+) and suspected total of 2,055 BTC (~$130M). Galaxy reports approximately 600 attacker addresses to U.S. federal law enforcement, exchanges, and compliance firms. 73 victims engaged directly with researchers.","source":"CryptoTimes / CoinTelegraph / The Block","source_url":"https://www.cryptotimes.io/2026/08/04/coldcard-exploit-15-attackers-130m-losses-galaxy/"},{"date":"2026-08-04","event":"CoinDesk reports Coldcard urging all users to move funds as exploit remains active. Forbes, TechCrunch, and Fortune publish major coverage of the incident.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2026/08/04/coldcard-urges-users-to-move-bitcoin-as-active-wallet-exploit-continues"},{"date":"2026-08-05","event":"On-chain messaging activity documented at primary Wave 1 consolidation address. At least one OP_RETURN message offering unsolicited money-laundering services identified. 90% of stolen BTC remains unmoved. No arrests or fund seizures announced.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/05/coldcard-hacker-wallet-turns-into-on-chain-public-bulletin-board/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 383e3b08-4643-4071-b9ba-18e5df2258e8
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.