Skip to main content
Sign in

Audit log

Every state-changing event for Coldcard / Coinkite Hardware Wallet Firmware Exploit: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-01 12:07:49Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    4hSYPvDB6KTt…NxUKPjkNsha256 → base58
    verifying row…
    canonical bytes (21954 B) ▸
    {"actor":"system:backfill","investigation_id":"2166bf7d-c5c4-4a44-a9a8-fbed8b9d3827","kind":"publish","page_slug":"coldcard-coinkite-hardware-wallet-firmware-exploit","published_at":"2026-08-01T12:07:49.706Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Coldcard / Coinkite Hardware Wallet Firmware Exploit","sections":[{"content":"Coinkite, the Canadian company behind the Coldcard hardware wallet line, published a security advisory on July 30, 2026, disclosing that a firmware defect introduced in version 4.0.1 (March 2021) caused wallet seed generation to bypass the device's hardware true random number generator (TRNG) and instead rely on Yasmarang, a MicroPython pseudo-random number generator never designed for cryptographic use. The fallback generator was seeded using the chip's serial number and internal clock registers — neither of which is secret — reducing effective seed entropy from the intended 128 bits to approximately 40 bits on Mk3 devices and 72 bits on Mk4, Mk5, and Q devices running firmware released before the fixed versions. Researchers described the practical search space on Mk3 devices as roughly 1.1 trillion possible combinations rather than the astronomically large space a properly generated 12-word BIP-39 mnemonic implies, making offline brute-force reconstruction of private keys computationally feasible for a well-resourced attacker. The root cause was identified as a single commit that changed the seed-generation call from ckcc.rng_bytes — which correctly invoked the STM32 hardware peripheral — to ngu.random.bytes, which routed through the broken libngu code path. The flaw existed in open-source firmware visible on GitHub for more than five years before exploitation.","heading":"Vulnerability Overview","severity":"critical","sources":[{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":2,"name":"CryptoTimes — Coldcard Mk3 Firmware Bug Leaves BTC Wallet Seeds Exposed, $38M Drained","type":"news_article","url":"https://www.cryptotimes.io/2026/07/31/bitcoins-invisible-risk-coldcard-mk3-firmware-bug-leaves-btc-wallet-seeds-exposed-38m-drained/"},{"credibility":2,"name":"TFTC — Coinkite Issues Mk3 Security Warning After 594 BTC Swept in Minutes","type":"news_article","url":"https://www.tftc.io/coldcard-mk3-rng-security-warning-594-btc-swept"}]},{"content":"The vulnerability affected multiple generations of Coldcard hardware wallets across a range of firmware versions. Mk3 devices running firmware 4.0.1 through 4.1.9 (and reportedly through 5.0.3 in some analyses) produced seeds with approximately 40 bits of effective entropy. Mk4, Mk5, and Q devices produced seeds with approximately 72 bits of effective entropy when seeds were generated before fixed firmware versions: 5.6.0 or Edge 6.6.0X for Mk4/Mk5, and 1.5.0Q or Edge 6.6.0QX for Q devices. Fixed firmware for Mk3 was released as version 4.2.0 or later. Coinkite confirmed that TAPSIGNER, OPENDIME, and SATSCARD products use separate codebases and are not affected. Competing hardware wallet manufacturers Block, Trezor, and Ledger each publicly confirmed their products are unaffected. An exception to the migration requirement applies to users who added at least 50 fair, independent, private dice rolls during the original seed generation process, as these rolls contribute sufficient independent entropy to potentially neutralize the weak PRNG output; users with fewer than 50 rolls are advised to migrate regardless. Strong, unique BIP39 passphrases provide additional protection but are not a reliable substitute for migration given the risk of guessable passphrases.","heading":"Affected Devices and Firmware Versions","severity":"critical","sources":[{"credibility":2,"name":"Bitcoin Well — COLDCARD Vulnerability: What Owners Need to Know","type":"research","url":"https://bitcoinwell.com/coldcard-vulnerability"},{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":2,"name":"crypto.news — A build error in Coldcard firmware drained $38 million in bitcoin in 25 minutes","type":"news_article","url":"https://crypto.news/coldcard-firmware-bug-drains-38-million-bitcoin/"}]},{"content":"On July 31, 2026, between approximately 01:31 and 01:56 UTC, an unknown attacker swept approximately 594 BTC (valued at approximately $38 million at the time) from roughly 500 single-signature Bitcoin wallets in a window spanning three blockchain blocks. CoinDesk reported the attack was executed across approximately 500 transactions in that three-block window, with each affected wallet holding more than 0.15 BTC. The attacker subsequently consolidated approximately 562 BTC into a single address, which remained dormant as of reporting. All drained wallets were single-signature; no multi-signature or Taproot wallets were among the confirmed victims. Researchers noted the attacker prioritized BIP-84 derivation paths, consistent with native SegWit addresses, suggesting the use of an automated scanning and sweeping tool. Many drained UTXOs had been dormant since 2021, matching the period during which the vulnerable firmware was in use. On-chain analysis noted a uniform fee structure — every sweep paid an identical hardcoded 30.0 sat/vB fee, described as a 30-to-75x overpayment — further consistent with an automated tool that held pre-computed private keys and broadcast all transactions in a coordinated burst.","heading":"The July 2026 Exploit: Initial Sweep","severity":"critical","sources":[{"credibility":1,"name":"CoinDesk — Major Bitcoin Wallet Flaw Drains 594 BTC in 25-Minute Sweep","type":"news_article","url":"https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep"},{"credibility":2,"name":"CryptoTimes — Coldcard Mk3 Firmware Bug Leaves BTC Wallet Seeds Exposed, $38M Drained","type":"news_article","url":"https://www.cryptotimes.io/2026/07/31/bitcoins-invisible-risk-coldcard-mk3-firmware-bug-leaves-btc-wallet-seeds-exposed-38m-drained/"},{"credibility":2,"name":"TFTC — Coinkite Issues Mk3 Security Warning After 594 BTC Swept in Minutes","type":"news_article","url":"https://www.tftc.io/coldcard-mk3-rng-security-warning-594-btc-swept"}]},{"content":"Galaxy Research conducted on-chain analysis documenting a broader attack scope than the initial reporting. According to Galaxy, the total losses linked to the Coldcard vulnerability reached approximately 1,082.65 BTC (roughly $70 million), with 1,196 addresses drained across an attack window spanning blocks 960,183 through 960,191 — approximately 41 minutes in total. Bitcoin Magazine reported the $70 million figure in a headline dated July 31, 2026. Researcher Clay Garrett identified approximately 695 earlier matching transactions, indicating the attacker may have conducted preliminary sweeps or reconnaissance prior to the main event. The Block reported the Galaxy Research findings. The attacker's identity remained unknown as of the time of reporting.","heading":"Total Scope: Galaxy Research On-Chain Analysis","severity":"critical","sources":[{"credibility":1,"name":"The Block — Bitcoin Losses Linked to Coldcard Vulnerability Grow to $70 Million, Galaxy Research Says","type":"research","url":"https://www.theblock.co/post/410332/bitcoin-losses-linked-coldcard-vulnerability-70-million-galaxy-research"},{"credibility":2,"name":"Bitcoin Magazine — Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen","type":"news_article","url":"https://bitcoinmagazine.com/news/coldcard-wallet-exposed-after-bitcoin-hack"},{"credibility":2,"name":"TFTC — Coinkite Issues Mk3 Security Warning After 594 BTC Swept in Minutes","type":"news_article","url":"https://www.tftc.io/coldcard-mk3-rng-security-warning-594-btc-swept"}]},{"content":"Because updating firmware does not alter or repair an existing seed phrase, any wallet whose seed was generated on an affected Coldcard device running vulnerable firmware remains at risk as long as funds have not been migrated. Coinkite explicitly confirmed: 'Updating the firmware does not change or repair an existing seed. Updated firmware corrects how the next seed is generated.' Researchers noted that the underlying weakness remains exploitable for any seed still holding funds that was generated during the vulnerable period, and that attackers with knowledge of the flaw can continue targeting addresses whose public keys or extended public keys (xpubs) have been broadcast on-chain or otherwise exposed. The flaw also affected other outputs of the same flawed generator, including paper wallet keys, seed-splitting masks, device cloning keys, and Key Teleport transfers. Bitcoin Core developer Gregory Sanders reproduced the attack using setup button-press counts and confirmed its impact on Mk3 and Mk2 models. Kevin Loaec of Wizardsardine and Rob Hamilton of AnchorWatch were among the first to publicly alert the community to the entropy flaw.","heading":"Ongoing Risk to Unswept Wallets","severity":"critical","sources":[{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":2,"name":"Bitcoin Well — COLDCARD Vulnerability: What Owners Need to Know","type":"research","url":"https://bitcoinwell.com/coldcard-vulnerability"},{"credibility":1,"name":"CoinDesk — Major Bitcoin Wallet Flaw Drains 594 BTC in 25-Minute Sweep","type":"news_article","url":"https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep"}]},{"content":"Coinkite CEO Rodolfo Novak (widely known as NVK) issued a public apology on July 31, 2026, stating that the company accepted full responsibility for the firmware failure. In an open letter, NVK urged: 'If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further.' Coinkite released fixed firmware versions — 4.2.0 or later for Mk3, 5.6.0 or later for Mk4/Mk5, and 1.5.0Q or later for Q — and published a detailed security advisory on its blog on July 30, 2026, updated July 31, 2026. The company's recommended migration procedure requires users to: (1) update firmware on the device before generating any replacement seed; (2) generate a new seed on the updated device; (3) verify backup and receiving address; (4) conduct a small test transaction; (5) migrate remaining funds; and (6) retain the old backup until migration is fully confirmed. NVK suggested the vulnerability may have been discovered by the attacker using artificial intelligence, stating the incident represented 'a sober reality of the new AI paradigm' in which AI-assisted code review can identify latent bugs faster than experienced security experts — a claim characterized as alleged given the attacker's identity and methods remain unconfirmed.","heading":"Coinkite Response and Mitigation","severity":"high","sources":[{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":2,"name":"Bitcoin Magazine — Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach","type":"news_article","url":"https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack"},{"credibility":2,"name":"Bitcoin.com News — Coinkite Warns Coldcard Mk3 Owners After Reports of $38M Bitcoin Loss","type":"news_article","url":"https://news.bitcoin.com/crypto-news/coinkite-warns-coldcard-mk3-owners-after-reports-of-38m-bitcoin-loss/"}]},{"content":"The exploit triggered a significant public debate about the viability of individual key management for ordinary Bitcoin holders. Lorenzo Valente of ARK Invest argued that consumers had 'traded counterparty risk for software risk, hardware risk, supply-chain risk, phishing risk, backup risk.' Bitcoin podcaster Guy Swann characterized the incident as 'the worst hit in bitcoin history to the most knowledgeable and properly secured bitcoiners.' Casa CEO Nick Neuman criticized recommended recovery procedures involving dice rolls, stating: 'You just can't ask people to roll dice to be secure with your self custody. It's a non-starter for 99% of people.' Industry observers suggested the incident may accelerate adoption of regulated products such as BlackRock's iShares Bitcoin Trust (IBIT) over direct self-custody. Security firm Blockaid noted that most 2026 crypto losses have stemmed from operational failures rather than smart contract vulnerabilities. Bitcoin's price traded above $64,000 during the exploitation window; the theft had little visible impact on market price at the time of reporting.","heading":"Self-Custody Debate and Industry Impact","severity":"medium","sources":[{"credibility":1,"name":"CoinDesk — Coldcard's $38 Million 'So Far' Exploit Shakes Faith in Self-Custody, May Push Investors to ETFs","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"credibility":2,"name":"Bitcoin Foundation — Coldcard Hardware Bitcoin Wallet Bug Puts Years of BTC Seeds at Risk","type":"news_article","url":"https://bitcoinfoundation.org/news/crimes-and-fraud-news/coldcard-hardware-bitcoin-wallet-bug/"}]},{"content":"As of the date of this investigation (August 1, 2026), no regulatory actions by the SEC, CFTC, or other governmental bodies against Coinkite or related to the Coldcard vulnerability have been publicly reported or confirmed. No class action lawsuits against Coinkite have been publicly filed or announced as of the same date. The absence of confirmed regulatory or legal action should not be interpreted as exoneration; such proceedings, if initiated, typically lag the underlying events by weeks or months.","heading":"Regulatory and Legal Context","severity":"low","sources":[{"credibility":2,"name":"CryptoSlate — A flaw in Coldcard seed generation lets attackers recreate private keys from the press of a button","type":"news_article","url":"https://cryptoslate.com/a-flaw-in-coldcard-seed-generation-lets-attackers-recreate-private-keys-from-the-press-of-a-button/"}]}],"sources_used":[{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":1,"name":"CoinDesk — Major Bitcoin Wallet Flaw Drains 594 BTC in 25-Minute Sweep","type":"news_article","url":"https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep"},{"credibility":1,"name":"CoinDesk — Coldcard's $38 Million Exploit Shakes Faith in Self-Custody, May Push Investors to ETFs","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"credibility":1,"name":"The Block — Bitcoin Losses Linked to Coldcard Vulnerability Grow to $70 Million, Galaxy Research Says","type":"research","url":"https://www.theblock.co/post/410332/bitcoin-losses-linked-coldcard-vulnerability-70-million-galaxy-research"},{"credibility":2,"name":"Bitcoin Magazine — Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach","type":"news_article","url":"https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack"},{"credibility":2,"name":"Bitcoin Magazine — Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen","type":"news_article","url":"https://bitcoinmagazine.com/news/coldcard-wallet-exposed-after-bitcoin-hack"},{"credibility":2,"name":"Bitcoin Foundation — Coldcard Hardware Bitcoin Wallet Bug Puts Years of BTC Seeds at Risk","type":"news_article","url":"https://bitcoinfoundation.org/news/crimes-and-fraud-news/coldcard-hardware-bitcoin-wallet-bug/"},{"credibility":2,"name":"crypto.news — A build error in Coldcard firmware drained $38 million in bitcoin in 25 minutes","type":"news_article","url":"https://crypto.news/coldcard-firmware-bug-drains-38-million-bitcoin/"},{"credibility":2,"name":"Bitcoin Well — COLDCARD Vulnerability: What Owners Need to Know","type":"research","url":"https://bitcoinwell.com/coldcard-vulnerability"},{"credibility":2,"name":"TFTC — Coinkite Issues Mk3 Security Warning After 594 BTC Swept in Minutes","type":"news_article","url":"https://www.tftc.io/coldcard-mk3-rng-security-warning-594-btc-swept"},{"credibility":2,"name":"CryptoTimes — Bitcoin's Invisible Risk: Coldcard Mk3 Firmware Bug Leaves BTC Wallet Seeds Exposed, $38M Drained","type":"news_article","url":"https://www.cryptotimes.io/2026/07/31/bitcoins-invisible-risk-coldcard-mk3-firmware-bug-leaves-btc-wallet-seeds-exposed-38m-drained/"},{"credibility":2,"name":"Bitcoin.com News — Coinkite Warns Coldcard Mk3 Owners After Reports of $38M Bitcoin Loss","type":"news_article","url":"https://news.bitcoin.com/crypto-news/coinkite-warns-coldcard-mk3-owners-after-reports-of-38m-bitcoin-loss/"},{"credibility":2,"name":"CryptoSlate — A flaw in Coldcard seed generation lets attackers recreate private keys from the press of a button","type":"news_article","url":"https://cryptoslate.com/a-flaw-in-coldcard-seed-generation-lets-attackers-recreate-private-keys-from-the-press-of-a-button/"}],"summary":"A firmware entropy bug silently present in Coldcard hardware wallets since March 2021 caused affected devices to bypass their hardware random number generator (TRNG) and fall back to a software-based pseudo-random generator seeded by non-secret chip data, reducing seed entropy from the intended 128 bits to approximately 40 bits on Mk3 devices and 72 bits on Mk4/Mk5/Q devices. On July 31, 2026, an unknown attacker exploited the vulnerability to sweep approximately 594 BTC (roughly $38 million) from around 500 single-signature wallets in approximately 25 minutes; Galaxy Research subsequently documented total losses of approximately 1,082 BTC (~$70 million) across a broader attack window. Firmware updates do not retroactively repair already-generated seeds, meaning any wallet seed created under affected firmware versions remains at risk until funds are migrated to a new wallet generated on patched firmware.","timeline":[{"date":"2021-03-01","event":"Coldcard firmware 4.0.0 / 4.0.1 released for Mk3, introducing the seed-generation defect that replaced the hardware TRNG call (ckcc.rng_bytes) with a software PRNG path (ngu.random.bytes / Yasmarang), reducing effective entropy to approximately 40 bits on Mk3 devices.","source":"COINKITE Blog Security Advisory; CryptoTimes","source_url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"date":"2021-03-01","event":"Mk4, Mk5, and Q devices begin shipping with firmware that similarly reduced seed entropy to approximately 72 bits, with the flaw present in all versions prior to the patched releases.","source":"Bitcoin Well; COINKITE Blog","source_url":"https://bitcoinwell.com/coldcard-vulnerability"},{"date":"2026-07-30","event":"Coinkite publishes a security advisory disclosing the firmware entropy vulnerability affecting Coldcard Mk3 devices (firmware 4.0.1 through 4.1.9) and Mk4/Mk5/Q devices (seeds generated before patched firmware versions). Fixed firmware versions released: 4.2.0+ for Mk3, 5.6.0+ for Mk4/Mk5, 1.5.0Q+ for Q.","source":"COINKITE Blog Security Advisory","source_url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"date":"2026-07-31","event":"Between approximately 01:31 and 01:56 UTC, an unknown attacker sweeps approximately 594 BTC (~$38 million) from roughly 500 single-signature wallets across three blockchain blocks in approximately 25 minutes. All drained wallets are single-signature; affected coins include UTXOs dormant since 2021.","source":"CoinDesk; crypto.news","source_url":"https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep"},{"date":"2026-07-31","event":"Coinkite CEO NVK issues public apology, accepts full responsibility, and urgently advises all users who generated seeds on affected firmware to migrate funds immediately. NVK alleges the vulnerability may have been discovered by the attacker using artificial intelligence.","source":"Bitcoin Magazine; Bitcoin.com News","source_url":"https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack"},{"date":"2026-07-31","event":"Galaxy Research documents total losses of approximately 1,082.65 BTC (~$70 million) across 1,196 addresses, with an attack window spanning blocks 960,183 through 960,191 (approximately 41 minutes). Researcher Clay Garrett identifies approximately 695 earlier matching transactions indicating broader scope.","source":"The Block; Bitcoin Magazine","source_url":"https://www.theblock.co/post/410332/bitcoin-losses-linked-coldcard-vulnerability-70-million-galaxy-research"},{"date":"2026-07-31","event":"Bitcoin Core developer Gregory Sanders reproduces the attack using Mk3 setup button-press counts, confirming impact on Mk3 and Mk2 models. Kevin Loaec (Wizardsardine) and Rob Hamilton (AnchorWatch) are among early public alerts.","source":"TFTC; CryptoTimes","source_url":"https://www.tftc.io/coldcard-mk3-rng-security-warning-594-btc-swept"},{"date":"2026-08-01","event":"Investigation date. No regulatory actions or class action lawsuits against Coinkite publicly confirmed. Attacker identity remains unknown. Stolen BTC remains in attacker-controlled addresses per available on-chain data.","source":"AVOID.NET investigation","source_url":"https://www.avoid.net"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 824bc643-03a4-413d-bfa7-e21fd7193a18
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.