Skip to main content
Sign in
Coldcard / Coinkite1 decision on this page

Audit log

Every state-changing event for Coldcard / Coinkite: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-21 17:07:23Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    5mMbjUQAzaHY…1MyaoNuQsha256 → base58
    verifying row…
    canonical bytes (35590 B) ▸
    {"actor":"system:backfill","investigation_id":"7c156a5d-4c24-4892-8eab-51312039323a","kind":"publish","page_slug":"coldcard-coinkite","published_at":"2026-08-21T17:07:23.390Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Coldcard / Coinkite","sections":[{"content":"Coinkite Inc. is a Bitcoin-focused hardware company headquartered in Toronto, Canada. The company was founded in 2013 by Rodolfo Novak (known publicly as NVK) and Peter Gray. Coinkite initially operated as a Bitcoin exchange and web wallet platform before discontinuing those services in 2016 — citing regulatory pressure and persistent distributed denial-of-service attacks — and pivoting entirely to hardware products. Its flagship product line, the Coldcard hardware wallet, has been sold since 2017 and became well regarded in Bitcoin-only and self-custody communities for its air-gapped design, coercion-resistant features, and, for a time, its open-source firmware. Coinkite's other products include Opendime (a USB Bitcoin bearer instrument), TAPSIGNER (an NFC signing card), SATSCARD, and BLOCKCLOCK. Opendime, TAPSIGNER, and SATSCARD were not affected by the 2026 firmware vulnerability.","heading":"Company Background","severity":"low","sources":[{"credibility":2,"name":"Coinkite Company Overview — Policy Commons","type":"other","url":"https://policycommons.net/artifacts/2118659/company-overview/2873960/"},{"credibility":1,"name":"About Coldcard — Coldcard.com","type":"official","url":"https://coldcard.com/about"},{"credibility":1,"name":"Coinkite: Bitcoin Security and Fun Devices — coinkite.com","type":"official","url":"https://coinkite.com/"}]},{"content":"Beginning July 30, 2026, attackers exploited a firmware vulnerability in Coldcard hardware wallets that had been dormant since March 2021, resulting in the theft of approximately 1,816 BTC — valued at roughly $116 million at the time — from more than 5,200 wallet addresses across multiple attack waves. This represents the largest hardware wallet exploit on record as of the date of this writing.\n\nThe technical root cause, as detailed by Block's Bitcoin Engineering and Security teams in a July 30, 2026 advisory (published early due to active exploitation already underway), was a build configuration error in the libngu cryptographic library. When Coinkite integrated Bitcoin Core's libsecp256k1 in March 2021, a macro responsible for directing seed generation to the STM32 hardware true random number generator (TRNG) was set to zero. Because the macro check used '#ifndef' rather than a non-zero test, MicroPython silently compiled its software fallback — the Yasmarang pseudorandom number generator — initialized only from the device's chip UID and timer registers, providing no fresh cryptographic entropy after initialization. The result was that seeds generated on affected firmware were derived from a predictable, narrow entropy pool rather than the intended 128 bits of randomness.\n\nEffective entropy was estimated at approximately 40 bits on Mk2 and Mk3 devices, and approximately 72 bits on Mk4, Mk5, and Q devices — the latter owing to a secure-element hash that nevertheless left a reseed value of only four bytes (2^32 distinguishable output streams). An attacker who knew or could reconstruct the device UID and timer state could reproduce candidate seed phrases entirely offline and test them against public Bitcoin blockchain address data, without ever needing physical access to a device.\n\nAffected firmware versions, per Coinkite's own advisory, were: Mk2/Mk3 versions 4.0.1 through 4.1.9; Mk4/Mk5 standard firmware before version 5.6.0; Mk4/Mk5 Edge before version 6.6.0X; Q standard before version 1.5.0Q; and Q Edge before version 6.6.0QX. Users who had generated seed phrases using 50 or more independent dice rolls were reportedly not affected by this specific flaw.\n\nThe first attack wave on July 30 drained roughly 594 BTC (~$38 million) from approximately 500 wallets in 25 minutes. Subsequent waves continued through at least August 4, 2026. Galaxy Research mapped the sweep wave by wave and confirmed at least three major waves and numerous smaller incidents. TRM Labs reported total confirmed losses of approximately 1,816 BTC (~$116 million) from over 5,200 addresses.\n\nCoinkite CEO Rodolfo Novak issued a public apology, stating the company was 'heartbroken' and taking 'full accountability for the firmware bug.' The company advised all users who had generated seeds on affected firmware to migrate funds immediately to new seeds on patched firmware, cautioning that updating firmware alone did not retroactively secure seeds generated under the vulnerable versions. Coinkite also noted a belief that AI-assisted computation was involved in the exploit, though this assertion has not been independently verified.","heading":"2026 Firmware Entropy Vulnerability and Theft ($116 Million)","severity":"critical","sources":[{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the $116 Million Coldcard Hack — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":2,"name":"Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware — Block Engineering Blog","type":"research","url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware"},{"credibility":2,"name":"Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"credibility":1,"name":"Hackers steal over $130M by exploiting bug in offline hardware wallets — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"credibility":1,"name":"Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit — Fortune","type":"news_article","url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog (official)","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":1,"name":"What we know about ongoing Coldcard hack that's stolen over $100M worth of bitcoin — CBC News","type":"news_article","url":"https://www.cbc.ca/news/world/bitcoin-coinkite-security-hack-9.7295582"},{"credibility":1,"name":"Coldcard bitcoin hardware wallet flaw linked to $89M bitcoin theft — Fox Business","type":"news_article","url":"https://www.foxbusiness.com/fox-news-tech/coldcard-wallet-attack-drains-up-89m-bitcoin-from-1200-addresses"}]},{"content":"Bitcoin developer James O'Beirne has stated that he identified concerns about the libngu library's random number generation path while auditing Coldcard firmware in May 2025 — approximately 14 months before the active exploitation began — and reported those concerns to Coinkite at that time. According to O'Beirne, Coinkite's response (attributed to CTO Peter Gray) was, in effect, that if something were wrong, the company would already know about it by now. No remediation was made in response to the report.\n\nCoinkite has not publicly disputed O'Beirne's account of this interaction as of the date of this writing. The prior warning, if accurately described, raises questions about Coinkite's internal vulnerability response processes. This section reflects O'Beirne's account as reported; it has not been adjudicated.","heading":"Prior Warning Dismissed: May 2025 Developer Report","severity":"high","sources":[{"credibility":2,"name":"Coinkite Was Warned 14 Months Early About the Coldcard Flaw — Phemex","type":"news_article","url":"https://phemex.com/academy/coldcard-security-flaw-warning"},{"credibility":3,"name":"TFTC on X: James O'Beirne reveals he flagged libngu in May 2025","type":"social_media","url":"https://x.com/TFTC21/status/2084664235582533831"}]},{"content":"Following the July 2026 exploit, Bitcoin developer James O'Beirne published an analysis on August 4, 2026 alleging that Coinkite co-founder and CTO Peter Gray authored the vulnerable libngu code under the pseudonymous GitHub account 'switck.' O'Beirne's basis was 58 commits in the libngu repository authored under 'switck' that carry valid GPG signatures matching Gray's personal cryptographic key — the same key used for Gray's commits under his own name in the same repository. O'Beirne's findings were reportedly independently verified by Bitcoin analyst Dylan LeClair and other community researchers.\n\nSome outlets subsequently speculated about possible intentional insertion of the flaw (an 'inside job' theory). These allegations of intentional misconduct are unproven and have not been substantiated by any law enforcement finding, court filing, or regulatory action as of the date of this writing. The cryptographic evidence establishes Gray's authorship of the code in question; it does not establish intent. Coinkite had not issued a detailed public response to the GPG identity analysis or the insider-job claims as of this writing.\n\nCoinBuzzNow and CoinDailies reported allegations of possible CEO and CTO charges, but no criminal charges against either Rodolfo Novak or Peter Gray have been publicly filed or confirmed as of this writing. These allegations should be treated as unverified speculation absent a formal charging document.","heading":"CTO Attribution and Insider-Job Allegations","severity":"high","sources":[{"credibility":2,"name":"Coinkite CTO Peter Gray linked to the code behind the $114M Coldcard hack — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/"},{"credibility":2,"name":"From Trusted Vendor to Insider Job? Coinkite CTO Now Linked to $110M Coldcard Hack Code — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/09/from-trusted-vendor-to-insider-job-coinkite-cto-now-linked-to-110m-coldcard-hack-code/"},{"credibility":2,"name":"Blame lands on Coinkite CTO as BTC exploit loss nears $120M — CryptoNews","type":"news_article","url":"https://cryptonews.net/news/security/33248351/"},{"credibility":2,"name":"Coinkite CTO Accused Of Ignoring Prior Warning On Coldcard Code Flaw — Bitcoin World","type":"news_article","url":"https://bitcoinworld.co.in/coinkite-cto-ignored-warning-coldcard-flaw/"}]},{"content":"Following the July 2026 exploit, victims and their legal representatives have announced intentions to pursue class-action claims against Coinkite in Canada, where the company is registered. Legal experts have publicly assessed the case as difficult, noting that plaintiffs would need to establish that Coinkite could have foreseen the specific attack vector, and that Coinkite's published terms of service contain broad disclaimers.\n\nLaw firms including Fieldfisher and Weir Foulds have published analyses identifying two potential recovery routes for victims: litigation against Coinkite in Canadian courts (grounded in product liability or negligence claims), and independent blockchain-tracing efforts targeting the unknown perpetrators. No class-action complaint had been formally filed and served as of the date of this writing; the proceedings are at the pre-litigation and demand stage.\n\nIn early August 2026, Coinkite suspended its automated customer-data deletion policy, citing 'legal obligations arising from the security incident, including the preservation of records that may be relevant to ongoing and anticipated legal proceedings.' The company offered an opt-out for customers who wished to remain under the original data-handling terms. No regulatory body — including Canada's OPC (Office of the Privacy Commissioner) or any financial regulator — had publicly announced an investigation into Coinkite as of this writing.","heading":"Legal Proceedings and Class-Action Threats","severity":"high","sources":[{"credibility":2,"name":"Coinkite Faces Class Action Threat as Bitcoin Wallet Bug Costs Users Over 1,300 BTC — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/"},{"credibility":2,"name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery — Weir Foulds","type":"other","url":"https://www.weirfoulds.com/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery"},{"credibility":2,"name":"Coldcard hack: what happened and what victims can do to recover — Fieldfisher","type":"other","url":"https://www.fieldfisher.com/en/insights/coinkite-coldcard-hack-what-victims-need-to-know"},{"credibility":2,"name":"Coldcard Maker Suspends Data Deletion as Legal Proceedings Loom — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/07/coldcard-maker-suspends-data-deletion-as-legal-proceedings-loom/"},{"credibility":2,"name":"Coldcard overhauls data retention policy, prepares for 'legal obligations' from $100M exploit — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/coldcard-overhauls-data-retention-policy/"}]},{"content":"Separately from the firmware exploit, Coinkite drew criticism in early August 2026 for its data retention practices. CEO Rodolfo Novak had previously stated publicly that Coinkite deleted customer data 90 days after a purchase and offered anonymous buying options. Following the exploit, Coinkite sent security alert emails to addresses associated with purchases dating back to 2019, revealing that purchase email addresses had been retained indefinitely. Coinkite later acknowledged that it lacked a formal deletion schedule for purchase email addresses.\n\nThis disclosure prompted criticism from privacy-focused Bitcoin users who considered it contradictory to Novak's prior public statements. Coinkite's position was that retained email addresses allowed customers to log in and verify their other personal data had been deleted per the stated policy. The company subsequently updated its data-handling practices and offered customers an opt-out from the new retention protocol associated with legal proceedings.","heading":"Customer Data Retention and Privacy Controversy","severity":"medium","sources":[{"credibility":2,"name":"Coinkite Under Fire for Retaining Customer Emails After $88M Coldcard Hack — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/coinkite-under-fire-for-retaining-customer-emails-after-88m-coldcard-hack/"},{"credibility":1,"name":"Update on Customer Data Retention — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/update-on-customer-data-retention/"}]},{"content":"In November 2020, researchers from Shift Crypto (makers of the BitBox02 wallet) and Nunchuk responsibly disclosed a multisig verification vulnerability in Coldcard to Coinkite. The flaw allowed a maliciously configured companion software wallet to substitute attacker-controlled extended public keys (xpubs) during multisig wallet registration on the Coldcard device, meaning all bitcoin subsequently received to that multisig wallet could be redirected to the attacker. A physical device was not required to execute the attack under certain configurations.\n\nCoinkite released a fix on January 8, 2021 in firmware version 3.2.1. However, CEO Rodolfo Novak subsequently described the responsible disclosure on the Citadel Dispatch podcast as 'PR terrorism' and publicly questioned whether a researcher without a formal CVE number should be considered a professional. The remarks drew criticism from the Bitcoin security research community. No user funds were publicly reported as stolen as a result of this specific flaw before the patch was issued.","heading":"Prior Security Incident: 2020–2021 Multisig Verification Flaw","severity":"medium","sources":[{"credibility":2,"name":"Remote multisig theft attack on the Coldcard hardware wallet — BitBox Swiss Engineering Blog","type":"research","url":"https://blog.bitbox.swiss/en/remote-multisig-theft-attack-on-the-coldcard-hardware-wallet/"},{"credibility":2,"name":"Remote multisig theft attack on the Coldcard hardware wallet — Benma's Blog","type":"research","url":"https://benma.github.io/2021/02/09/coldcard-multisig-vulnerability.html"},{"credibility":2,"name":"The Coldcard hack proves reputation is not a security model — CoinDesk Opinion","type":"news_article","url":"https://www.coindesk.com/opinion/2026/08/17/the-coldcard-hack-proves-reputation-is-not-a-security-model"}]},{"content":"Coldcard firmware was distributed under the GPLv3 open-source license until November 18, 2020, when Coinkite switched to an MIT + Commons Clause license. The Commons Clause removes the right to commercially sell software whose value derives substantially from the licensed code, meaning the firmware is source-viewable but not freely forkable or redistributable for commercial purposes. The Commons Clause's own documentation explicitly states this arrangement is not 'open source' by the recognized Open Source Definition.\n\nCoinkite's marketing language subsequently described the firmware as 'verifiable' rather than open-source, a distinction critics have argued was not consistently clear in public communications. Foundation Devices founder Zach Herbert publicly objected to the license change. Multiple post-exploit analyses noted that the same March 2021 commit that stripped out the remaining GPL-licensed code was also the commit that introduced the entropy flaw — though a causal link between the license change and the vulnerability has not been established.\n\nThe license change is material to users who rely on open-source status as a security property: a truly open-source firmware can be freely audited, forked, and independently compiled by any party, reducing reliance on the vendor's own assurances.","heading":"Firmware License Change: From GPL to Source-Available","severity":"medium","sources":[{"credibility":2,"name":"Coldcard's Source-Available License Left a $100M Entropy Bug Unguarded — TFTC","type":"news_article","url":"https://www.tftc.io/coldcard-source-available-license-entropy-bug-bitcoin-self-custody"},{"credibility":2,"name":"Open Source vs. Source-Available: What the Coldcard Failure Teaches About Bitcoin Software Incentives — Bitcoin Magazine","type":"news_article","url":"https://bitcoinmagazine.com/culture/open-source-vs-source-available-what-the-coldcard-failure-teaches-about-bitcoin-software-incentives"},{"credibility":2,"name":"Coldcard Review 2026: Bitcoin-Only, Air-Gapped, Not Open Source — State of Surveillance","type":"other","url":"https://stateofsurveillance.org/resources/coldcard/"}]},{"content":"Prior to the July 2026 exploit, the Coldcard was widely regarded within Bitcoin self-custody communities as one of the most security-conscious hardware wallets available. Its air-gapped design — using microSD card, NFC, or QR-code transfer rather than USB connectivity for signing — reduced its attack surface compared to wallets that require a persistent USB connection. The device included duress PINs that load a decoy wallet, a 'brick-me' PIN option for emergency self-destruction, and anti-phishing login words to detect device substitution.\n\nColdcard supports only Bitcoin (by design, as a deliberate product philosophy), is compatible with personal Bitcoin nodes via software such as Sparrow, Electrum, and Specter, and ships with dual secure elements from different manufacturers (Microchip ATECC608 and Maxim DS28C36B), which raises the barrier to supply-chain attacks. Current models are the Coldcard Mk5 (compact, $169.94) and Coldcard Q (full QWERTY keyboard, QR scanner, dual microSD, AAA battery power, $249.21).\n\nThe company's Mk4 was released in February 2022. The Coldcard Q was announced in February 2023. A Mk5 was subsequently announced. None of these hardware security features were implicated in the 2026 exploit, which was purely a firmware-level entropy failure in seed generation.","heading":"Pre-Hack Reputation and Product Features","severity":"low","sources":[{"credibility":2,"name":"Coinkite Announces COLDCARD Mk5 Hardware Wallet — National Law Review (press release)","type":"other","url":"https://natlawreview.com/press-releases/coinkite-announces-coldcard-mk5-hardware-wallet-leap-forward-bitcoin"},{"credibility":2,"name":"Coinkite's New Bitcoin Hardware Wallet Looks Like BlackBerry, Takes AAA Batteries — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2023/02/14/coinkites-new-bitcoin-hardware-wallet-looks-like-blackberry-takes-aaa-batteries"},{"credibility":2,"name":"Coldcard Review 2026: Bitcoin-Only, Air-Gapped, Not Open Source — State of Surveillance","type":"other","url":"https://stateofsurveillance.org/resources/coldcard/"}]}],"sources_used":[{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the $116 Million Coldcard Hack — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":2,"name":"Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware — Block Engineering Blog","type":"research","url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware"},{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog (official)","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":1,"name":"Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit — Fortune","type":"news_article","url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/"},{"credibility":1,"name":"Hackers steal over $130M by exploiting bug in offline hardware wallets — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"credibility":2,"name":"Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"credibility":2,"name":"How a bug in Coldcard's code went unnoticed for years — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/17/how-a-bug-in-coldcard-s-code-went-unnoticed-for-years-leading-to-usd100-million-in-hacked-funds"},{"credibility":2,"name":"The Coldcard hack proves reputation is not a security model — CoinDesk Opinion","type":"news_article","url":"https://www.coindesk.com/opinion/2026/08/17/the-coldcard-hack-proves-reputation-is-not-a-security-model"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"credibility":1,"name":"What we know about ongoing Coldcard hack — CBC News","type":"news_article","url":"https://www.cbc.ca/news/world/bitcoin-coinkite-security-hack-9.7295582"},{"credibility":1,"name":"Coldcard bitcoin hardware wallet flaw linked to $89M bitcoin theft — Fox Business","type":"news_article","url":"https://www.foxbusiness.com/fox-news-tech/coldcard-wallet-attack-drains-up-89m-bitcoin-from-1200-addresses"},{"credibility":2,"name":"Coinkite Faces Class Action Threat as Bitcoin Wallet Bug Costs Users Over 1,300 BTC — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/"},{"credibility":2,"name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery — Weir Foulds","type":"other","url":"https://www.weirfoulds.com/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery"},{"credibility":2,"name":"Coldcard hack: what happened and what victims can do to recover — Fieldfisher","type":"other","url":"https://www.fieldfisher.com/en/insights/coinkite-coldcard-hack-what-victims-need-to-know"},{"credibility":2,"name":"Coldcard Maker Suspends Data Deletion as Legal Proceedings Loom — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/07/coldcard-maker-suspends-data-deletion-as-legal-proceedings-loom/"},{"credibility":2,"name":"Coinkite Under Fire for Retaining Customer Emails — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/coinkite-under-fire-for-retaining-customer-emails-after-88m-coldcard-hack/"},{"credibility":1,"name":"Update on Customer Data Retention — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/update-on-customer-data-retention/"},{"credibility":2,"name":"Coldcard's Source-Available License Left a $100M Entropy Bug Unguarded — TFTC","type":"news_article","url":"https://www.tftc.io/coldcard-source-available-license-entropy-bug-bitcoin-self-custody"},{"credibility":2,"name":"Open Source vs. Source-Available: What the Coldcard Failure Teaches — Bitcoin Magazine","type":"news_article","url":"https://bitcoinmagazine.com/culture/open-source-vs-source-available-what-the-coldcard-failure-teaches-about-bitcoin-software-incentives"},{"credibility":2,"name":"Remote multisig theft attack on the Coldcard hardware wallet — BitBox Swiss Engineering Blog","type":"research","url":"https://blog.bitbox.swiss/en/remote-multisig-theft-attack-on-the-coldcard-hardware-wallet/"},{"credibility":2,"name":"Remote multisig theft attack on the Coldcard hardware wallet — Benma's Blog","type":"research","url":"https://benma.github.io/2021/02/09/coldcard-multisig-vulnerability.html"},{"credibility":2,"name":"Coinkite CTO Peter Gray linked to the code behind the $114M Coldcard hack — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/"},{"credibility":2,"name":"From Trusted Vendor to Insider Job? Coinkite CTO Now Linked to $110M Coldcard Hack Code — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/09/from-trusted-vendor-to-insider-job-coinkite-cto-now-linked-to-110m-coldcard-hack-code/"},{"credibility":2,"name":"Coinkite Was Warned 14 Months Early About the Coldcard Flaw — Phemex","type":"news_article","url":"https://phemex.com/academy/coldcard-security-flaw-warning"},{"credibility":2,"name":"Coldcard Review 2026: Bitcoin-Only, Air-Gapped, Not Open Source — State of Surveillance","type":"other","url":"https://stateofsurveillance.org/resources/coldcard/"},{"credibility":2,"name":"Coinkite Announces COLDCARD Mk5 Hardware Wallet — National Law Review","type":"other","url":"https://natlawreview.com/press-releases/coinkite-announces-coldcard-mk5-hardware-wallet-leap-forward-bitcoin"},{"credibility":2,"name":"Coinkite's New Bitcoin Hardware Wallet Looks Like BlackBerry, Takes AAA Batteries — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2023/02/14/coinkites-new-bitcoin-hardware-wallet-looks-like-blackberry-takes-aaa-batteries"},{"credibility":2,"name":"Coinkite Company Overview — Policy Commons","type":"other","url":"https://policycommons.net/artifacts/2118659/company-overview/2873960/"},{"credibility":1,"name":"About Coldcard — coldcard.com (official)","type":"official","url":"https://coldcard.com/about"},{"credibility":2,"name":"ZachXBT Refuses to Trace the $88M Coldcard Hack — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/zachxbt-declines-trace-coldcard-hack/"},{"credibility":2,"name":"Coinkite Updates COLDCARD After Seed Flaw Exposed Bitcoin Wallets — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/21/coinkite-updates-coldcard-after-seed-flaw-exposed-bitcoin-wallets/"}],"summary":"Coinkite is a Toronto-based Canadian company founded in 2013 that manufactures Bitcoin-only hardware products, most notably the Coldcard hardware wallet. In July 2026, a firmware vulnerability introduced in March 2021 — which caused seed generation to rely on a weak software pseudorandom number generator instead of the device's hardware entropy source — was actively exploited, resulting in the theft of approximately 1,816 BTC (roughly $116 million) from over 5,200 wallet addresses. Coinkite acknowledged the flaw, released patched firmware, and faces class-action litigation threats; the perpetrators have not been publicly identified.","timeline":[{"date":"2013-01-01","event":"Coinkite Inc. founded in Toronto, Canada by Rodolfo Novak and Peter Gray, initially as a Bitcoin exchange and web wallet platform.","source":"Policy Commons / Coinkite company overview","source_url":"https://policycommons.net/artifacts/2118659/company-overview/2873960/"},{"date":"2016-01-01","event":"Coinkite discontinues its web wallet and exchange services, citing regulatory challenges and DDoS attacks, pivoting to hardware products.","source":"Policy Commons / Coinkite company overview","source_url":"https://policycommons.net/artifacts/2118659/company-overview/2873960/"},{"date":"2017-01-01","event":"Coldcard hardware wallet first released. Mk1 and subsequent models follow.","source":"About Coldcard — coldcard.com","source_url":"https://coldcard.com/about"},{"date":"2020-11-18","event":"Coinkite changes Coldcard firmware license from GPLv3 to MIT + Commons Clause, making the firmware source-available but no longer freely forkable or open-source by OSI definition.","source":"Coldcard's Source-Available License Left a $100M Entropy Bug Unguarded — TFTC","source_url":"https://www.tftc.io/coldcard-source-available-license-entropy-bug-bitcoin-self-custody"},{"date":"2020-11-07","event":"Shift Crypto and Nunchuk responsibly disclose a multisig xpub-substitution vulnerability to Coinkite.","source":"Remote multisig theft attack on the Coldcard hardware wallet — Benma's Blog","source_url":"https://benma.github.io/2021/02/09/coldcard-multisig-vulnerability.html"},{"date":"2021-01-08","event":"Coinkite releases firmware version 3.2.1 patching the multisig verification flaw. CEO Novak separately describes the responsible disclosure as 'PR terrorism' on a podcast.","source":"Remote multisig theft attack on the Coldcard hardware wallet — BitBox Swiss","source_url":"https://blog.bitbox.swiss/en/remote-multisig-theft-attack-on-the-coldcard-hardware-wallet/"},{"date":"2021-03-01","event":"Firmware version 4.0.1 released. A build configuration error in this release causes seed generation to use MicroPython's Yasmarang software PRNG fallback instead of the STM32 hardware TRNG, introducing the entropy vulnerability. The bug goes undetected.","source":"Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware — Block Engineering Blog","source_url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware"},{"date":"2022-02-01","event":"Coldcard Mk4 released.","source":"About Coldcard — coldcard.com","source_url":"https://coldcard.com/about"},{"date":"2023-02-14","event":"Coldcard Q announced — featuring a full QWERTY keyboard, QR scanner, and AAA battery power for true air-gapped operation.","source":"Coinkite's New Bitcoin Hardware Wallet Looks Like BlackBerry, Takes AAA Batteries — CoinDesk","source_url":"https://www.coindesk.com/tech/2023/02/14/coinkites-new-bitcoin-hardware-wallet-looks-like-blackberry-takes-aaa-batteries"},{"date":"2025-05-01","event":"Bitcoin developer James O'Beirne reportedly flags concerns about the libngu library's RNG path to Coinkite during a firmware audit. According to O'Beirne, CTO Peter Gray responds that the company would already know if something were wrong. No fix is issued.","source":"Coinkite Was Warned 14 Months Early About the Coldcard Flaw — Phemex","source_url":"https://phemex.com/academy/coldcard-security-flaw-warning"},{"date":"2026-07-30","event":"Active exploitation of the firmware entropy vulnerability begins. First wave drains approximately 594 BTC (~$38 million) from roughly 500 wallet addresses in approximately 25 minutes. Coinkite discloses the vulnerability and issues an emergency firmware advisory.","source":"Coldcard exploit reignites Bitcoin self-custody debate — CoinDesk","source_url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"date":"2026-07-30","event":"Block's Bitcoin Engineering and Security teams publish a technical advisory on the COLDCARD PRNG fallback, disclosing the Yasmarang flaw and 32-bit reseed limitation. Publication was accelerated due to active exploitation already underway.","source":"Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware — Block Engineering Blog","source_url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware"},{"date":"2026-08-02","event":"Coinkite draws separate criticism for revealing it had retained customer purchase email addresses indefinitely despite prior public statements suggesting a 90-day deletion policy.","source":"Coinkite Under Fire for Retaining Customer Emails — Bitcoin.com News","source_url":"https://news.bitcoin.com/security/coinkite-under-fire-for-retaining-customer-emails-after-88m-coldcard-hack/"},{"date":"2026-08-04","event":"Total confirmed theft passes $116 million across multiple waves. Bitcoin developer James O'Beirne publishes analysis linking CTO Peter Gray to the vulnerable libngu code via GPG commit signatures on the pseudonymous 'switck' GitHub account.","source":"Bitcoin owners rocked by $116 million hack — Fortune","source_url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/"},{"date":"2026-08-07","event":"Coinkite suspends automated customer data deletion, citing anticipated legal obligations from the security incident. Customers given opt-out option.","source":"Coldcard Maker Suspends Data Deletion as Legal Proceedings Loom — Crypto Times","source_url":"https://www.cryptotimes.io/2026/08/07/coldcard-maker-suspends-data-deletion-as-legal-proceedings-loom/"},{"date":"2026-08-17","event":"CoinDesk publishes a detailed account of how the firmware bug went unnoticed for years, including analysis of the license change and security research community criticism of Coinkite's disclosure response culture.","source":"How a bug in Coldcard's code went unnoticed for years, leading to $100 million in hacked funds — CoinDesk","source_url":"https://www.coindesk.com/tech/2026/08/17/how-a-bug-in-coldcard-s-code-went-unnoticed-for-years-leading-to-usd100-million-in-hacked-funds"},{"date":"2026-08-21","event":"No criminal charges against Coinkite, Rodolfo Novak, or Peter Gray have been publicly confirmed. No class-action complaint has been formally served as of this date. Patched firmware is available for all affected models.","source":"Coinkite Updates COLDCARD After Seed Flaw — Crypto Times","source_url":"https://www.cryptotimes.io/2026/08/21/coinkite-updates-coldcard-after-seed-flaw-exposed-bitcoin-wallets/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 6f7d9d11-dbab-40c1-874c-04083d92fdf8
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.