← Coldcard (Coinkite Firmware Exploit)1 decision on this page
Audit log
Every state-changing event for Coldcard (Coinkite Firmware Exploit): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-12 23:05:31ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 446,550,241
- sig
3METhYgiWfJ3…53PHzjgaexplorer ↗- hash
8aaDLjy7nD2M…NsYRFpQysha256 → base58
verifying row…full verify ↗canonical bytes (28353 B) ▸
{"actor":"system:backfill","investigation_id":"b80170e6-0dd7-423c-a5b7-1bfb99f9305b","kind":"publish","page_slug":"coldcard-coinkite-firmware-exploit","published_at":"2026-09-12T23:05:30.905Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Coldcard (Coinkite Firmware Exploit)","sections":[{"content":"The root cause was a C preprocessor macro error in the libngu cryptographic library integrated into Coldcard firmware beginning with version 4.0.1 in March 2021. Coinkite's production board configuration set the macro MICROPY_HW_ENABLE_RNG to zero, intending to disable a software fallback path. However, the libngu library used a guard condition of `#ifndef MICROPY_HW_ENABLE_RNG`, which checks only whether the macro exists — not whether its value is non-zero. Because the macro was defined (as zero), the guard evaluated as false, causing libngu's rng_get() to silently resolve to MicroPython's built-in Yasmarang pseudorandom number generator rather than the STM32 hardware true random number generator.\n\nThe Yasmarang PRNG was initialized from three non-cryptographic sources: the MCU's fixed UID, the SysTick counter (offering approximately 80,000–120,000 possible values at boot), and RTC registers that are often correlated or static. These values were collected only once, producing deterministic output thereafter. An independent technical analysis published by Block's engineering team confirmed that for Mk2/Mk3 devices running vulnerable firmware, the effective search space ceiling was approximately 2^16.29 when the attacker knows the device UID but not the precise SysTick timing — well below the 128-bit security level expected from a 12-word BIP-39 seed.\n\nFor Mk4, Mk5, and Q devices, the secure element contributed 32 bytes of entropy, but only 4 bytes reached the reseed function, capping the maximum distinguishable output streams at 2^32 (requiring on average 2^31 candidate trials to enumerate). Coinkite's own technical backgrounder estimated approximately 40-bit effective entropy on Mk2/Mk3 and roughly 72-bit effective entropy on Mk4/Mk5/Q — both substantially below the 128-bit standard.\n\nThe Yasmarang generator itself entered MicroPython in May 2018 but did not affect Coldcard seed generation until the libNgU migration in March 2021. TAPSIGNER, OPENDIME, and SATSCARD products were unaffected.","heading":"Technical Vulnerability: Entropy Collapse in Seed Generation","severity":"critical","sources":[{"credibility":1,"name":"Technical Deep Dive into the Entropy Issue — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/entropy-technical-backgrounder/"},{"credibility":2,"name":"Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware — Block Engineering Blog","type":"research","url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware"},{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"}]},{"content":"According to Coinkite's official security advisory, the following firmware versions are affected:\n\n- Mk2/Mk3: versions 4.0.1 through 4.1.9\n- Mk4/Mk5 Standard: versions prior to 5.6.0\n- Mk4/Mk5 Edge: versions prior to 6.6.0X\n- Q Standard: versions prior to 1.5.0Q\n- Q Edge: versions prior to 6.6.0QX\n\nThe vulnerable window for seed generation spans from March 2021 to July 2026. Coinkite clarified that seeds generated using at least 50 independent dice rolls as an additional entropy source during setup are not considered at risk, as user-supplied entropy bypassed the software RNG path. The advisory confirmed that installing the patched firmware alone does not protect wallets whose seeds were generated during the vulnerable window; full migration to a newly generated seed on patched hardware is required.","heading":"Affected Firmware Versions and Devices","severity":"critical","sources":[{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":2,"name":"Coldcard Hack Explained: Affected Wallets, Firmware Fixes and What Users Should Do — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/learn/what-is-coldcard-hack/"}]},{"content":"The exploitation began on July 30, 2026 and proceeded in at least four documented waves. In the first wave, approximately 1,082–1,196 Bitcoin addresses were swept within 41 minutes, with roughly 594–1,082 BTC (estimates vary by source and precise wave boundary) moved to attacker-controlled consolidation addresses. Galaxy Research, tracking the incident, documented losses of approximately 1,816 BTC worth roughly $116 million across 5,200+ addresses as of its published tally. TechCrunch and Yahoo Finance reported total losses exceeding $130 million when a suspected fourth wave is included, and CBC News reported 1,596 BTC confirmed stolen from approximately 7,300 addresses at a mid-incident count.\n\nTRM Labs, which published an independent on-chain analysis, noted that the single-hop consolidation pattern — without significant layering or mixing — differed from the behavior typical of state-sponsored groups such as North Korea's TraderTraitor cluster. Attackers did deposit 64.9 BTC to Wasabi Wallet and moved approximately 200 ETH (apparently related to secondary activity) to Tornado Cash on August 4, 2026. OP_RETURN messages attached to some transactions included money-laundering solicitations, suggesting the perpetrators may have sought third-party assistance in cashing out.\n\nGalaxy Research cautioned that the sweep pattern is technically indistinguishable on-chain from a legitimate owner voluntarily consolidating funds — attribution therefore relies on corroborating intelligence rather than transaction structure alone. TRM Labs stated it had not attributed the theft to a specific actor as of its report publication.","heading":"Attack Timeline and Scale of Losses","severity":"critical","sources":[{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":1,"name":"Hackers steal over $130 million by exploiting bug in offline hardware wallets — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"credibility":1,"name":"What we know about ongoing Coldcard hack that's stolen over $100M worth of bitcoin — CBC News","type":"news_article","url":"https://www.cbc.ca/news/world/bitcoin-coinkite-security-hack-9.7295582"},{"credibility":2,"name":"Damage From Coldcard Hack Reaches $130 Million — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/damage-coldcard-hack-reaches-130-142500652.html"}]},{"content":"According to reporting by Phemex and CoinDesk, Bitcoin developer James O'Beirne raised concerns about the randomness code in Coldcard's firmware with Coinkite in May 2025 — approximately 14 months before the July 31, 2026 patch was issued and the exploit became public. According to available reporting, Coinkite's response to O'Beirne was characterized as an argument from absence rather than a technical rebuttal: the company reportedly stated that the flaw would likely have already manifested in real-world losses if it were genuine. As CoinDesk noted, low-entropy seed generation produces wallets that function normally for the owner with no detectable symptom, making the absence of prior losses an unreliable indicator of safety.\n\nCoinkite's official security advisory, updated August 1, 2026, does not disclose when the company first became aware of the issue internally, nor does it reference O'Beirne's May 2025 report. The advisory's timeline begins with the July 30, 2026 exploitation event. The question of what Coinkite knew, when, and whether any internal investigation took place between May 2025 and July 2026 has not been answered publicly as of the date of this investigation.","heading":"Prior Disclosure and Warning","severity":"high","sources":[{"credibility":2,"name":"Coinkite Was Warned 14 Months Early About the Coldcard Flaw — Phemex Academy","type":"news_article","url":"https://phemex.com/academy/coldcard-security-flaw-warning"},{"credibility":1,"name":"How a bug in Coldcard's code went unnoticed for years, leading to $100 million in hacked funds — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/17/how-a-bug-in-coldcard-s-code-went-unnoticed-for-years-leading-to-usd100-million-in-hacked-funds"},{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"}]},{"content":"Coinkite issued an emergency firmware patch on July 31, 2026 — one day after exploitation began — and published a security advisory warning users to migrate funds immediately. The company released updated firmware versions 5.6.0 (and subsequently 5.6.1) for Mk4/Mk5, and version 1.5.0Q (subsequently 1.5.1Q) for the Q model.\n\nThe updated firmware replaced the Yasmarang PRNG fallback with a SHA-256 Hash_DRBG implementation, added a requirement for user-supplied entropy during seed generation (at least 65 key presses, 50 dice rolls, or 128 coin flips), tightened USB data access protocols, improved transaction verification to check partially signed Bitcoin transactions immediately before signing, and addressed additional issues in firmware validation, Delta Mode, and wallet backup handling.\n\nCoinkite stated publicly that 'law enforcement authorities continue investigating the thefts and are working to identify those responsible,' and indicated the company remained available to assist investigators. The company characterized the vulnerability as a firmware bug rather than an intentional design shortcut. Coinkite confirmed that seeds generated with at least 50 independent dice rolls at setup time are not at risk, as user-added entropy bypassed the weak software RNG path.\n\nThe company did not announce a victim compensation fund, insurance claim, or structured restitution program as of the date of this investigation.","heading":"Coinkite's Response and Remediation","severity":"medium","sources":[{"credibility":2,"name":"Coldcard Adds New Security Measures After $130 Million Bitcoin Exploit — Decrypt","type":"news_article","url":"https://decrypt.co/376270/coldcard-new-security-after-bitcoin-exploit"},{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":2,"name":"Coldcard Issues Enhanced Firmware Update Amid Ongoing Bitcoin Theft Fallout — Crowdfund Insider","type":"news_article","url":"https://www.crowdfundinsider.com/2026/08/300062-coldcard-issues-enhanced-firmware-update-amid-ongoing-bitcoin-btc-theft-fallout/"}]},{"content":"According to reporting by Coinpedia, Bitcoin Magazine (citing WuBlockchain), and Blockonomi, the FBI may have identified alleged first-wave attackers as of approximately August 19, 2026, based in part on blockchain data from a paid analytics provider whose internal logs reportedly matched the attackers' activity patterns. As of the date of this investigation, no public announcement of an arrest, named suspect, indictment, or asset seizure had been made. The identification reports remain at the level of law enforcement leads, not public charges, and should be treated as unconfirmed.\n\nOn the civil side, legal analysts at Weir Foulds, Lexology, and MONDAQ identified two potential routes for victim recovery: on-chain tracing of stolen funds, and potential litigation against Coinkite in Canada, where the company is registered. Bitcoin.com News reported that victims were planning class-action proceedings against Coinkite following losses exceeding 1,300 BTC. Legal experts were described as sharply divided on Coinkite's liability, with Coinkite's terms of service reportedly containing arbitration clauses that could complicate class litigation. No court filings had been made public as of this writing.\n\nNo SEC, CFTC, or other financial regulatory action against Coinkite had been publicly announced as of September 2026. Coinkite manufactures hardware devices rather than operating as a financial intermediary, which may affect regulatory jurisdiction.","heading":"Law Enforcement and Legal Action","severity":"high","sources":[{"credibility":2,"name":"FBI May Have Identified First-Wave Coldcard Theft Attackers — SpendNode","type":"news_article","url":"https://www.spendnode.io/blog/fbi-identifies-coldcard-theft-attackers-august-2026/"},{"credibility":2,"name":"Coinkite Faces Class Action Threat as Bitcoin Wallet Bug Costs Users Over 1,300 BTC — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/"},{"credibility":2,"name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery — Weir Foulds / Lexology","type":"other","url":"https://www.lexology.com/library/detail.aspx?g=fb177a37-2ba6-419e-9fc5-b337da7bae64"}]},{"content":"The Coldcard incident is widely described in industry reporting as the largest hardware wallet compromise in recorded history. CoinDesk and IG Markets noted that the exploit reignited debate about Bitcoin self-custody, with some analysts suggesting the event may accelerate institutional adoption of ETF-based exposure over direct wallet custody. The incident is particularly notable because Coldcard was regarded among the most security-focused hardware wallets on the market, with a design philosophy emphasizing air-gapped operation and open-source firmware.\n\nA secondary analysis published by crypto.news noted that an AI-assisted red team audit conducted after the exploit allegedly identified 85 additional critical vulnerabilities across various Bitcoin wallet implementations. Bitcoin Magazine reported that AI tooling was likely involved in the attackers' discovery of the Coldcard flaw, though this claim has not been independently verified and Coinkite itself described this possibility as a suggestion, not a confirmed finding.\n\nBlock's engineering team published a detailed independent vulnerability disclosure, and Karma-X.io published a post-hotfix analysis identifying 39 alleged unpatched findings in firmware v5.6.0. These secondary findings had not been publicly resolved by Coinkite as of this writing.","heading":"Broader Industry Impact and Self-Custody Debate","severity":"medium","sources":[{"credibility":1,"name":"Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"credibility":2,"name":"Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach — Bitcoin Magazine","type":"news_article","url":"https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack"},{"credibility":2,"name":"Coldcard's RNG flaw is still draining wallets, and an AI audit just found 85 more critical bugs across Bitcoin — crypto.news","type":"news_article","url":"https://crypto.news/coldcard-rng-flaw-bitcoin-wallet-ai-audit/"},{"credibility":3,"name":"Full Disclosure: Coldcard v5.6.0 Post-Hotfix Analysis and 39 Unpatched Findings — Karma-X.io","type":"research","url":"https://karma-x.io/blog/post/75/"},{"credibility":2,"name":"Coldcard Hardware Wallet Hack Drains $89M: What It Means — IG UK","type":"news_article","url":"https://www.ig.com/uk/trading-strategies/coldcard-hardware-wallet-hack-self-custody-260803"}]},{"content":"As of the patch date (July 31, 2026), users who generated wallet seeds on affected firmware versions between March 2021 and July 2026 remain at risk unless they have completed full seed migration. Patching the firmware device alone is insufficient — the underlying private keys derived from the weak seed retain the same reduced entropy regardless of the installed firmware version.\n\nCoinkite's advisory states that users who generated seeds using at least 50 independent dice rolls as entropy input at setup time are not at risk. Users holding funds in wallets created on affected devices without dice-roll entropy are advised to: (1) update to patched firmware, (2) generate a new seed on the updated device, (3) verify the new seed's security, and (4) transfer all funds to addresses derived from the new seed before discarding the old wallet.\n\nA BIP-39 passphrase provides some additional protection by extending the key derivation space, but Coinkite's advisory does not treat a passphrase as a substitute for full seed migration in affected cases.","heading":"User Risk Status","severity":"critical","sources":[{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":3,"name":"ColdCard Entropy Incident — The $38M RNG Failure and How to Remediate","type":"community_report","url":"https://nwfella.github.io/coldcard-entropy-incident/"}]}],"sources_used":[{"credibility":1,"name":"Technical Deep Dive into the Entropy Issue — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/entropy-technical-backgrounder/"},{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":2,"name":"Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware — Block Engineering Blog","type":"research","url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware"},{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":1,"name":"Hackers steal over $130 million by exploiting bug in offline hardware wallets — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"credibility":1,"name":"What we know about ongoing Coldcard hack that's stolen over $100M worth of bitcoin — CBC News","type":"news_article","url":"https://www.cbc.ca/news/world/bitcoin-coinkite-security-hack-9.7295582"},{"credibility":1,"name":"Coldcard exploit reignites Bitcoin self-custody debate — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"credibility":1,"name":"How a bug in Coldcard's code went unnoticed for years — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/17/how-a-bug-in-coldcard-s-code-went-unnoticed-for-years-leading-to-usd100-million-in-hacked-funds"},{"credibility":2,"name":"Coldcard Adds New Security Measures After $130 Million Bitcoin Exploit — Decrypt","type":"news_article","url":"https://decrypt.co/376270/coldcard-new-security-after-bitcoin-exploit"},{"credibility":2,"name":"Coinkite Was Warned 14 Months Early About the Coldcard Flaw — Phemex Academy","type":"news_article","url":"https://phemex.com/academy/coldcard-security-flaw-warning"},{"credibility":1,"name":"Coldcard Hack: $116 Million Bitcoin Stolen Via Firmware Flaw — Forbes","type":"news_article","url":"https://www.forbes.com/sites/boazsobrado/2026/08/04/i-did-everything-right-ai-warning-after-116-million-bitcoin-hack/"},{"credibility":2,"name":"Damage From Coldcard Hack Reaches $130 Million — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/damage-coldcard-hack-reaches-130-142500652.html"},{"credibility":2,"name":"Coinkite Faces Class Action Threat as Bitcoin Wallet Bug Costs Users Over 1,300 BTC — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/"},{"credibility":2,"name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery — Weir Foulds / Lexology","type":"other","url":"https://www.lexology.com/library/detail.aspx?g=fb177a37-2ba6-419e-9fc5-b337da7bae64"},{"credibility":2,"name":"FBI May Have Identified First-Wave Coldcard Theft Attackers — SpendNode","type":"news_article","url":"https://www.spendnode.io/blog/fbi-identifies-coldcard-theft-attackers-august-2026/"},{"credibility":2,"name":"Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach — Bitcoin Magazine","type":"news_article","url":"https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack"},{"credibility":3,"name":"Full Disclosure: Coldcard v5.6.0 Post-Hotfix Analysis and 39 Unpatched Findings — Karma-X.io","type":"research","url":"https://karma-x.io/blog/post/75/"},{"credibility":2,"name":"Coldcard's RNG flaw is still draining wallets, and an AI audit just found 85 more critical bugs — crypto.news","type":"news_article","url":"https://crypto.news/coldcard-rng-flaw-bitcoin-wallet-ai-audit/"},{"credibility":2,"name":"Coldcard wallet breach drains $130M in Bitcoin from 7,300 devices — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/07/coldcard-wallet-breach-bitcoin/"},{"credibility":2,"name":"Coldcard Issues Enhanced Firmware Update Amid Ongoing Bitcoin Theft Fallout — Crowdfund Insider","type":"news_article","url":"https://www.crowdfundinsider.com/2026/08/300062-coldcard-issues-enhanced-firmware-update-amid-ongoing-bitcoin-btc-theft-fallout/"},{"credibility":2,"name":"Bitcoin Hardware Wallet Security: Lessons From the Coldcard Seed-Generation Flaw — KuCoin","type":"news_article","url":"https://www.kucoin.com/blog/coldcard-seed-generation-flaw-bitcoin-security"},{"credibility":3,"name":"ColdCard Entropy Incident — The $38M RNG Failure and How to Remediate","type":"community_report","url":"https://nwfella.github.io/coldcard-entropy-incident/"}],"summary":"Coldcard is a Bitcoin-only hardware wallet produced by Toronto-based Coinkite Inc. A build configuration error introduced in firmware v4.0.1 (March 2021) caused seed generation to rely on a weak software pseudorandom number generator rather than the device's hardware true random number generator, reducing effective entropy to as little as 40 bits on older models. Beginning July 30, 2026, attackers exploited this flaw to drain an estimated 1,816+ BTC (approximately $116–$130 million, depending on source and wave count) from over 5,200 addresses across four coordinated attack waves, marking the largest hardware wallet compromise in recorded history.","timeline":[{"date":"2018-05-01","event":"MicroPython's Yasmarang PRNG entered the MicroPython codebase. It would later become the inadvertent fallback for Coldcard seed generation.","source":"COINKITE Blog — Technical Deep Dive","source_url":"https://blog.coinkite.com/entropy-technical-backgrounder/"},{"date":"2021-03-01","event":"Coldcard firmware v4.0.1 released. A build configuration error — MICROPY_HW_ENABLE_RNG set to zero with a #ifndef guard that does not check the macro's value — caused seed generation to route through the Yasmarang software PRNG instead of the STM32 hardware RNG. Effective entropy reduced to approximately 40 bits on Mk2/Mk3 devices.","source":"COINKITE Blog — Technical Deep Dive","source_url":"https://blog.coinkite.com/entropy-technical-backgrounder/"},{"date":"2025-05-01","event":"Bitcoin developer James O'Beirne reportedly flagged the randomness code issue to Coinkite. Coinkite's response was characterized as an argument from absence — that the flaw would likely have shown up in real-world losses already if it were genuine — rather than a technical rebuttal.","source":"Phemex Academy — Coinkite Was Warned 14 Months Early","source_url":"https://phemex.com/academy/coldcard-security-flaw-warning"},{"date":"2026-07-30","event":"Exploitation begins. Wave 1: approximately 594–1,082 BTC drained from roughly 500–1,196 addresses in 25–41 minutes (figures vary by source). Attackers used reconstructed private keys derived from the weak PRNG output without physical device access.","source":"The Hacker News — Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes","source_url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"date":"2026-07-31","event":"Coinkite issues emergency firmware patches for all affected models and publishes a security advisory advising all users who generated seeds between March 2021 and July 2026 to migrate to a new seed immediately.","source":"Coldcard Security Advisory — COINKITE Blog","source_url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"date":"2026-08-01","event":"Coinkite updates its security advisory with additional model-specific firmware version information and user guidance.","source":"Coldcard Security Advisory — COINKITE Blog","source_url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"date":"2026-08-04","event":"Attackers deposit 64.9 BTC to Wasabi Wallet and approximately 200 ETH to Tornado Cash. OP_RETURN messages on some transactions solicit money-laundering assistance. TechCrunch reports total losses have surpassed $130 million.","source":"TRM Labs — The Largest Hardware Wallet Exploit of 2026","source_url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"date":"2026-08-04","event":"TechCrunch publishes a report citing blockchain-monitoring firms confirming over $130 million in losses. Galaxy Research documents losses reaching approximately $100 million at this date.","source":"Hackers steal over $130 million by exploiting bug in offline hardware wallets — TechCrunch","source_url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"date":"2026-08-07","event":"Reports indicate approximately 1,596 BTC confirmed stolen from approximately 7,300 addresses, with a potential fourth wave that could bring total to roughly 2,055 BTC (~$130 million).","source":"Coldcard wallet breach drains $130M in Bitcoin from 7,300 devices — Cryptonomist","source_url":"https://en.cryptonomist.ch/2026/08/07/coldcard-wallet-breach-bitcoin/"},{"date":"2026-08-17","event":"CoinDesk publishes a detailed investigation into how the bug went unnoticed for years, including reporting on the May 2025 O'Beirne warning and Coinkite's response at that time.","source":"How a bug in Coldcard's code went unnoticed for years — CoinDesk","source_url":"https://www.coindesk.com/tech/2026/08/17/how-a-bug-in-coldcard-s-code-went-unnoticed-for-years-leading-to-usd100-million-in-hacked-funds"},{"date":"2026-08-19","event":"Reports emerge, citing Bitcoin Magazine and WuBlockchain, that the FBI may have identified alleged first-wave attackers using logs from a paid blockchain analytics provider. No arrest, charge, or named suspect has been publicly confirmed as of this writing.","source":"FBI May Have Identified First-Wave Coldcard Theft Attackers — SpendNode","source_url":"https://www.spendnode.io/blog/fbi-identifies-coldcard-theft-attackers-august-2026/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision bed554dd-1ee6-4184-82b0-bcd497ba5da4
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.