Coldcard (Coinkite Hardware Wallet Exploit)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·61yszM…Pv6fSummary
Coldcard is a Bitcoin-only hardware wallet produced by Toronto-based Coinkite Inc. Beginning July 30, 2026, attackers exploited a firmware build error introduced in March 2021 that caused seed generation to fall back on a weak software pseudorandom number generator instead of the device's hardware entropy source, reducing effective key strength to as little as 40 bits on older models. Across four attack waves spanning several days, roughly 1,816 BTC (approximately $116 million) was drained from over 5,200 addresses without any physical access to the affected devices, making it the largest hardware wallet exploit on record.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(14 events)
28 January 2021
Vulnerable macro check exists in the libngu library, predating its integration into Coldcard firmware.
Block Engineering Blog1 March 2021
Coldcard firmware migrates to the libngu cryptographic library, introducing the vulnerable code path.
Block Engineering Blog17 March 2021
Firmware version 4.0.0 released with the RNG fallback bug active; seed generation silently begins using weak Yasmarang PRNG on Mk2/Mk3 devices.
Block Engineering Blog14 March 2022
Mk4 firmware v5.0.0 released including 32-bit reseed; Mk4/Q/Mk5 seeds carry ~72-bit effective entropy rather than 40 bits, but remain below the intended 128-bit security level.
Block Engineering Blog1 May 2025
Bitcoin developer James O'Beirne reportedly flags the flawed randomness code to Coinkite. According to third-party reporting, CTO Peter Gray responds with an argument from absence rather than a technical review.
Phemex — Coinkite Was Warned 14 Months Early About the Coldcard Flaw30 July 2026
Wave 1 attack: approximately 1,082.65 BTC drained from ~1,196 addresses in approximately 41 minutes. Coinkite issues a security advisory the same day.
TRM Labs31 July 2026
Wave 2 attack: ~594 BTC drained from ~500 addresses in ~25 minutes. Coinkite CEO Rodolfo Novak publishes public apology. Emergency patched firmware released for all models.
CoinDesk / TRM Labs3 August 2026
Wave 4 detected; cumulative total reaches approximately 1,816 BTC (~$116 million) from over 5,200 addresses.
Fortune / TRM Labs4 August 2026
Limited laundering activity detected: 64.9 BTC deposited to Wasabi Wallet; 200 ETH deposited to Tornado Cash after BTC converted via THORChain.
CryptoTimes4 August 2026
Coinkite reverses policy of automatically deleting customer records, citing anticipated legal obligations from the incident.
Cryptopolitan7 August 2026
Roughly 90% of stolen BTC remains unmoved; ~600 flagged attacker addresses shared with exchanges and law enforcement. No arrest or fund seizure announced.
TRM Labs1 August 2026
Coinkite releases hardened follow-up firmware (v5.6.1 for Mk4/Mk5, v1.5.1Q for Q) approximately three weeks after initial emergency patch, following a comprehensive post-incident audit.
Crowdfund InsiderDecision Log
- hash: 9XkfuCzraBfdi453dgAK4XonqTA8hcqttWuBfXY2pW37
This investigation is cryptographically anchored to the Solana blockchain (1 event). 0 of 22 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/23/2026, 5:05:15 PM
last updated: 9/23/2026, 5:05:34 PM
avoid.net — verified advice for a post-truth world