Skip to main content
AVOID.NET

Fact-check findings

What an automated fact-checker found when it re-read Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

7 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #1[disputed][awaiting moderator]in the summary
    Beginning July 31, 2026
    reviewerWave 1 of the theft began on July 31, 2026Multiple independent sources (Protos timeline, an independent on-chain technical writeup) place Wave 1 at July 30, 2026, not July 31. The cited CoinDesk article is dated July 31 because that is when the news broke, one day after the sweep.
    Proposed correction (not yet applied)
    Beginning July 30, 2026
  2. #6[disputed][awaiting moderator]in section: Attacker Cluster Identification and Scale
    led by Head of Research Alex Thorn
    reviewerGalaxy Research is led by Head of Research Alex ThornMinor but verifiable title inaccuracy; his official title includes 'Firmwide.'
    Proposed correction (not yet applied)
    led by Head of Firmwide Research Alex Thorn
  3. #11[disputed][awaiting moderator]in section: Stolen Funds: Confirmed Amounts and Wave Breakdown
    Wave 1, occurring July 31, 2026 between 01:31 and 01:56 UTC, swept 1,082.65 BTC from approximately 1,196 addresses in roughly 41 minutes
    reviewerWave 1 swept 1,082.65 BTC from ~1,196 addresses between 01:31 and 01:56 UTC on July 31, 2026, in ~41 minutesThe stated window (01:31-01:56) is only 25 minutes, internally inconsistent with the sentence's own '41 minutes' claim, and does not match independent on-chain timelines, which place the sweep at 01:10-01:51 UTC on July 30.
    Proposed correction (not yet applied)
    Wave 1, occurring July 30, 2026 between 01:10 and 01:51 UTC, swept 1,082.65 BTC from approximately 1,196 addresses in roughly 41 minutes
  4. #18[disputed][awaiting moderator]in section: Exploitation Method and Open-Market Entry
    originated in Coldcard firmware version 4.0.0, released March 1, 2021
    reviewerThe vulnerability originated in Coldcard firmware version 4.0.0, released March 1, 2021The page conflates the internal code-commit date with the public firmware release date; the same error recurs in the timeline entry's date_original field.
    Proposed correction (not yet applied)
    originated in Coldcard firmware version 4.0.0, released March 17, 2021
  5. #32[disputed][awaiting moderator]in the timeline
    2021-03-01
    reviewerFirmware 4.0.0 was released on 2021-03-01, introducing the vulnerabilitySame underlying error as the sections[4] finding; the stored date_original field should reflect the public release date, not the commit date.
    Proposed correction (not yet applied)
    2021-03-17
  6. #33[disputed][awaiting moderator]in the timeline
    2026-07-31
    reviewerWave 1 occurred on 2026-07-31Timeline date field should match the actual sweep date (July 30), not the date the news broke (July 31).
    Proposed correction (not yet applied)
    2026-07-30
  7. #34[disputed][awaiting moderator]in the timeline
    between 01:31 and 01:56 UTC in roughly 41 minutes
    reviewerWave 1 occurred between 01:31 and 01:56 UTCThe stated 01:31-01:56 window is only 25 minutes, internally inconsistent with the event text's own '41 minutes' and with independent on-chain analysis.
    Proposed correction (not yet applied)
    between 01:10 and 01:51 UTC in roughly 41 minutes

unverifiable

1 claim

No source the reviewer could reach confirms or contradicts the claim.

  1. #17[unverifiable][awaiting moderator]in section: Transaction Fingerprinting and On-Chain Attribution Methodology
    Additional cluster addresses include bc1qx76cae2706qd5q576feh7xq8rfcsjpf2htfhe3 (approximately 398.48 BTC from 491 inputs) and bc1q8jy96fe5lf8vfugydnte3cguk92gpev7kwtp3q (approximately 89.62 BTC from 204 inputs).
    reviewerAdditional cluster addresses moved ~398.48 BTC (491 inputs) and ~89.62 BTC (204 inputs)Plausible and consistent with the page's overall reporting on wallet consolidation, but the specific per-address BTC and input counts could not be independently verified with the tools available.

stale

4 claims

The claim was accurate when written but events since have overtaken it.

  1. #2[stale][awaiting moderator]in the summary
    at least 15 distinct threat actors
    reviewerAt least 15 distinct threat actors have exploited the vulnerabilityThe 15-attacker figure was accurate as of August 4, 2026 but was superseded within two weeks by Galaxy Research's own revised count of over 33 footprints; the page presents the number without a time-bound qualifier in the summary.
    Proposed correction (not yet applied)
    at least 33 distinct threat actors
  2. #5[stale][awaiting moderator]in the summary
    with 100% of funds from the first three attack waves unmoved
    reviewerAs of Aug 4-5, 2026, ~90% of stolen funds remain dormant, with 100% of Wave 1-3 funds unmovedThe 100%/90% figures were accurate on August 4-5, 2026, the date the page cites, but have since been superseded by Galaxy Research's own follow-up reporting showing active cash-out from the Wave 3 cluster.
    Proposed correction (not yet applied)
    though by September 2026 Galaxy Research reported dormancy had fallen to approximately 82%, with the Wave 3 cluster actively cashing out via THORChain and CoinJoin transactions
  3. #7[stale][awaiting moderator]in section: Attacker Cluster Identification and Scale
    identified at least 15 distinct attacking entities through on-chain behavioral fingerprinting
    reviewerGalaxy Research identified at least 15 distinct attacking entities through on-chain behavioral fingerprintingSame underlying staleness as the summary's 15-attacker figure.
    Proposed correction (not yet applied)
    identified at least 33 distinct attacking entities through on-chain behavioral fingerprinting
  4. #27[stale][awaiting moderator]in section: Dormant Fund Status and Liquidation Risk
    Furthermore, 100% of funds from the first three confirmed attack waves have not moved from their identified attacker wallet destinations.
    reviewerAs of Aug 4-5, 2026, ~90% of stolen BTC remains unmoved, 100% of Wave 1-3 funds unmovedAccurate as of the page's stated date but materially superseded by subsequent Galaxy Research reporting.
    Proposed correction (not yet applied)
    Furthermore, as of early August 2026, 100% of funds from the first three confirmed attack waves had not moved from their identified attacker wallet destinations; by September 2026, Galaxy Research reported the Wave 3 cluster had begun actively cashing out via THORChain and CoinJoin transactions, lowering overall dormancy across the exploit to approximately 82%.

partially supported

1 claim

The cited evidence supports part of the claim but not all of it.

  1. #21[partially supported][awaiting moderator]in section: Exploitation Method and Open-Market Entry
    Dragonfly managing partner Haseeb Qureshi stated that AI models reportedly rediscovered the vulnerability in under 20 minutes, though crypto analytics firm Tokenomist disputed the source of that claim as deriving from a pseudonymous Reddit user who scanned code after the vulnerability was already public.
    reviewerHaseeb Qureshi said AI reportedly rediscovered the vulnerability in under 20 minutes; Tokenomist disputed the source as a pseudonymous Reddit user who scanned public codeThe page conflates two distinct claims from its own cited article: Qureshi's 20-minute figure (from a claimed blind GLM-5.2 test) and a separate, faster 2-minute viral claim that Tokenomist specifically traced to an after-the-fact Reddit demonstration. Presenting Tokenomist's rebuttal as directed at Qureshi's claim overstates the connection between the two.

confirmed

21 claims

The cited evidence supports the claim as written.

  1. #3[confirmed][no action needed]in the summary
    drain an estimated 1,596–2,055 BTC (approximately $100–130 million) from over 7,300 victim addresses
    reviewerThe attack drained an estimated 1,596-2,055 BTC (~$100-130M) from over 7,300 victim addressesFigures are consistent across multiple independent outlets reporting on the same Galaxy Research data as of August 4, 2026.
  2. #4[confirmed][no action needed]in the summary
    shared roughly 600 suspected attacker-controlled addresses with U.S. federal law enforcement, crypto exchanges, and compliance firms
    reviewerGalaxy Research shared roughly 600 suspected attacker addresses with US federal law enforcement, exchanges, and compliance firmsCorroborated by contemporaneous reporting.
  3. #8[confirmed][no action needed]in section: Attacker Cluster Identification and Scale
    running from Footprint A through Footprint O as of August 4, 2026
    reviewerFootprints were catalogued A through O as of August 4, 2026Unlike the unqualified '15 distinct threat actors' claims elsewhere, this sentence correctly scopes the count to a specific date.
  4. #9[confirmed][no action needed]in section: Attacker Cluster Identification and Scale
    The fifteenth footprint (O) was identified only after a victim reported a loss of under 1 BTC, which allowed Galaxy to trace a previously uncatalogued attacker who had moved approximately 12 BTC across 126 addresses.
    reviewerFootprint O was identified after a victim reported a loss of under 1 BTC, tracing an attacker who moved ~12 BTC across 126 addressesFigures independently corroborated.
  5. #10[confirmed][no action needed]in section: Attacker Cluster Identification and Scale
    Galaxy cautioned that the 15 clusters do not necessarily represent 15 individuals — some addresses may be controlled by the same person or group, and additional attackers may remain unidentified.
    reviewerGalaxy cautioned that the 15 clusters may not represent 15 individualsConsistent with multiple analytics firms' cautious framing of attribution.
  6. #12[confirmed][no action needed]in section: Stolen Funds: Confirmed Amounts and Wave Breakdown
    Waves 2 and 3 brought the confirmed total to 1,367.05 BTC across 4,585 addresses.
    reviewerWaves 2 and 3 brought the confirmed total to 1,367.05 BTC across 4,585 addressesMatches independent reporting.
  7. #13[confirmed][no action needed]in section: Stolen Funds: Confirmed Amounts and Wave Breakdown
    Wave 4 was observed live on August 3, 2026, sweeping an estimated 388.9–448.7 BTC across 462–709 victim addresses within approximately 2.5 hours.
    reviewerWave 4 swept an estimated 388.9-448.7 BTC across 462-709 addresses within ~2.5 hours, observed live August 3, 2026Confirmed by the cited source.
  8. #14[confirmed][no action needed]in section: Stolen Funds: Confirmed Amounts and Wave Breakdown
    Loss estimates escalated from approximately $38 million at initial discovery, to $88.6 million by the weekend, to over $100 million confirmed by August 4, 2026.
    reviewerLoss estimates escalated from ~$38M to $88.6M to over $100M by August 4, 2026Escalation sequence matches the dated headlines in the page's own source list.
  9. #15[confirmed][no action needed]in section: Transaction Fingerprinting and On-Chain Attribution Methodology
    Galaxy Research measured Wave 1's sweep rate at approximately 13.8 transfers per block against a pre-incident baseline of 0.3 per block, which Thorn described as 'the fingerprint of an automated pipeline chewing through a pre-computed list of vulnerable keys against a live mempool.'
    reviewerWave 1's sweep rate was ~13.8 transfers per block vs a 0.3/block baseline; Thorn called it 'the fingerprint of an automated pipeline...'Quote and statistics independently corroborated.
  10. #16[confirmed][no action needed]in section: Transaction Fingerprinting and On-Chain Attribution Methodology
    Galaxy also noted that the sweeps were assessed as 'probably orchestrated with a large language model,' though this characterization was not independently confirmed.
    reviewerGalaxy assessed the sweeps as 'probably orchestrated with a large language model'Quote and appropriate hedging both confirmed.
  11. #19[confirmed][no action needed]in section: Exploitation Method and Open-Market Entry
    This reduced effective entropy to approximately 40 bits on Mk2/Mk3 devices and approximately 72 bits on Mk4/Mk5/Q devices, versus the 128-bit standard for a 12-word BIP-39 seed.
    reviewerEntropy fell to ~40 bits on Mk2/Mk3 and ~72 bits on Mk4/Mk5/Q, vs the 128-bit BIP-39 standardFigures for Mk3 and Mk4/Mk5/Q independently confirmed; Mk2 is grouped with Mk3 in Coinkite's own fix versioning, consistent with the page's grouping.
  12. #20[confirmed][no action needed]in section: Exploitation Method and Open-Market Entry
    Affected firmware versions include Mk2/Mk3 versions 4.0.0 through 4.1.9, Mk4/Mk5 versions prior to 5.6.0, and Q model versions prior to 1.5.0Q. Wallets generated using the dice-roll option with 50 or more manual rolls are not considered affected.
    reviewerAffected versions: Mk2/Mk3 4.0.0-4.1.9, Mk4/Mk5 prior to 5.6.0, Q prior to 1.5.0Q; dice-roll with 50+ rolls unaffectedConfirmed against Coinkite's own official security-status page.
  13. #22[confirmed][no action needed]in section: Law Enforcement Cooperation and Exchange Monitoring
    Galaxy Research supplied approximately 600 suspected attacker-controlled addresses to U.S. federal law enforcement, major cryptocurrency exchanges, compliance firms, cyber investigators, and the Security Alliance (SEAL), a non-profit providing 24/7 incident response coordination for the crypto industry.
    reviewer~600 addresses shared with US federal law enforcement, exchanges, compliance firms, cyber investigators, and SEAL; 73 victims engaged; no arrests as of Aug 5Consistent with contemporaneous reporting and SEAL's own self-description.
  14. #23[confirmed][no action needed]in section: Law Enforcement Cooperation and Exchange Monitoring
    Coinkite stated that its legal team 'will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible.'
    reviewerCoinkite's legal team will coordinate with law enforcement across multiple jurisdictionsDirect quote verified against the primary source.
  15. #24[confirmed][no action needed]in section: Law Enforcement Cooperation and Exchange Monitoring
    No public arrests, indictments, or fund seizures had been announced as of August 5, 2026.
    reviewerNo public arrests, indictments, or fund seizures had been announced as of August 5, 2026Claim is explicitly time-bound and remains accurate for the date stated; no arrests had been publicly confirmed as of this review (Sept 2026) either.
  16. #25[confirmed][no action needed]in section: Law Enforcement Cooperation and Exchange Monitoring
    one such embedded message constituted an alleged money-laundering solicitation offering a 10% fee for KYC bypass services
    reviewerOP_RETURN messaging at the Wave 1 consolidation address included a money-laundering solicitation offering a 10% fee for KYC bypassConsistent with the cited outlet's reporting.
  17. #26[confirmed][no action needed]in section: Alleged Laundering Activity and Cross-Chain Movement
    including a platform identified as 'Duel,' where funds were reportedly withdrawn before account-level freezes could be applied
    reviewerFunds deposited to gambling platform 'Duel' were withdrawn before account-level freezes could be appliedDirectly supported by the page's own cited source.
  18. #28[confirmed][no action needed]in section: Dormant Fund Status and Liquidation Risk
    The average targeted wallet had been dormant for approximately 3.18 years before being swept, indicating the victim population consisted disproportionately of long-term Bitcoin holders.
    reviewerThe average targeted wallet had been dormant for approximately 3.18 years before being sweptFigure independently corroborated.
  19. #29[confirmed][no action needed]in section: Dormant Fund Status and Liquidation Risk
    A subset of attackers has reportedly begun cross-chain conversion, with some BTC alleged to have been swapped to Ethereum via THORChain and routed through Tornado Cash, though the scale of these movements relative to total stolen funds is not independently confirmed at the time of this investigation.
    reviewerSome BTC was allegedly swapped to ETH via THORChain and routed through Tornado Cash; scale not independently confirmedAppropriately hedged claim, corroborated in substance and in its acknowledgment of unconfirmed scale.
  20. #30[confirmed][no action needed]in section: Attribution Gaps and Unknown Actor Risk
    Investigators have not linked the incident to any known state-sponsored threat group, including those previously associated with North Korea or Russia, though such attribution has not been publicly ruled out.
    reviewerNo confirmed off-chain identities attributed to any footprint as of Aug 5, 2026; no link to known state-sponsored groupsNo public reporting found linking the incident to a state-sponsored group; claim accurately reflects the state of public attribution.
  21. #31[confirmed][no action needed]in section: Attribution Gaps and Unknown Actor Risk
    Coinkite's emergency firmware update does not remediate seeds already generated under the vulnerable firmware, meaning funds in legacy wallets remain at risk until moved.
    reviewerCoinkite's emergency firmware update does not remediate seeds already generated under vulnerable firmwareConfirmed against Coinkite's own official guidance.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.