Skip to main content
AVOID.NET
Coldcard / Coinkite Hardware Wallet Firmware Exploitreviewed 2026-09-06 · 43 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Coldcard / Coinkite Hardware Wallet Firmware Exploit against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

6 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #2[disputed][awaiting moderator]in the summary
    On July 31, 2026, an unknown attacker exploited the vulnerability to sweep approximately 594 BTC (roughly $38 million) from around 500 single-signature wallets in approximately 25 minutes
    reviewerOn July 31, 2026, an unknown attacker swept approximately 594 BTC (~$38 million) from around 500 single-signature wallets in approximately 25 minutesSources conflict: CoinDesk and crypto.news date the sweep July 31, but Coinkite's own advisory (published same day as the theft, dated July 30) plus several independent block-timestamp reconstructions (TFTC, atlas21, cryip.co, Block engineering) place the sweep on Thursday, July 30, 2026, with the first block (960188) confirming at 01:36 UTC. NVK's July 31 apology also references 'yesterday's news,' consistent with a July 30 theft. The weight of block-timestamp evidence favors July 30.
    Proposed correction (not yet applied)
    On July 30, 2026, an unknown attacker exploited the vulnerability to sweep approximately 594 BTC (roughly $38 million) from around 500 single-signature wallets in approximately 25 minutes
  2. #12[disputed][awaiting moderator]in section: The July 2026 Exploit: Initial Sweep
    On July 31, 2026, between approximately 01:31 and 01:56 UTC
    reviewerOn July 31, 2026, between approximately 01:31 and 01:56 UTC, an attacker swept ~594 BTC from ~500 single-sig wallets across three blocksSame underlying date discrepancy as the summary; block-timestamp reconstructions and Coinkite's same-day advisory point to July 30 rather than July 31.
    Proposed correction (not yet applied)
    On July 30, 2026, between approximately 01:31 and 01:56 UTC
  3. #27[disputed][awaiting moderator]in section: Coinkite Response and Mitigation
    published a detailed security advisory on its blog on July 30, 2026, updated July 31, 2026
    reviewerCoinkite published a detailed security advisory on July 30, 2026, updated July 31, 2026The advisory's meaningful update (extending scope beyond Mk3) is independently dated to August 1, 2026, not July 31.
    Proposed correction (not yet applied)
    published a detailed security advisory on its blog on July 30, 2026, updated August 1, 2026
  4. #36[disputed][awaiting moderator]in the timeline
    2021-03
    reviewerMk4, Mk5, and Q devices began shipping with firmware that reduced seed entropy to ~72 bits in March 2021Mk4 (2022), Q (2023), and Mk5 (March 2026) did not exist in March 2021, so this entry's date is factually impossible as written; the entropy weakness affected each model's firmware from its own release through the 2026 fix, and the fact itself was publicly disclosed/expanded to cover these models on August 1, 2026.
    Proposed correction (not yet applied)
    2026-08-01
  5. #37[disputed][awaiting moderator]in the timeline
    Mk4, Mk5, and Q devices begin shipping with firmware that similarly reduced seed entropy to approximately 72 bits, with the flaw present in all versions prior to the patched releases.
    reviewerMk4, Mk5, and Q devices begin shipping with firmware that similarly reduced seed entropy to approximately 72 bits, with the flaw present in all versions prior to the patched releasesAs written, this entry implies Mk4/Mk5/Q devices existed and began shipping with the flaw in March 2021, which is not possible given their actual release dates (2022, 2023, and March 2026 respectively).
    Proposed correction (not yet applied)
    Coinkite discloses that Mk4, Mk5, and Q devices running firmware released before the fixed versions similarly produced seeds with approximately 72 bits of entropy, with the flaw present in all such versions prior to the 2026 patched releases.
  6. #39[disputed][awaiting moderator]in the timeline
    2026-07-31
    reviewerBetween approximately 01:31 and 01:56 UTC (dated 2026-07-31), an attacker sweeps ~594 BTC from ~500 wallets across three blocksSame underlying date discrepancy as the summary and sections[2] finding; corrected to July 30 per block-timestamp evidence.
    Proposed correction (not yet applied)
    2026-07-30

unverifiable

1 claim

No source the reviewer could reach confirms or contradicts the claim.

  1. #22[unverifiable][awaiting moderator]in section: Ongoing Risk to Unswept Wallets
    The flaw also affected other outputs of the same flawed generator, including paper wallet keys, seed-splitting masks, device cloning keys, and Key Teleport transfers.
    reviewerThe flaw also affected other outputs of the same generator, including paper wallet keys, seed-splitting masks, device cloning keys, and Key Teleport transfersCould not independently confirm this specific list of secondary affected outputs (paper wallets, seed-splitting masks, cloning keys, Key Teleport) in any source consulted; plausible given the shared PRNG but not verified.

stale

2 claims

The claim was accurate when written but events since have overtaken it.

  1. #3[stale][awaiting moderator]in the summary
    Galaxy Research subsequently documented total losses of approximately 1,082 BTC (~$70 million) across a broader attack window.
    reviewerGalaxy Research documented total losses of approximately 1,082 BTC (~$70 million) across a broader attack windowThe $70M/1,082 BTC figure was accurate only for the initial wave (per Galaxy Research's first report); it was superseded within days by additional waves reported by Galaxy Research and covered by The Hacker News, CoinDesk, and Forbes, with cumulative figures reaching $88.6M by Aug 2 and over $100M by Aug 3-4, 2026.
    Proposed correction (not yet applied)
    Galaxy Research subsequently documented total losses that grew across three suspected attack waves to approximately 1,367 BTC (~$88.6 million) across roughly 4,585 addresses by August 2, 2026, with later reporting placing cumulative losses above $100 million.
  2. #19[stale][awaiting moderator]in section: Total Scope: Galaxy Research On-Chain Analysis
    According to Galaxy, the total losses linked to the Coldcard vulnerability reached approximately 1,082.65 BTC (roughly $70 million), with 1,196 addresses drained across an attack window spanning blocks 960,183 through 960,191 — approximately 41 minutes in total.
    reviewerGalaxy Research: total losses reached ~1,082.65 BTC (~$70M) across 1,196 addresses, attack window blocks 960,183-960,191, ~41 minutesThis section presents the $70M figure as the definitive 'Total Scope' but it was the initial wave only; Galaxy Research and other outlets documented two further waves within days, more than doubling the address count and raising losses toward $90-130M by early August 2026.
    Proposed correction (not yet applied)
    According to Galaxy, the total losses linked to the Coldcard vulnerability grew across three suspected attack waves to approximately 1,367.05 BTC (roughly $88.6 million) across 4,585 addresses by August 2, 2026; the initial wave alone accounted for approximately 1,082.65 BTC (roughly $70 million) across 1,196 addresses in a window spanning blocks 960,183 through 960,191 — approximately 41 minutes in total.

partially supported

3 claims

The cited evidence supports part of the claim but not all of it.

  1. #5[partially supported][awaiting moderator]in section: Vulnerability Overview
    The root cause was identified as a single commit that changed the seed-generation call from ckcc.rng_bytes — which correctly invoked the STM32 hardware peripheral — to ngu.random.bytes, which routed through the broken libngu code path.
    reviewerThe advisory attributes the flaw to bypassing the TRNG in favor of Yasmarang (a MicroPython PRNG), seeded by the chip serial number and clock registers, with root cause traced to a commit changing ckcc.rng_bytes to ngu.random.bytesThe claim is factually accurate and independently corroborated, but the specific URL cited by this section (the main advisory) does not itself contain this technical detail; the correct citation would be Coinkite's 'entropy-technical-backgrounder' post or the Block engineering analysis.
  2. #24[partially supported][awaiting moderator]in section: Ongoing Risk to Unswept Wallets
    Kevin Loaec of Wizardsardine and Rob Hamilton of AnchorWatch were among the first to publicly alert the community to the entropy flaw.
    reviewerKevin Loaec of Wizardsardine and Rob Hamilton of AnchorWatch were among the first to publicly alert the community to the entropy flawThe page conflates two distinct roles into a single description; per the cited source, only Loaec is characterized as an early public alerter, while Hamilton's contribution was on-chain analysis.
  3. #42[partially supported][awaiting moderator]in the timeline
    Bitcoin Core developer Gregory Sanders reproduces the attack using Mk3 setup button-press counts, confirming impact on Mk3 and Mk2 models. Kevin Loaec (Wizardsardine) and Rob Hamilton (AnchorWatch) are among early public alerts.
    reviewerGregory Sanders reproduces the attack; Kevin Loaec and Rob Hamilton among early public alertsSame characterization issue as the sections[4] finding on Loaec/Hamilton; Sanders' reproduction claim itself is confirmed.

confirmed

31 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    A firmware entropy bug silently present in Coldcard hardware wallets since March 2021 caused affected devices to bypass their hardware random number generator (TRNG) and fall back to a software-based pseudo-random generator seeded by non-secret chip data, reducing seed entropy from the intended 128 bits to approximately 40 bits on Mk3 devices and 72 bits on Mk4/Mk5/Q devices.
    reviewerA firmware entropy bug present since March 2021 caused Coldcard devices to bypass their hardware TRNG and fall back to a software PRNG seeded by non-secret chip data, reducing entropy to ~40 bits (Mk3) / ~72 bits (Mk4/Mk5/Q)Figures and mechanism corroborated by Coinkite's own advisory and an independent technical analysis from Block's engineering team.
  2. #4[confirmed][no action needed]in the summary
    Firmware updates do not retroactively repair already-generated seeds, meaning any wallet seed created under affected firmware versions remains at risk until funds are migrated to a new wallet generated on patched firmware.
    reviewerFirmware updates do not retroactively repair already-generated seeds; affected seeds remain at risk until funds are migratedDirectly corroborated by Coinkite's own quoted language elsewhere on the page.
  3. #6[confirmed][no action needed]in section: Vulnerability Overview
    Researchers described the practical search space on Mk3 devices as roughly 1.1 trillion possible combinations rather than the astronomically large space a properly generated 12-word BIP-39 mnemonic implies, making offline brute-force reconstruction of private keys computationally feasible for a well-resourced attacker.
    reviewerMk3 practical search space is roughly 1.1 trillion possible combinations, making offline brute-force reconstruction feasibleFigure is consistent across independent technical sources.
  4. #7[confirmed][no action needed]in section: Vulnerability Overview
    The flaw existed in open-source firmware visible on GitHub for more than five years before exploitation.
    reviewerThe flaw existed in open-source firmware visible on GitHub for more than five years before exploitationMarch 2021 commit to July 2026 exploitation is roughly 5 years 4 months, consistent with 'more than five years.'
  5. #8[confirmed][no action needed]in section: Affected Devices and Firmware Versions
    Coinkite confirmed that TAPSIGNER, OPENDIME, and SATSCARD products use separate codebases and are not affected.
    reviewerTAPSIGNER, OPENDIME, and SATSCARD use separate codebases and are not affectedVerbatim match to the cited advisory.
  6. #9[confirmed][no action needed]in section: Affected Devices and Firmware Versions
    Competing hardware wallet manufacturers Block, Trezor, and Ledger each publicly confirmed their products are unaffected.
    reviewerCompeting manufacturers Block, Trezor, and Ledger each publicly confirmed their products are unaffectedConfirmed via Trezor's own blog and multiple news outlets; Block's 'confirmation' took the form of a detailed third-party engineering analysis rather than a brief denial, but the substance (its own products unaffected) matches.
  7. #10[confirmed][no action needed]in section: Affected Devices and Firmware Versions
    An exception to the migration requirement applies to users who added at least 50 fair, independent, private dice rolls during the original seed generation process, as these rolls contribute sufficient independent entropy to potentially neutralize the weak PRNG output; users with fewer than 50 rolls are advised to migrate regardless.
    reviewerUsers who added at least 50 fair, independent, private dice rolls during seed generation may not need to migrateMatches the advisory's stated dice-roll threshold.
  8. #11[confirmed][no action needed]in section: Affected Devices and Firmware Versions
    Mk3 devices running firmware 4.0.1 through 4.1.9 (and reportedly through 5.0.3 in some analyses) produced seeds with approximately 40 bits of effective entropy.
    reviewerMk3 devices running firmware 4.0.1 through 4.1.9 (and reportedly through 5.0.3 in some analyses) produced seeds with ~40 bits of entropyThe page's hedged phrasing accurately reflects a minor discrepancy between sources on the affected firmware ceiling.
  9. #13[confirmed][no action needed]in section: The July 2026 Exploit: Initial Sweep
    CoinDesk reported the attack was executed across approximately 500 transactions in that three-block window, with each affected wallet holding more than 0.15 BTC.
    reviewerCoinDesk reported ~500 transactions in a three-block window, each affected wallet holding more than 0.15 BTCMatches CoinDesk's reporting as relayed by a secondary outlet.
  10. #14[confirmed][no action needed]in section: The July 2026 Exploit: Initial Sweep
    The attacker subsequently consolidated approximately 562 BTC into a single address, which remained dormant as of reporting.
    reviewerThe attacker consolidated approximately 562 BTC into a single address, which remained dormant as of reportingConfirmed by independent reporting.
  11. #15[confirmed][no action needed]in section: The July 2026 Exploit: Initial Sweep
    All drained wallets were single-signature; no multi-signature or Taproot wallets were among the confirmed victims.
    reviewerAll drained wallets were single-signature; no multi-signature or Taproot wallets were among the confirmed victimsDirectly matches CoinDesk's reporting.
  12. #16[confirmed][no action needed]in section: The July 2026 Exploit: Initial Sweep
    Researchers noted the attacker prioritized BIP-84 derivation paths, consistent with native SegWit addresses, suggesting the use of an automated scanning and sweeping tool.
    reviewerThe attacker prioritized BIP-84 derivation paths, consistent with native SegWit, suggesting an automated scanning toolCorroborated by independent on-chain breakdown.
  13. #17[confirmed][no action needed]in section: The July 2026 Exploit: Initial Sweep
    Many drained UTXOs had been dormant since 2021, matching the period during which the vulnerable firmware was in use.
    reviewerMany drained UTXOs had been dormant since 2021, matching the period the vulnerable firmware was in useConfirmed by independent reporting.
  14. #18[confirmed][no action needed]in section: The July 2026 Exploit: Initial Sweep
    On-chain analysis noted a uniform fee structure — every sweep paid an identical hardcoded 30.0 sat/vB fee, described as a 30-to-75x overpayment — further consistent with an automated tool that held pre-computed private keys and broadcast all transactions in a coordinated burst.
    reviewerEvery sweep paid an identical hardcoded 30.0 sat/vB fee, a 30-to-75x overpayment, consistent with an automated toolNear-verbatim match to the cited source.
  15. #20[confirmed][no action needed]in section: Total Scope: Galaxy Research On-Chain Analysis
    Researcher Clay Garrett identified approximately 695 earlier matching transactions, indicating the attacker may have conducted preliminary sweeps or reconnaissance prior to the main event.
    reviewerResearcher Clay Garrett identified approximately 695 earlier matching transactions, indicating possible preliminary sweeps or reconnaissanceFigure matches Garrett's original on-chain finding closely (695 transactions, ~488 BTC, bringing running total to ~1,082.6 BTC).
  16. #21[confirmed][no action needed]in section: Total Scope: Galaxy Research On-Chain Analysis
    The attacker's identity remained unknown as of the time of reporting.
    reviewerThe attacker's identity remained unknown as of the time of reportingNo source found identifies the attacker.
  17. #23[confirmed][no action needed]in section: Ongoing Risk to Unswept Wallets
    Bitcoin Core developer Gregory Sanders reproduced the attack using setup button-press counts and confirmed its impact on Mk3 and Mk2 models.
    reviewerBitcoin Core developer Gregory Sanders reproduced the attack using setup button-press counts and confirmed impact on Mk3 and Mk2 modelsConfirmed via direct fetch of the cited source.
  18. #25[confirmed][no action needed]in section: Coinkite Response and Mitigation
    Coinkite CEO Rodolfo Novak (widely known as NVK) issued a public apology on July 31, 2026, stating that the company accepted full responsibility for the firmware failure.
    reviewerCoinkite CEO NVK issued a public apology on July 31, 2026, accepting full responsibilityDate and substance confirmed; the 'yesterday's news' phrasing further corroborates that the theft itself occurred July 30, one day before this apology.
  19. #26[confirmed][no action needed]in section: Coinkite Response and Mitigation
    In an open letter, NVK urged: 'If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further.'
    reviewerNVK quote: 'If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further.'Verbatim quote confirmed.
  20. #28[confirmed][no action needed]in section: Coinkite Response and Mitigation
    NVK suggested the vulnerability may have been discovered by the attacker using artificial intelligence, stating the incident represented 'a sober reality of the new AI paradigm' in which AI-assisted code review can identify latent bugs faster than experienced security experts — a claim characterized as alleged given the attacker's identity and methods remain unconfirmed.
    reviewerNVK suggested the attacker may have used AI, calling it 'a sober reality of the new AI paradigm'Quote and appropriate hedging ('alleged') both confirmed.
  21. #29[confirmed][no action needed]in section: Self-Custody Debate and Industry Impact
    Lorenzo Valente of ARK Invest argued that consumers had 'traded counterparty risk for software risk, hardware risk, supply-chain risk, phishing risk, backup risk.'
    reviewerLorenzo Valente of ARK Invest: consumers 'traded counterparty risk for software risk, hardware risk, supply-chain risk, phishing risk, backup risk'Quote confirmed verbatim as a partial excerpt of Valente's original statement.
  22. #30[confirmed][no action needed]in section: Self-Custody Debate and Industry Impact
    Bitcoin podcaster Guy Swann characterized the incident as 'the worst hit in bitcoin history to the most knowledgeable and properly secured bitcoiners.'
    reviewerGuy Swann characterized the incident as 'the worst hit in bitcoin history to the most knowledgeable and properly secured bitcoiners'Quote confirmed, with the page's straight-quote rendering of Swann's scare-quoted 'properly secured.'
  23. #31[confirmed][no action needed]in section: Self-Custody Debate and Industry Impact
    Casa CEO Nick Neuman criticized recommended recovery procedures involving dice rolls, stating: 'You just can't ask people to roll dice to be secure with your self custody. It's a non-starter for 99% of people.'
    reviewerCasa CEO Nick Neuman: 'You just can't ask people to roll dice to be secure with your self custody. It's a non-starter for 99% of people.'Quote confirmed verbatim.
  24. #32[confirmed][no action needed]in section: Self-Custody Debate and Industry Impact
    Security firm Blockaid noted that most 2026 crypto losses have stemmed from operational failures rather than smart contract vulnerabilities.
    reviewerBlockaid noted that most 2026 crypto losses have stemmed from operational failures rather than smart contract vulnerabilitiesThe page's 'most' is a fair paraphrase of Blockaid's reported 74% figure.
  25. #33[confirmed][no action needed]in section: Self-Custody Debate and Industry Impact
    Bitcoin's price traded above $64,000 during the exploitation window; the theft had little visible impact on market price at the time of reporting.
    reviewerBitcoin's price traded above $64,000 during the exploitation windowPrice figure corroborated for the surrounding period; no evidence of a sharp price reaction to the theft was found.
  26. #34[confirmed][no action needed]in section: Regulatory and Legal Context
    As of the date of this investigation (August 1, 2026), no regulatory actions by the SEC, CFTC, or other governmental bodies against Coinkite or related to the Coldcard vulnerability have been publicly reported or confirmed.
    reviewerAs of August 1, 2026, no regulatory actions by the SEC, CFTC, or other governmental bodies against Coinkite have been publicly reportedNo contrary evidence found in any source reviewed, including reporting from later in August 2026.
  27. #35[confirmed][no action needed]in section: Regulatory and Legal Context
    No class action lawsuits against Coinkite have been publicly filed or announced as of the same date.
    reviewerNo class action lawsuits against Coinkite have been publicly filed or announced as of August 1, 2026True as of the stated cutoff, though a public class-action threat (not yet a filed suit) emerged the very next day; this is noted as a coverage gap rather than a factual error.
  28. #38[confirmed][no action needed]in the timeline
    Coinkite publishes a security advisory disclosing the firmware entropy vulnerability affecting Coldcard Mk3 devices (firmware 4.0.1 through 4.1.9) and Mk4/Mk5/Q devices (seeds generated before patched firmware versions). Fixed firmware versions released: 4.2.0+ for Mk3, 5.6.0+ for Mk4/Mk5, 1.5.0Q+ for Q.
    reviewerCoinkite publishes a security advisory disclosing the vulnerability on July 30, 2026Note the advisory's initial July 30 scope only covered Mk3; the Mk4/Mk5/Q entropy details described here were not added until the August 1, 2026 update (see separate finding on timeline[1] and sections[5]).
  29. #40[confirmed][no action needed]in the timeline
    Coinkite CEO NVK issues public apology, accepts full responsibility, and urgently advises all users who generated seeds on affected firmware to migrate funds immediately. NVK alleges the vulnerability may have been discovered by the attacker using artificial intelligence.
    reviewerCoinkite CEO NVK issues public apology on July 31, 2026, accepts responsibility, advises migration; alleges AI involvementDate and content confirmed.
  30. #41[confirmed][no action needed]in the timeline
    Galaxy Research documents total losses of approximately 1,082.65 BTC (~$70 million) across 1,196 addresses, with an attack window spanning blocks 960,183 through 960,191 (approximately 41 minutes). Researcher Clay Garrett identifies approximately 695 earlier matching transactions indicating broader scope.
    reviewerGalaxy Research documents total losses of ~1,082.65 BTC (~$70M) across 1,196 addresses, blocks 960,183-960,191, ~41 minutes; Clay Garrett identifies ~695 earlier matching transactions (dated as of July 31, 2026 report)As a dated historical record of a specific report, this entry is accurate; however, the timeline has no later entry reflecting the subsequent waves (Aug 1-2, 2026) that raised the total to $88.6M+ — see coverage_gaps.
  31. #43[confirmed][no action needed]in the timeline
    Investigation date. No regulatory actions or class action lawsuits against Coinkite publicly confirmed. Attacker identity remains unknown. Stolen BTC remains in attacker-controlled addresses per available on-chain data.
    reviewerAs of investigation date (August 2026 / August 1, 2026), no regulatory actions or lawsuits confirmed, attacker identity unknown, stolen BTC remains in attacker-controlled addressesAccurate as a snapshot statement for the stated investigation date; the underlying facts (attacker unidentified, no lawsuits filed) remain true in later reporting reviewed, though the loss total and scope grew substantially after this date.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.