← Coldcard / Coinkite — Firmware Seed Entropy Exploit (Multi-Actor, August 2026)1 decision on this page
Audit log
Every state-changing event for Coldcard / Coinkite — Firmware Seed Entropy Exploit (Multi-Actor, August 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-10 23:06:51ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
Gaa9YCNcjXyN…LmBkpqFAsha256 → base58
verifying row…canonical bytes (28222 B) ▸
{"actor":"system:backfill","investigation_id":"a9cdc7b5-15a1-4e71-857b-15faed45731b","kind":"publish","page_slug":"coldcard-coinkite-firmware-seed-entropy-exploit-multi-actor-august-2026","published_at":"2026-08-10T23:06:50.928Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Coldcard / Coinkite — Firmware Seed Entropy Exploit (Multi-Actor, August 2026)","sections":[{"content":"The root cause is a build-configuration defect introduced during a software-library migration in March 2021. Coldcard firmware integrated the libngu cryptographic library, which exposed two functions sharing identical interfaces: one correctly calling the STM32 hardware RNG and one acting as a software fallback (MicroPython's Yasmarang PRNG) intended for boards without hardware entropy sources. The build guard used the expression `#ifndef MICROPY_HW_ENABLE_RNG`, which evaluates to true when the macro is defined as `0` — a state that Coldcard's production board configuration set explicitly to signal use of its own hardware-RNG wrapper. The result was that `rng_get()` silently resolved to Yasmarang, a deterministic software PRNG seeded primarily from the STM32 chip serial number and internal timer values — information that is reconstructible by an attacker without physical device access. Coinkite's official disclosure page classifies the root cause as 'a build-integration and symbol-resolution defect, not an intentional runtime fallback.' On Mk2/Mk3 hardware, no secure-element entropy was mixed into seed generation at all, yielding an estimated 40 bits of effective entropy. On Mk4, Mk5, and Q models, the secure element contributed a 32-bit state word, raising estimated entropy to approximately 72 bits — still far below the 128-bit security target for a 12-word BIP-39 seed.","heading":"Vulnerability Overview","severity":"critical","sources":[{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog (official disclosure)","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":1,"name":"COLDCARD Security Disclosure History — Coinkite","type":"official","url":"https://coinkite.com/historical-disclosures"},{"credibility":2,"name":"BlockSec Weekly: COLDCARD Entropy and LULA Exploits","type":"research","url":"https://blocksec.com/blog/web3-security-coldcard-entropy-lula-exploits"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"}]},{"content":"Coinkite confirmed the following firmware ranges as vulnerable. Mk2 and Mk3 devices running firmware 4.0.1 through 4.1.9 received no hardware-RNG contribution to seed generation and face the most severe entropy degradation (approximately 40 bits). Mk4 and Mk5 devices running standard firmware before version 5.6.0, or Edge firmware before 6.6.0X, received only a 32-bit secure-element reseed word, yielding an estimated 72 bits of entropy. Q devices running standard firmware before 1.5.0Q, or Edge firmware before 6.6.0QX, are affected to the same degree as Mk4 and Mk5. The vulnerable window spans approximately five years — from March 2021 through the emergency patch release on August 1, 2026. TAPSIGNER, OPENDIME, and SATSCARD products were confirmed unaffected. Users who supplemented device seed generation with at least 50 independent, private dice rolls are stated by Coinkite to be unaffected by this specific flaw alone. Users holding a strong, unique BIP-39 passphrase face reduced — though not eliminated — risk and are still advised to migrate.","heading":"Affected Firmware Versions and Models","severity":"critical","sources":[{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":1,"name":"COLDCARD Security Disclosure History — Coinkite","type":"official","url":"https://coinkite.com/historical-disclosures"},{"credibility":2,"name":"Coldcard hack: how a build flag drained 116M in bitcoin — Crypto.news","type":"news_article","url":"https://crypto.news/coldcard-hack-bitcoin-self-custody-entropy/"}]},{"content":"Attackers performed offline seed recovery without requiring physical access to any device. The attack proceeded in three stages: first, constraining the Yasmarang PRNG candidate state space using reconstructible device metadata (chip UID, internal timer state, and prior RNG-call history); second, deriving candidate BIP-39 seeds and validating them against public blockchain data including addresses, extended public keys, and on-chain transaction records; third, upon a match, reconstructing private keys and sweeping the wallet's funds on-chain. The initial wave on July 30, 2026 drained approximately 1,082.65 BTC from 1,196 addresses within 41 minutes, suggesting automated tooling. Subsequent waves continued on July 31 and over the weekend of August 1–2. A fourth wave was detected on the morning of August 4. BlockSec and Galaxy Research tracked the sweeps using heuristic address clustering on coldcardwatch.com. On-chain indicators noted by TRM Labs include a single 64.9 BTC deposit to a Wasabi Wallet coinjoin and approximately 200 ETH equivalent sent to Tornado Cash on August 4 — both consistent with early-stage laundering attempts. The majority of stolen BTC remained unmoved as of August 10, 2026. OP_RETURN spam messages soliciting money-laundering assistance appeared in victim-adjacent transactions. Victims averaged 3.18 years of wallet dormancy before being swept, indicating the primary affected population is long-term Bitcoin holders.","heading":"Attack Methodology and On-Chain Evidence","severity":"critical","sources":[{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":2,"name":"BlockSec Weekly: COLDCARD Entropy and LULA Exploits","type":"research","url":"https://blocksec.com/blog/web3-security-coldcard-entropy-lula-exploits"},{"credibility":2,"name":"15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/coldcard-exploit-15-attackers-130m-losses-galaxy/"},{"credibility":2,"name":"Galaxy estimates Coldcard exploit may have stolen up to 2,055 Bitcoin — Crypto.news","type":"news_article","url":"https://crypto.news/galaxy-estimates-coldcard-exploit-may-have-stolen-up-to-2055-bitcoin/"}]},{"content":"Loss estimates have risen across successive reporting windows as new attack waves were identified. The Hacker News reported approximately $70.2 million (1,082.65 BTC) confirmed stolen in the initial 41-minute wave on July 30 alone. Fox Business subsequently reported $89 million across 1,200 addresses. TRM Labs and Fortune placed losses at approximately $116 million (1,816 BTC across 5,200+ addresses) as of August 3–5. Galaxy Research's August 4 estimate extended the range to 1,596 BTC confirmed across approximately 7,300 addresses, with a possible 2,055 BTC ($130 million) if a fourth suspected wave is fully attributed. TechCrunch cited blockchain-monitoring firms placing the total above $130 million. As of August 10, 2026, Coinkite's own tracking logs more than 2,000 BTC in stolen funds. TRM Labs classifies this as the third-largest crypto hack of 2026 and the largest hardware wallet exploit on record. The year-to-date 2026 total across all crypto incidents exceeds $1.2 billion across 276 incidents per TRM Labs.","heading":"Financial Impact and Scale","severity":"critical","sources":[{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"credibility":2,"name":"Bitcoin losses from Coldcard hack could swell to $130 million, Galaxy Research says — The Block","type":"news_article","url":"https://www.theblock.co/news/defi/2026-08-04-coldcard-hack-130-million-galaxy-research-410533"},{"credibility":1,"name":"Hackers steal over $130M by exploiting bug in offline hardware wallets — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":2,"name":"Coldcard Hack Losses Hit $100M With 1,596 BTC Stolen in Ongoing Attack — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/coldcard-hack-losses-hit-100m-with-1596-btc-stolen/"},{"credibility":1,"name":"Coldcard bitcoin hardware wallet flaw linked to $89M bitcoin theft — Fox Business","type":"news_article","url":"https://www.foxbusiness.com/fox-news-tech/coldcard-wallet-attack-drains-up-89m-bitcoin-from-1200-addresses"}]},{"content":"No single threat actor has been publicly identified. Galaxy Research's Alex Thorn stated that at least 15 independent attackers are now exploiting the vulnerability, characterizing the situation as 'an open scramble of independent actors and imitators' rather than a coordinated single-group operation. Transaction construction methods differ meaningfully across theft waves, consistent with multiple independent parties having developed or obtained the brute-force tooling independently. TRM Labs notes that the limited layering and mixing activity observed — in contrast to state-sponsored actor patterns such as North Korea's TraderTraitor — suggests opportunistic rather than professional-grade operations. Galaxy Research is supplying attacker and victim address clusters to federal law enforcement and compliance firms. On the researcher side, Block Engineering published the technical entropy analysis; Galaxy Research mapped the sweep patterns and coordinated victim reconciliation (73 confirmed victim reports as of early August). Ledger CTO Charles Guillemet offered public technical commentary comparing the incident to a similar 2022 Trust Wallet entropy vulnerability discovered by Ledger's Donjon research team. Security researcher James O'Beirne is cited as publicly warning that single-key Mk3 wallets generated between 2021 and 2023 without passphrases, dice rolls, or multisig should be treated as immediately at risk. Coinkite's CEO, Rodolfo Novak (publicly known as NVK), issued a public apology on July 31, 2026, accepting full responsibility for the firmware failure. NVK also suggested that AI-assisted code review may have played a role in discovering or accelerating exploitation of the vulnerability.","heading":"Actors Involved","severity":"critical","sources":[{"credibility":2,"name":"15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/coldcard-exploit-15-attackers-130m-losses-galaxy/"},{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":2,"name":"The Coldcard Incident: How Did This Happen? — Ledger Blog","type":"news_article","url":"https://www.ledger.com/blog-coldcard-incident"},{"credibility":2,"name":"Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach — Bitcoin Magazine","type":"news_article","url":"https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack"},{"credibility":1,"name":"Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"}]},{"content":"Coinkite published its initial security advisory on July 30–31, 2026. CEO Rodolfo Novak (NVK) publicly apologized and accepted full corporate responsibility for the firmware defect. Emergency fixed firmware was released on July 31, 2026 at 9:33 AM EDT for all affected model lines: Mk2/Mk3 version 4.2.0, Mk4/Mk5 version 5.6.0, Q version 1.5.0Q, and respective Edge variants 6.6.0X and 6.6.0QX. Coinkite's guidance is unambiguous: installing the patched firmware does not repair an already-generated seed. Any seed created on affected firmware must be treated as compromised. Recommended migration steps include: update firmware first without generating a new seed, verify existing backup integrity, create a fresh seed on patched hardware, verify the wallet fingerprint and a receive address, send a small test transaction, then transfer the remaining balance. Coinkite's advisory note states: 'The last three days have been some of the hardest in this company's history.' The company confirmed that the flaw is a 'build-integration and symbol-resolution defect, not an intentional runtime fallback,' and that TAPSIGNER, OPENDIME, and SATSCARD products are unaffected.","heading":"Coinkite Response and Patch","severity":"high","sources":[{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":1,"name":"COLDCARD Security Disclosure History — Coinkite","type":"official","url":"https://coinkite.com/historical-disclosures"},{"credibility":1,"name":"Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit — Fortune","type":"news_article","url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/"},{"credibility":1,"name":"Coldcard Hack: $116 Million Bitcoin Stolen Via Firmware Flaw — Forbes","type":"news_article","url":"https://www.forbes.com/sites/boazsobrado/2026/08/04/i-did-everything-right-ai-warning-after-116-million-bitcoin-hack/"}]},{"content":"No class action lawsuit had been formally filed as of August 10, 2026. Stoltmann Law Offices, a US firm specializing in investment fraud and cybercrime, publicly solicited Coldcard victims to evaluate potential claims and outlined possible legal theories including breach of express warranty, breach of implied warranty, negligence in development practices, negligent misrepresentation, consumer-protection violations, and product-defect theories. Stoltmann's public statement notes: 'No court has made findings regarding liability for any reported loss.' News.Bitcoin.com reported that victims are planning class-action lawsuits and that legal experts are 'sharply divided' on Coinkite's liability. Galaxy Research is cooperating with federal law enforcement by supplying attacker and victim address clusters. No regulatory action by the SEC, CFTC, or other financial regulators has been reported in connection with the incident as of the investigation date.","heading":"Legal Exposure and Regulatory Context","severity":"high","sources":[{"credibility":3,"name":"Coldcard Wallet Bitcoin Theft — Legal Options for Victims — Stoltmann Law","type":"other","url":"https://stoltmannlaw.com/coldcard-wallet-bitcoin-theft-claims/"},{"credibility":2,"name":"Coinkite Faces Class Action Threat as Bitcoin Wallet Bug Costs Users Over 1,300 BTC — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/"},{"credibility":2,"name":"What to do if you're a Coldcard victim — Protos","type":"news_article","url":"https://protos.com/what-to-do-if-youre-a-coldcard-victim/"}]},{"content":"The incident has triggered a significant public debate over Bitcoin self-custody practices. Bitcoin commentator Guy Swann characterized the event as 'the worst hit in bitcoin history to the most knowledgeable and properly secured bitcoiners.' Lorenzo Valente of ARK Invest noted that users had 'traded counterparty risk for software risk, hardware risk, supply-chain risk, phishing risk, backup risk.' Casa CEO Nick Neuman criticized Coinkite's guidance recommending 50 dice rolls as a mitigation, calling it impractical for mainstream adoption. CoinDesk noted the incident may accelerate a shift toward regulated custodians and spot Bitcoin ETFs. The self-custody community faced a particular irony: victims were predominantly experienced holders — averaging 3.18 years of wallet dormancy — who had deliberately chosen hardware wallets specifically to avoid exchange counterparty risk. Bitcoin Magazine alleged that AI-assisted code review tools may have played a role in identifying or exploiting the vulnerability, citing NVK's own public framing, though no confirmed evidence of AI-generated exploit tooling has been published. Ledger used the incident to publicly contrast its own security certification approach, noting its use of AIS-31, PTG.2, Common Criteria EAL5+/EAL6+-evaluated entropy sources.","heading":"Industry Impact and Self-Custody Debate","severity":"medium","sources":[{"credibility":1,"name":"Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"credibility":2,"name":"The Coldcard Incident: How Did This Happen? — Ledger Blog","type":"news_article","url":"https://www.ledger.com/blog-coldcard-incident"},{"credibility":1,"name":"What we know about ongoing Coldcard hack that's stolen over $100M worth of bitcoin — CBC News","type":"news_article","url":"https://www.cbc.ca/news/world/bitcoin-coinkite-security-hack-9.7295582"},{"credibility":2,"name":"Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach — Bitcoin Magazine","type":"news_article","url":"https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack"}]}],"sources_used":[{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog (official disclosure)","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":1,"name":"COLDCARD Security Disclosure History — Coinkite","type":"official","url":"https://coinkite.com/historical-disclosures"},{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"credibility":1,"name":"Hackers steal over $130M by exploiting bug in offline hardware wallets — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"credibility":1,"name":"Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit — Fortune","type":"news_article","url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/"},{"credibility":1,"name":"Coldcard Hack: $116 Million Bitcoin Stolen Via Firmware Flaw — Forbes","type":"news_article","url":"https://www.forbes.com/sites/boazsobrado/2026/08/04/i-did-everything-right-ai-warning-after-116-million-bitcoin-hack/"},{"credibility":1,"name":"Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"credibility":2,"name":"Bitcoin losses from Coldcard hack could swell to $130 million, Galaxy Research says — The Block","type":"news_article","url":"https://www.theblock.co/news/defi/2026-08-04-coldcard-hack-130-million-galaxy-research-410533"},{"credibility":1,"name":"Coldcard bitcoin hardware wallet flaw linked to $89M bitcoin theft — Fox Business","type":"news_article","url":"https://www.foxbusiness.com/fox-news-tech/coldcard-wallet-attack-drains-up-89m-bitcoin-from-1200-addresses"},{"credibility":1,"name":"What we know about ongoing Coldcard hack that's stolen over $100M worth of bitcoin — CBC News","type":"news_article","url":"https://www.cbc.ca/news/world/bitcoin-coinkite-security-hack-9.7295582"},{"credibility":2,"name":"15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/coldcard-exploit-15-attackers-130m-losses-galaxy/"},{"credibility":2,"name":"Galaxy estimates Coldcard exploit may have stolen up to 2,055 Bitcoin — Crypto.news","type":"news_article","url":"https://crypto.news/galaxy-estimates-coldcard-exploit-may-have-stolen-up-to-2055-bitcoin/"},{"credibility":2,"name":"Coldcard Hack Losses Hit $100M With 1,596 BTC Stolen in Ongoing Attack — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/coldcard-hack-losses-hit-100m-with-1596-btc-stolen/"},{"credibility":2,"name":"BlockSec Weekly: COLDCARD Entropy and LULA Exploits","type":"research","url":"https://blocksec.com/blog/web3-security-coldcard-entropy-lula-exploits"},{"credibility":2,"name":"Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach — Bitcoin Magazine","type":"news_article","url":"https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack"},{"credibility":2,"name":"The Coldcard Incident: How Did This Happen? — Ledger Blog","type":"news_article","url":"https://www.ledger.com/blog-coldcard-incident"},{"credibility":2,"name":"Coldcard security flaw triggers loss of millions in Bitcoin — DigitalShield / Escudo Digital","type":"news_article","url":"https://www.escudodigital.com/en/cybersecurity/coldcard-security-flaw-triggers-loss-of-millions-in-bitcoin.html"},{"credibility":2,"name":"Coldcard Vulnerability Sparks Panic — KuCoin Blog","type":"news_article","url":"https://www.kucoin.com/blog/coldcard-firmware-vulnerability-bitcoin-seed-bug"},{"credibility":3,"name":"Coldcard Wallet Bitcoin Theft — Legal Options for Victims — Stoltmann Law","type":"other","url":"https://stoltmannlaw.com/coldcard-wallet-bitcoin-theft-claims/"},{"credibility":2,"name":"Coinkite Faces Class Action Threat as Bitcoin Wallet Bug Costs Users Over 1,300 BTC — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/"},{"credibility":2,"name":"What to do if you're a Coldcard victim — Protos","type":"news_article","url":"https://protos.com/what-to-do-if-youre-a-coldcard-victim/"},{"credibility":2,"name":"A build error in Coldcard's firmware drained $38 million in bitcoin in 25 minutes — Crypto.news","type":"news_article","url":"https://crypto.news/coldcard-firmware-bug-drains-38-million-bitcoin/"}],"summary":"A build-integration defect introduced in Coldcard firmware version 4.0.1 (March 2021) silently routed BIP-39 seed generation to a weak software pseudorandom number generator instead of the device's STM32 hardware random number generator, reducing effective entropy from the intended 128 bits to as low as 40 bits on Mk3 devices and approximately 72 bits on Mk4, Mk5, and Q models. Beginning July 30, 2026, at least 15 independent threat actors exploited the flaw to brute-force private keys offline and sweep affected wallets without physical device access. As of August 10, 2026, losses exceed 2,055 BTC (approximately $130 million USD) across more than 7,700 addresses, making this the largest hardware wallet exploit on record.","timeline":[{"date":"2021-03-01","event":"Coldcard firmware version 4.0.1 released, introducing the build-integration defect that routes seed generation to MicroPython's Yasmarang software PRNG instead of the STM32 hardware RNG.","source":"COLDCARD Security Disclosure History — Coinkite","source_url":"https://coinkite.com/historical-disclosures"},{"date":"2026-07-30","event":"First confirmed attack wave begins. Approximately 1,082.65 BTC ($70.2 million) drained from 1,196 addresses within 41 minutes using offline brute-force seed recovery. Coinkite publishes initial security advisory.","source":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","source_url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"date":"2026-07-31","event":"Coinkite CEO Rodolfo Novak (NVK) issues public apology, accepts full corporate responsibility. Emergency patched firmware released at 9:33 AM EDT for all affected model lines (Mk2/Mk3 v4.2.0, Mk4/Mk5 v5.6.0, Q v1.5.0Q, Edge variants). Second confirmed theft wave recorded. CoinDesk reports approximately $38 million stolen in the initial period.","source":"Coldcard Security Advisory — COINKITE Blog; CoinDesk","source_url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"date":"2026-08-01","event":"Third wave of thefts identified over the weekend of August 1–2. Cumulative losses approach $89 million per Fox Business reporting.","source":"Coldcard bitcoin hardware wallet flaw linked to $89M bitcoin theft — Fox Business","source_url":"https://www.foxbusiness.com/fox-news-tech/coldcard-wallet-attack-drains-up-89m-bitcoin-from-1200-addresses"},{"date":"2026-08-03","event":"Fortune publishes in-depth coverage. TRM Labs and Galaxy Research estimate losses at approximately 1,816 BTC ($116 million) across 5,200+ addresses. Fortune confirms Block Engineering published the technical RNG analysis and Galaxy Research mapped attack patterns.","source":"Bitcoin owners rocked by $116 million hack — Fortune","source_url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/"},{"date":"2026-08-04","event":"Fourth wave of thefts detected. Galaxy Research's Alex Thorn publicly states at least 15 independent attackers are now exploiting the vulnerability. A 64.9 BTC Wasabi Wallet coinjoin deposit and approximately 200 ETH to Tornado Cash observed, indicating early laundering activity. Galaxy confirms 1,596 BTC stolen across approximately 7,300 addresses; estimates up to 2,055 BTC ($130 million) including unconfirmed fourth wave. TechCrunch reports total losses exceed $130 million. Galaxy begins supplying attacker/victim address clusters to federal law enforcement.","source":"15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — Crypto Times; TechCrunch","source_url":"https://www.cryptotimes.io/2026/08/04/coldcard-exploit-15-attackers-130m-losses-galaxy/"},{"date":"2026-08-05","event":"TRM Labs publishes comprehensive incident report, classifying the event as the third-largest crypto hack of 2026 and the largest hardware wallet exploit on record.","source":"The Largest Hardware Wallet Exploit of 2026 — TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"date":"2026-08-10","event":"Coinkite's internal tracking logs exceed 2,000 BTC in total stolen funds. Approximately 90% of stolen Bitcoin remains unmoved on-chain. No formal class action or regulatory action filed as of this date. Investigation ongoing.","source":"Coinkite firmware update tracking; Galaxy Research ongoing reporting","source_url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 2f8d789b-3ee3-4fba-9293-1ac7bb2a12b7
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.