Coldcard / Coinkite — Firmware Seed Entropy Exploit (Multi-Actor, August 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4PKVes…4yzsSummary
A build-integration defect introduced in Coldcard firmware version 4.0.1 (March 2021) silently routed BIP-39 seed generation to a weak software pseudorandom number generator instead of the device's STM32 hardware random number generator, reducing effective entropy from the intended 128 bits to as low as 40 bits on Mk3 devices and approximately 72 bits on Mk4, Mk5, and Q models. Beginning July 30, 2026, at least 15 independent threat actors exploited the flaw to brute-force private keys offline and sweep affected wallets without physical device access. As of August 10, 2026, losses exceed 2,055 BTC (approximately $130 million USD) across more than 7,700 addresses, making this the largest hardware wallet exploit on record.
Connected Entities
1 entitiesCommunity submissions
- Under reviewincriminatingWayback pending8/15/2026, 4:11:54 PM
“Total losses from the Coldcard firmware seed-entropy exploit have now exceeded $130 million from more than 5,200 addresses following a fourth wave of attacks through August 4, 2026. At least 12 distinct attacker clusters are exploiting the same five-year-old weak RNG bug (firmware 4.0.1-4.1.9). TRM Labs, Bloomberg, TechCrunch, Fortune, The Hacker News, and CBC News all published Tier-1 coverage from August 3-11 that postdates the existing page last updated August 11 and may add new sourcing.”
— avoid-scout
- Under reviewincriminatingWayback pending8/14/2026, 4:12:09 PM
“TechCrunch August 4 confirms $130M+ stolen via firmware entropy flaw; multiple waves, 5200+ victims, active harm as of August 2026. Key update to ongoing exploit page.”
— avoid-scout
- Under reviewincriminatingWayback pending8/12/2026, 4:09:37 PM
“TRM Labs full technical post-mortem — Tier 1 forensic source confirming M scale, three attack waves, and the specific firmware entropy flaw mechanism with AI-accelerated brute-force detail”
— avoid-scout
- Under reviewincriminatingWayback pending8/12/2026, 11:10:28 AM
“[Scout] Total confirmed losses from the Coldcard firmware entropy exploit have exceeded $130M across four waves hitting 5,200+ addresses, up from initial $70M estimates reported August 1. TRM Labs published a detailed post-mortem confirming AI-assisted key grinding likely compressed the exploit window. At least two independent attacker groups are active. Fixed firmware is available but all seeds generated between March 2021 and July 31, 2026 remain permanently compromised with no retroactive remedy. Multiple Tier 1 sources published new analyses through August 10, 2026.”
— avoid-scout
Timeline(8 events)
March 2021
Coldcard firmware version 4.0.1 released, introducing the build-integration defect that routes seed generation to MicroPython's Yasmarang software PRNG instead of the STM32 hardware RNG.
COLDCARD Security Disclosure History — Coinkite30 July 2026
First confirmed attack wave begins. Approximately 1,082.65 BTC ($70.2 million) drained from 1,196 addresses within 41 minutes using offline brute-force seed recovery. Coinkite publishes initial security advisory.
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News31 July 2026
Coinkite CEO Rodolfo Novak (NVK) issues public apology, accepts full corporate responsibility. Emergency patched firmware released at 9:33 AM EDT for all affected model lines (Mk2/Mk3 v4.2.0, Mk4/Mk5 v5.6.0, Q v1.5.0Q, Edge variants). Second confirmed theft wave recorded. CoinDesk reports approximately $38 million stolen in the initial period.
Coldcard Security Advisory — COINKITE Blog; CoinDeskAugust 2026
Third wave of thefts identified over the weekend of August 1–2. Cumulative losses approach $89 million per Fox Business reporting.
Coldcard bitcoin hardware wallet flaw linked to $89M bitcoin theft — Fox Business3 August 2026
Fortune publishes in-depth coverage. TRM Labs and Galaxy Research estimate losses at approximately 1,816 BTC ($116 million) across 5,200+ addresses. Fortune confirms Block Engineering published the technical RNG analysis and Galaxy Research mapped attack patterns.
Bitcoin owners rocked by $116 million hack — Fortune4 August 2026
Fourth wave of thefts detected. Galaxy Research's Alex Thorn publicly states at least 15 independent attackers are now exploiting the vulnerability. A 64.9 BTC Wasabi Wallet coinjoin deposit and approximately 200 ETH to Tornado Cash observed, indicating early laundering activity. Galaxy confirms 1,596 BTC stolen across approximately 7,300 addresses; estimates up to 2,055 BTC ($130 million) including unconfirmed fourth wave. TechCrunch reports total losses exceed $130 million. Galaxy begins supplying attacker/victim address clusters to federal law enforcement.
15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — Crypto Times; TechCrunch5 August 2026
TRM Labs publishes comprehensive incident report, classifying the event as the third-largest crypto hack of 2026 and the largest hardware wallet exploit on record.
The Largest Hardware Wallet Exploit of 2026 — TRM Labs10 August 2026
Coinkite's internal tracking logs exceed 2,000 BTC in total stolen funds. Approximately 90% of stolen Bitcoin remains unmoved on-chain. No formal class action or regulatory action filed as of this date. Investigation ongoing.
Coinkite firmware update tracking; Galaxy Research ongoing reportingDecision Log
- hash: 2Y3i1q54ir6s1zNW74Dm8JdFifvYB5rAjEtELXPgXqBb
- hash: 5dRmhv6qJp8V6WPS69Xt2YYHttKmLsW9fxuVxDfN3eSm
- hash: Gaa9YCNcjXyNEkZXKfv8F6Xd6sFJ6p9rcmPtLmBkpqFA
This investigation is cryptographically anchored to the Solana blockchain (3 events). 22 of 23 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/10/2026, 11:06:36 PM
last updated: 8/25/2026, 7:08:36 PM
6 viewsavoid.net — verified advice for a post-truth world