Skip to main content
AVOID.NET

Coldcard / Coinkite Firmware Seed-Generation Exploit (July-August 2026)

avoid.net/coldcard-coinkite-firmware-seed-generation-exploit-july-august-20263/100·92% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·2n8HQs…dho2

Summary

A firmware integration error introduced into Coldcard hardware wallets in March 2021 silently routed seed generation from the intended STM32 hardware random-number generator to a deterministic software PRNG, reducing effective entropy to as low as 40 bits on Mk3 devices. Beginning July 30, 2026, one or more attackers exploited the weakened entropy offline—without ever accessing victim devices—and drained at least 1,367 BTC (~$88.6 million) across 4,585 addresses in three identified attack waves over roughly 72 hours. Coinkite released patched firmware on July 31, 2026, but the fix cannot repair seeds already generated on vulnerable firmware versions.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Coldcard / Coinkite Firmware Seed-Generation Exploit (July-August 2026)?
0
Accepted
10
Under review
0
Rejected / revoked

Community submissions

Timeline(8 events)

March 2021

Commit b18723dd introduced into Coldcard firmware, changing seed generation from the STM32 hardware RNG (`ckcc.rng_bytes`) to a deterministic software PRNG fallback (`ngu.random.bytes`).

Block Engineering Blog

17 March 2021

Vulnerable firmware version 4.0.0 released publicly for Mk3 devices, beginning a five-year exposure window.

Block Engineering Blog

30 July 2026

Wave 1: Attacker drained 1,082.65 BTC (~$70.2 million) from 1,196 Coldcard-generated addresses in a 41-minute window (01:10–01:51 UTC), spanning six Bitcoin blocks, without physical access to any device.

CoinDesk

31 July 2026

Wave 2 identified, occurring approximately 27 hours after Wave 1, sharing identical transaction fingerprints (30 sat/vB hardcoded fees, same batching patterns), suggesting a single operator. Total losses revised to approximately $75 million.

Crypto Times

31 July 2026

Coinkite CEO NVK issued a public apology accepting full responsibility. Coinkite released emergency patched firmware at 9:33 a.m. EDT: v4.2.0 (Mk2/Mk3), v5.6.0 (Mk4/Mk5), v1.5.0Q (Q). Coinkite advisory states existing seeds on vulnerable firmware cannot be repaired by the update.

CoinDesk / Coinkite Official Blog

August 2026

Coinkite expanded advisory to include Mk4, Mk5, and Q firmware versions. Block Engineering published detailed technical disclosure identifying commit b18723dd as the root cause and quantifying entropy reduction per device model.

Block Engineering Blog / Coinkite Official Blog

August 2026

Galaxy Research reported approximately 600 addresses believed to hold stolen funds to federal investigators, industry compliance firms, and cross-industry cyber investigators.

Galaxy Research on X

2 August 2026

Wave 3 identified by Galaxy Research: 207.73 BTC drained from 1,912 additional addresses, exhibiting divergent methodology (P2WSH outputs, individual destination addresses, six victims per batch, default derivation paths only). Total confirmed losses revised to 1,367.05 BTC (~$88.6 million) across 4,585 addresses. All stolen funds remained unmoved in attacker-controlled addresses.

CoinDesk / Crypto Times
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (4 events). 18 of 22 cited source URLs have an Internet Archive snapshot.

Fact-checked 2026-09-0730 claims checked5 corrections pending0 applied⛓ anchoredSee findings →

model: claude-sonnet-4-6

generated: 8/2/2026, 11:05:22 PM

last updated: 8/27/2026, 3:46:57 AM

7 views

avoid.net — verified advice for a post-truth world