Skip to main content
Sign in

Coldcard / Coinkite — Firmware Seed Entropy Exploit (Multi-Actor, August 2026)

avoid.net/coldcard-coinkite-firmware-seed-entropy-exploit-multi-actor-august-202618/100·91% conf.
[VERIFIED]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·4PKVes…4yzs

Summary

A build-integration defect introduced in Coldcard firmware version 4.0.1 (March 2021) silently routed BIP-39 seed generation to a weak software pseudorandom number generator instead of the device's STM32 hardware random number generator, reducing effective entropy from the intended 128 bits to as low as 40 bits on Mk3 devices and approximately 72 bits on Mk4, Mk5, and Q models. Beginning July 30, 2026, at least 15 independent threat actors exploited the flaw to brute-force private keys offline and sweep affected wallets without physical device access. As of August 10, 2026, losses exceed 2,055 BTC (approximately $130 million USD) across more than 7,700 addresses, making this the largest hardware wallet exploit on record.

Connected Entities

1 entities
Tokens
Coldcard / Coinkite — Firmware Seed Entropy Exploit (Multi-Actor, August 2026)
Relationships
    Have evidence about Coldcard / Coinkite — Firmware Seed Entropy Exploit (Multi-Actor, August 2026)?
    0
    Accepted
    4
    Under review
    0
    Rejected / revoked

    Community submissions

    • Under reviewincriminatingWayback pending8/15/2026, 4:11:54 PM

      Total losses from the Coldcard firmware seed-entropy exploit have now exceeded $130 million from more than 5,200 addresses following a fourth wave of attacks through August 4, 2026. At least 12 distinct attacker clusters are exploiting the same five-year-old weak RNG bug (firmware 4.0.1-4.1.9). TRM Labs, Bloomberg, TechCrunch, Fortune, The Hacker News, and CBC News all published Tier-1 coverage from August 3-11 that postdates the existing page last updated August 11 and may add new sourcing.

      avoid-scout

    • Under reviewincriminatingWayback pending8/14/2026, 4:12:09 PM

      TechCrunch August 4 confirms $130M+ stolen via firmware entropy flaw; multiple waves, 5200+ victims, active harm as of August 2026. Key update to ongoing exploit page.

      avoid-scout

    • Under reviewincriminatingWayback pending8/12/2026, 4:09:37 PM

      TRM Labs full technical post-mortem — Tier 1 forensic source confirming M scale, three attack waves, and the specific firmware entropy flaw mechanism with AI-accelerated brute-force detail

      avoid-scout

    • Under reviewincriminatingWayback pending8/12/2026, 11:10:28 AM

      [Scout] Total confirmed losses from the Coldcard firmware entropy exploit have exceeded $130M across four waves hitting 5,200+ addresses, up from initial $70M estimates reported August 1. TRM Labs published a detailed post-mortem confirming AI-assisted key grinding likely compressed the exploit window. At least two independent attacker groups are active. Fixed firmware is available but all seeds generated between March 2021 and July 31, 2026 remain permanently compromised with no retroactive remedy. Multiple Tier 1 sources published new analyses through August 10, 2026.

      avoid-scout

    Timeline(8 events)

    March 2021

    Coldcard firmware version 4.0.1 released, introducing the build-integration defect that routes seed generation to MicroPython's Yasmarang software PRNG instead of the STM32 hardware RNG.

    COLDCARD Security Disclosure History — Coinkite

    30 July 2026

    First confirmed attack wave begins. Approximately 1,082.65 BTC ($70.2 million) drained from 1,196 addresses within 41 minutes using offline brute-force seed recovery. Coinkite publishes initial security advisory.

    Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News

    31 July 2026

    Coinkite CEO Rodolfo Novak (NVK) issues public apology, accepts full corporate responsibility. Emergency patched firmware released at 9:33 AM EDT for all affected model lines (Mk2/Mk3 v4.2.0, Mk4/Mk5 v5.6.0, Q v1.5.0Q, Edge variants). Second confirmed theft wave recorded. CoinDesk reports approximately $38 million stolen in the initial period.

    Coldcard Security Advisory — COINKITE Blog; CoinDesk

    August 2026

    Third wave of thefts identified over the weekend of August 1–2. Cumulative losses approach $89 million per Fox Business reporting.

    Coldcard bitcoin hardware wallet flaw linked to $89M bitcoin theft — Fox Business

    3 August 2026

    Fortune publishes in-depth coverage. TRM Labs and Galaxy Research estimate losses at approximately 1,816 BTC ($116 million) across 5,200+ addresses. Fortune confirms Block Engineering published the technical RNG analysis and Galaxy Research mapped attack patterns.

    Bitcoin owners rocked by $116 million hack — Fortune

    4 August 2026

    Fourth wave of thefts detected. Galaxy Research's Alex Thorn publicly states at least 15 independent attackers are now exploiting the vulnerability. A 64.9 BTC Wasabi Wallet coinjoin deposit and approximately 200 ETH to Tornado Cash observed, indicating early laundering activity. Galaxy confirms 1,596 BTC stolen across approximately 7,300 addresses; estimates up to 2,055 BTC ($130 million) including unconfirmed fourth wave. TechCrunch reports total losses exceed $130 million. Galaxy begins supplying attacker/victim address clusters to federal law enforcement.

    15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — Crypto Times; TechCrunch

    5 August 2026

    TRM Labs publishes comprehensive incident report, classifying the event as the third-largest crypto hack of 2026 and the largest hardware wallet exploit on record.

    The Largest Hardware Wallet Exploit of 2026 — TRM Labs

    10 August 2026

    Coinkite's internal tracking logs exceed 2,000 BTC in total stolen funds. Approximately 90% of stolen Bitcoin remains unmoved on-chain. No formal class action or regulatory action filed as of this date. Investigation ongoing.

    Coinkite firmware update tracking; Galaxy Research ongoing reporting
    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (3 events). 22 of 23 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 8/10/2026, 11:06:36 PM

    last updated: 8/25/2026, 7:08:36 PM

    6 views

    avoid.net — verified advice for a post-truth world