Fact-check findings
What an automated fact-checker found when it re-read Coldcard / Coinkite Firmware Seed-Generation Exploit (July-August 2026) against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
unverifiable
3 claimsNo source the reviewer could reach confirms or contradicts the claim.
- #17[unverifiable][awaiting moderator]in section: Coinkite Response and Remediation
“Novak suggested the vulnerability may have been identified and exploited using AI-assisted code analysis, stating that 'AI-assisted code review can now find latent bugs at a speed outpacing even the industry's most seasoned experts,' characterizing it as 'a sober reality of the new AI paradigm.'”
reviewerNVK suggested the vulnerability may have been identified and exploited using AI-assisted code analysis, stating AI-assisted code review 'can now find latent bugs at a speed outpacing even the industry's most seasoned experts,' calling it 'a sober reality of the new AI paradigm.'The general claim (NVK raised AI involvement as a theory) is well corroborated by independent headlines, but the exact wording of the two quoted phrases could not be independently confirmed against a primary transcript. - #18[unverifiable][awaiting moderator]in section: Law Enforcement and Investigative Activity
“Galaxy Research reported approximately 600 addresses believed to hold Bitcoin stolen from vulnerable Coldcard-generated addresses to federal investigators, industry compliance firms, and cross-industry cyber investigators.”
reviewerGalaxy Research reported approximately 600 addresses believed to hold stolen Bitcoin to federal investigators, industry compliance firms, and cross-industry cyber investigators.Plausible given Galaxy's confirmed involvement in the investigation, but the specific address count rests solely on an unfetchable social-media source. - #21[unverifiable][awaiting moderator]in section: Law Enforcement and Investigative Activity
“Legal firm Stoltmann Law Offices published an analysis of potential legal theories for victims—including negligence, breach of warranty, and consumer protection violations—but as of August 2, 2026, no lawsuits had been filed and no court had made any findings regarding liability.”
reviewerLegal firm Stoltmann Law Offices published an analysis of potential legal theories for victims; as of August 2, 2026, no lawsuits had been filed and no court had made findings on liability.Plausible given Stoltmann's history of soliciting crypto-theft claimants, but not independently verified.
stale
5 claimsThe claim was accurate when written but events since have overtaken it.
- #2[stale][awaiting moderator]in the summary
“Beginning July 30, 2026, one or more attackers exploited the weakened entropy offline—without ever accessing victim devices—and drained at least 1,367 BTC (~$88.6 million) across 4,585 addresses in three identified attack waves over roughly 72 hours.”
reviewerBeginning July 30, 2026, attackers drained at least 1,367 BTC (~$88.6 million) across 4,585 addresses in three identified attack waves over roughly 72 hours.The page's totals (1,367 BTC / $88.6M / 4,585 addresses / three waves / ~72 hours) reflect only the state of reporting as of August 2, 2026, the date of the page's newest cited sources. A fourth attack wave was confirmed within days, and by mid-August confirmed losses had grown to roughly 1,778-1,816 BTC across more than 5,200 addresses; by September 7, 2026 Galaxy Research put the figure near 1,779-1,806 BTC across over 8,600 addresses. This is a stale snapshot, not a final total.Proposed correction (not yet applied)Beginning July 30, 2026, one or more attackers exploited the weakened entropy offline—without ever accessing victim devices—and drained at least 1,800 BTC (~$116 million or more, with subsequent reporting placing confirmed losses above 1,800 BTC) across more than 5,200 addresses in at least four identified attack waves over more than a week. - #11[stale][awaiting moderator]in section: Attack Mechanics and Timeline
“As of reporting, all 1,367 BTC in attacker-controlled addresses remained unmoved—described by Galaxy Research as unusual for a theft of this scale, suggesting the perpetrator may be waiting for attention to subside or lacks a safe laundering path.”
reviewerAs of reporting, all 1,367 BTC in attacker-controlled addresses remained unmoved.True as of the page's August sources but superseded by current reporting: attacker-controlled funds have since moved through mixing (CoinJoin) transactions.Proposed correction (not yet applied)As of the August 2, 2026 reporting cited here, the confirmed stolen BTC in attacker-controlled addresses had remained unmoved—described by Galaxy Research as unusual for a theft of this scale, suggesting the perpetrator may be waiting for attention to subside or lacks a safe laundering path; Galaxy Research has since reported that the attacker began moving funds through CoinJoin transactions in September 2026. - #14[stale][awaiting moderator]in section: Financial Impact and Victim Profile
“The stolen funds had not been moved to exchanges or mixing services as of reporting, leaving them visible and tracked on-chain.”
reviewerThe stolen funds had not been moved to exchanges or mixing services as of reporting, leaving them visible and tracked on-chain.Same underlying staleness as the equivalent claim in the Attack Mechanics section — grouped together.Proposed correction (not yet applied)The stolen funds had not been moved to exchanges or mixing services as of the August 2026 reporting cited here; Galaxy Research has since reported that the attacker began laundering a portion of the funds through CoinJoin transactions in September 2026. - #27[stale][awaiting moderator]in section: Unresolved Risks and User Guidance
“Galaxy Research's assessment is that the profitable segment of the exploitable key space appears to have been largely exhausted by the three observed attack waves, but this assessment cannot be verified with certainty.”
reviewerGalaxy Research's assessment is that the profitable segment of the exploitable key space appears to have been largely exhausted by the three observed attack waves.A fourth wave, absent from the page, occurred and was confirmed within days of the page's cutoff, meaning the 'three waves' framing of when exhaustion occurred is outdated.Proposed correction (not yet applied)Galaxy Research's assessment is that the profitable segment of the exploitable key space appears to have been largely exhausted following a fourth confirmed attack wave in early August 2026, but this assessment cannot be verified with certainty. - #29[stale][awaiting moderator]in the timeline
“Wave 3 identified by Galaxy Research: 207.73 BTC drained from 1,912 additional addresses, exhibiting divergent methodology (P2WSH outputs, individual destination addresses, six victims per batch, default derivation paths only). Total confirmed losses revised to 1,367.05 BTC (~$88.6 million) across 4,585 addresses. All stolen funds remained unmoved in attacker-controlled addresses.”
reviewerGalaxy Research identified Wave 3 on the Friday-Saturday UTC window of August 1-2, 2026, draining 207.73 BTC from 1,912 additional addresses, with P2WSH outputs, individual destination addresses, and default derivation paths only, batching about six victims per sweep.The Wave 3 figures themselves (207.73 BTC / 1,912 addresses) are accurately reported as of August 2, but this timeline entry embeds both the now-superseded running total and the now-false 'remained unmoved' claim. Both are grouped with the same defect_group as the parallel claims elsewhere on the page.Proposed correction (not yet applied)Wave 3 identified by Galaxy Research: 207.73 BTC drained from 1,912 additional addresses, exhibiting divergent methodology (P2WSH outputs, individual destination addresses, six victims per batch, default derivation paths only). Total confirmed losses as of this date were revised to 1,367.05 BTC (~$88.6 million) across 4,585 addresses; subsequent reporting through mid-August identified a fourth attack wave and raised the confirmed total to roughly 1,800 BTC (~$116 million or more) across over 5,200 addresses, and Galaxy Research reported in September 2026 that a portion of the stolen funds had since been moved through CoinJoin transactions.
confirmed
22 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in the summary
“A firmware integration error introduced into Coldcard hardware wallets in March 2021 silently routed seed generation from the intended STM32 hardware random-number generator to a deterministic software PRNG, reducing effective entropy to as low as 40 bits on Mk3 devices.”
reviewerA firmware integration error introduced in March 2021 routed seed generation from the STM32 hardware RNG to a deterministic software PRNG, reducing effective entropy to as low as 40 bits on Mk3 devices.Independently corroborated by Block Engineering's technical writeup and multiple news outlets describing entropy collapsing from 128 bits to as low as 40. - #3[confirmed][no action needed]in the summary
“Coinkite released patched firmware on July 31, 2026, but the fix cannot repair seeds already generated on vulnerable firmware versions.”
reviewerCoinkite released patched firmware on July 31, 2026, but the fix cannot repair seeds already generated on vulnerable firmware versions.Matches the official Coinkite advisory. - #4[confirmed][no action needed]in section: Vulnerability Overview
“The root cause was a single commit (b18723dd, dated March 1, 2021) that changed wallet seed-generation code from `ckcc.rng_bytes`—which correctly invoked the STM32 hardware RNG peripheral—to `ngu.random.bytes`, which fell through to MicroPython's deterministic Yasmarang PRNG fallback. This regression entered released firmware as version 4.0.0 on March 17, 2021, and remained undetected for over five years.”
reviewerCommit b18723dd, dated March 1, 2021, changed seed-generation code from ckcc.rng_bytes (STM32 hardware RNG) to ngu.random.bytes (MicroPython Yasmarang PRNG fallback), entering released firmware as version 4.0.0 on March 17, 2021.Matches Block Engineering's technical disclosure exactly. - #5[confirmed][no action needed]in section: Vulnerability Overview
“The underlying issue was compounded by a configuration-macro bug in the libngu library: the production board definition sets `MICROPY_HW_ENABLE_RNG` to zero because Coldcard supplies its own RNG wrapper, but libngu checked only whether the macro was defined rather than whether it was enabled.”
reviewerlibngu checked only whether MICROPY_HW_ENABLE_RNG was defined rather than whether it was enabled, causing the build to silently bind to the insecure fallback even though the production board sets the macro to zero.Technical detail confirmed against the primary technical source. - #6[confirmed][no action needed]in section: Vulnerability Overview
“On Mk4, Q, and Mk5 devices, the secure element attempted a reseed but accepted only one 32-bit state word rather than initializing a cryptographic DRBG, capping the search space at approximately 2^32 possibilities rather than the intended 2^128.”
reviewerOn Mk4, Q, and Mk5 devices, the secure element reseed accepted only one 32-bit state word, capping the search space at approximately 2^32 rather than 2^128.Matches the Block Engineering technical breakdown. - #7[confirmed][no action needed]in section: Affected Models and Firmware Versions
“Mk2 and Mk3: firmware versions 4.0.1 through 4.1.9 (beginning March 2021); the vulnerability was fixed in version 4.2.0. Mk4 and Mk5 Standard: all versions before 5.6.0. Mk4 and Mk5 Edge builds: all versions before 6.6.0X. Q Standard: all versions before 1.5.0Q. Q Edge builds: all versions before 6.6.0QX.”
reviewerAffected firmware version ranges: Mk2/Mk3 versions 4.0.1-4.1.9 (fixed in 4.2.0); Mk4/Mk5 Standard before 5.6.0; Mk4/Mk5 Edge before 6.6.0X; Q Standard before 1.5.0Q; Q Edge before 6.6.0QX.Word-for-word match with the official Coinkite security advisory. - #8[confirmed][no action needed]in section: Affected Models and Firmware Versions
“Coinkite's advisory notes that seeds generated with at least 50 independent, private, fair dice rolls entered during setup are not considered at risk from the RNG issue alone, and that a strong BIP-39 passphrase provides an additional security barrier—but does not repair an affected seed.”
reviewerCoinkite's advisory states seeds generated with at least 50 independent, private, fair dice rolls are not considered at risk from the RNG issue alone.Confirmed against the official advisory. - #9[confirmed][no action needed]in section: Affected Models and Firmware Versions
“Products using different codebases—TAPSIGNER, OPENDIME, and SATSCARD—were confirmed unaffected. Competing hardware wallets from Block (Bitkey), Trezor, and Ledger were also confirmed unaffected.”
reviewerTAPSIGNER, OPENDIME, and SATSCARD (different codebases) were confirmed unaffected; competing hardware wallets from Block (Bitkey), Trezor, and Ledger were also confirmed unaffected.Independently corroborated across several outlets. - #10[confirmed][no action needed]in section: Attack Mechanics and Timeline
“Wave 1 began at approximately 01:10 UTC on July 30, 2026, and concluded at 01:51 UTC—a 41-minute window spanning six blocks—during which 1,082.65 BTC was drained from 1,196 addresses.”
reviewerWave 1 began at approximately 01:10 UTC on July 30, 2026, concluded at 01:51 UTC (41 minutes, six blocks), draining 1,082.65 BTC from 1,196 addresses.Consistent across CoinDesk, Block Engineering, and Galaxy-sourced reporting. Minor address-count variance (1,195 vs 1,196) appears across different outlets and does not rise to a factual dispute. - #12[confirmed][no action needed]in section: Attack Mechanics and Timeline
“Block's security researcher Clay Garrett identified that the attacker made at least one operational security error: they used a paid account at a well-known blockchain data provider to query source addresses during the sweeps, and Block traced the activity with what Garrett described as 'extraordinary specificity, down to the number, timing and sequence of requests.' Block passed this information to authorities.”
reviewerBlock security researcher Clay Garrett found the attacker used a paid blockchain data provider account, tracing it with 'extraordinary specificity, down to the number, timing and sequence of requests,' and passed this to authorities.Corroborated by Garrett's own public statement and independent reporting. - #13[confirmed][no action needed]in section: Financial Impact and Victim Profile
“Galaxy Research's revised estimate, as of August 2, 2026, placed total confirmed losses at 1,367.05 BTC across 4,585 addresses, valued at approximately $88.6 million at prevailing prices.”
reviewerGalaxy Research's revised estimate as of August 2, 2026 placed total confirmed losses at 1,367.05 BTC across 4,585 addresses (~$88.6 million).Accurately dated as an August 2 snapshot; the underlying figure was superseded by later reporting (see the separate stale finding on total losses), but the claim as framed here — 'as of August 2' — is itself accurate for that date. - #15[confirmed][no action needed]in section: Coinkite Response and Remediation
“Coinkite CEO Rodolfo Novak (known publicly as NVK) issued a public apology and acknowledgment of full responsibility on July 31, 2026, writing: 'I'm sorry and I'm devastated. Our team is heartbroken about yesterday's news.'”
reviewerCoinkite CEO Rodolfo Novak (NVK) issued a public apology on July 31, 2026: 'I'm sorry and I'm devastated. Our team is heartbroken about yesterday's news.'Core quote corroborated by independent coverage; the cited X post itself could not be directly fetched (see link_rot finding on this source). - #16[confirmed][no action needed]in section: Coinkite Response and Remediation
“Emergency firmware updates were released on July 31, 2026, at 9:33 a.m. EDT for all affected device families: version 4.2.0 for Mk2/Mk3, version 5.6.0 for Mk4/Mk5, and version 1.5.0Q for the Q model.”
reviewerEmergency firmware updates were released July 31, 2026 at 9:33 a.m. EDT: v4.2.0 (Mk2/Mk3), v5.6.0 (Mk4/Mk5), v1.5.0Q (Q).Version numbers confirmed against official advisory. - #19[confirmed][no action needed]in section: Law Enforcement and Investigative Activity
“Public commentator Natalie Brunell publicly asked the FBI director whether the agency was investigating the thefts.”
reviewerPublic commentator Natalie Brunell publicly asked the FBI director whether the agency was investigating the thefts.Corroborated by the cited source. - #20[confirmed][no action needed]in section: Law Enforcement and Investigative Activity
“As of reporting, no law enforcement agency had publicly confirmed an open investigation or made any arrests.”
reviewerAs of reporting, no law enforcement agency had publicly confirmed an open investigation or made any arrests.Still accurate based on the most recent reporting found. - #22[confirmed][no action needed]in section: Industry and Community Impact
“Bitcoin commentator Guy Swann characterized the event as 'the worst hit in bitcoin history to the most knowledgeable and properly secured bitcoiners,' in reference to the fact that Coldcard users are typically considered among the most security-conscious members of the Bitcoin community.”
reviewerBitcoin commentator Guy Swann characterized the event as 'the worst hit in bitcoin history to the most knowledgeable and properly secured bitcoiners.'Exact quote match confirmed against the original post. - #23[confirmed][no action needed]in section: Industry and Community Impact
“Lorenzo Valente of ARK Invest stated that consumers had 'traded counterparty risk for software risk, hardware risk, supply-chain risk, phishing risk, backup risk.'”
reviewerLorenzo Valente of ARK Invest stated that consumers had 'traded counterparty risk for software risk, hardware risk, supply-chain risk, phishing risk, backup risk.'Confirmed against the original post. - #24[confirmed][no action needed]in section: Industry and Community Impact
“Casa CEO Nick Neuman remarked that 'you just can't ask people to roll dice to be secure with your self custody,' referencing Coinkite's dice-roll mitigation guidance.”
reviewerCasa CEO Nick Neuman remarked that 'you just can't ask people to roll dice to be secure with your self custody.'Attribution to Neuman (not David Lawrence, who made a separate but similarly-themed remark) confirmed. - #25[confirmed][no action needed]in section: Industry and Community Impact
“Amicus co-founder David Lawrence suggested the event might represent 'a turning point' in the vision of widespread Bitcoin self-custody.”
reviewerAmicus co-founder David Lawrence suggested the event might represent 'a turning point' in the vision of widespread Bitcoin self-custody.The page paraphrases (not directly quotes) Lawrence's 'turning point' framing, which is consistent with his independently corroborated remarks. - #26[confirmed][no action needed]in section: AI Involvement Allegation
“The allegation is consistent with the pattern of exploitation—the vulnerability required identifying a subtle build-system macro interaction and linking it to exploitable entropy reduction, a task that AI-assisted static analysis tools are increasingly capable of performing at scale. No independent confirmation that an AI tool specifically surfaced this vulnerability has been published as of August 2, 2026.”
reviewerNVK alleged the attacker likely used AI-assisted code review; no independent confirmation an AI tool specifically surfaced the vulnerability has been published as of August 2, 2026.The page's careful hedging ('the allegation is therefore treated as alleged') is appropriate and matches the state of public reporting. - #28[confirmed][no action needed]in the timeline
“Wave 2 identified, occurring approximately 27 hours after Wave 1, sharing identical transaction fingerprints (30 sat/vB hardcoded fees, same batching patterns), suggesting a single operator. Total losses revised to approximately $75 million.”
reviewerWave 2 occurred approximately 27 hours after Wave 1, sharing identical transaction fingerprints (30 sat/vB hardcoded fees, same batching), suggesting a single operator; total losses revised to approximately $75 million.Note the 'single operator' finding applies specifically to Waves 1-2; Galaxy Research later identified at least 15 distinct attackers across the full campaign once later waves are included — see coverage_gaps. - #30[confirmed][no action needed]in the timeline
“Coinkite expanded advisory to include Mk4, Mk5, and Q firmware versions. Block Engineering published detailed technical disclosure identifying commit b18723dd as the root cause and quantifying entropy reduction per device model.”
reviewerCoinkite expanded advisory to include Mk4, Mk5, and Q firmware versions in August 2026; Block Engineering published detailed technical disclosure identifying commit b18723dd as root cause.Confirmed.