← Coldcard Firmware Exploit (2026)1 decision on this page
Audit log
Every state-changing event for Coldcard Firmware Exploit (2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-13 23:29:55ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 446,828,570
- sig
3ig2EfoSaKwt…gwEEdUtWexplorer ↗- hash
C2Ed2Zf3wnCJ…DXcGsftHsha256 → base58
verifying row…full verify ↗canonical bytes (30978 B) ▸
{"actor":"system:backfill","investigation_id":"03b9b84f-8853-453c-94ea-8d007ec9314f","kind":"publish","page_slug":"coldcard-firmware-exploit-2026","published_at":"2026-09-13T23:29:55.525Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Coldcard Firmware Exploit (2026)","sections":[{"content":"A single code commit dated March 1, 2021, authored in Coinkite's firmware repository, introduced the root cause of the exploit. During a migration to Bitcoin Core's libsecp256k1, Coinkite adopted libNgU, an embedded MicroPython library. The production build defined the preprocessor macro MICROPY_HW_ENABLE_RNG as zero, intending to disable the software PRNG path. However, the guard condition used #ifndef — checking whether the macro existed rather than whether it was nonzero. Because the macro was defined (even as zero), the #error directive designed to block compilation did not fire, and MicroPython's built-in Yasmarang PRNG compiled alongside the intended hardware TRNG code. During linking, the rng_get() function incorrectly resolved to the software implementation rather than the STM32 hardware random number generator.\n\nThe Yasmarang PRNG was initialized only from the chip's unique ID and timer registers, without collecting fresh entropy afterward. This meant an attacker who could sufficiently constrain or enumerate the device UID, timer state, and prior RNG-call history could reproduce candidate seed output streams offline, then check derived Bitcoin addresses against the public blockchain to identify vulnerable wallets — without ever touching the physical device.\n\nEffective entropy impact: Mk2 and Mk3 devices were reduced to approximately 40 bits of effective entropy; Mk4, Mk5, and Q devices fared slightly better at approximately 72 bits due to additional entropy contribution from their secure elements (SE1 and SE2). Both are far below the 128 bits expected from a standard 12-word BIP-39 seed.\n\nSources: Coinkite's own technical advisory and blog post acknowledge the build defect and confirm these entropy estimates.","heading":"The Vulnerability: Build-Flag Error in Firmware 4.0.1","severity":"critical","sources":[{"credibility":1,"name":"Coldcard Security Advisory | COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":1,"name":"Technical Deep Dive into the Entropy Issue | COINKITE Blog","type":"official","url":"https://blog.coinkite.com/entropy-technical-backgrounder/"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes | The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"}]},{"content":"The vulnerability affected the following Coldcard models and firmware versions:\n\n- Mk2 and Mk3: firmware versions 4.0.1 through 4.1.9 (shipped March 2021 through the July 2026 patch)\n- Mk4 and Mk5: all versions before 5.6.0\n- Coldcard Q: all versions before 1.5.0Q\n- Mk4/Mk5 Edge builds: before version 6.6.0X\n- Q Edge builds: before version 6.6.0QX\n\nSeeds generated with at least 50 independent, fair dice rolls (the 'dice entropy' feature) during the vulnerable period are not affected by this flaw. Seeds protected by a strong, unique BIP-39 passphrase are harder to access via seed compromise alone, though Coinkite still recommends replacing seeds from the affected period as a precaution.\n\nCoinkite confirmed: 'The COLDCARD devices themselves were not hacked, remotely accessed, or taken over.' The compromise is entirely in the seed generation phase; existing device hardware was not the attack surface.","heading":"Affected Firmware Versions and Devices","severity":"critical","sources":[{"credibility":1,"name":"Coldcard Security Advisory | COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":1,"name":"COLDCARD Security Disclosure History – Coinkite","type":"official","url":"https://coinkite.com/historical-disclosures"}]},{"content":"Attacks began on July 30, 2026, and proceeded across at least four distinct waves through approximately August 6, 2026, after which no confirmed new attack activity was observed.\n\nWave 1 (July 30, 2026): Approximately 594 BTC (roughly $38 million) was drained from around 500 addresses in approximately 25 minutes, according to CoinDesk's initial report. Separately, The Hacker News reported that 1,082.65 BTC was removed from 1,196 addresses in 41 minutes on July 30 — the discrepancy likely reflects different counting windows or definitions of Wave 1.\n\nSubsequent waves: Galaxy Research tracked additional waves that extended losses to 1,367 BTC across 4,585 addresses by August 2, and then onward to a confirmed 1,778–1,789 BTC across 8,865 addresses by mid-August.\n\nFinal estimates: TRM Labs and Galaxy Research produced slightly differing totals. Galaxy Research's August 14 and August 24 reports placed confirmed losses at approximately 1,778–1,789 BTC (roughly $111–115 million at time-of-theft prices). TRM Labs estimated approximately 1,816 BTC ($116 million). Including medium-confidence attributions, Galaxy's broader estimate reaches approximately 1,824 BTC ($140 million at current prices as of late August).\n\nGalaxy identified at least 25–33 separate attacker footprints across waves, and transaction construction patterns differed across waves — consistent with multiple distinct threat actors rather than a single group. Approximately 221 direct victim reports have been confirmed, accounting for about 790 BTC (44.2% of identified losses); the remainder was attributed through blockchain analysis of addresses without formal victim reports.\n\nThe stolen wallets showed significant dormancy: Galaxy reported a median dormancy period of 3.2 years (average 3.6 years) for compromised wallets, indicating many victims held long-term savings.","heading":"Attack Waves: Scale and Timing","severity":"critical","sources":[{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack | TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":2,"name":"Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft | CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"credibility":2,"name":"Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million | CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million"},{"credibility":2,"name":"Galaxy Finds $115M Lost in Coldcard Exploit Across 8,865 Addresses | Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/galaxy-finds-115m-lost-in-coldcard-exploit-across-8865-addresses/"},{"credibility":2,"name":"Galaxy Research: 1,778 BTC Stolen in Coldcard Exploit | SpendNode","type":"news_article","url":"https://www.spendnode.io/blog/galaxy-research-1778-btc-coldcard-exploit-august-2026/"},{"credibility":2,"name":"Coldcard Bitcoin Exploit Enters Fourth Wave With 462 New Suspected Victims | BeInCrypto","type":"news_article","url":"https://beincrypto.com/coldcard-fourth-attack-wave-bitcoin/"}]},{"content":"Cryptopolitan reported that Bitcoin developer James O'Beirne traced the vulnerable code commit to Coinkite CTO Peter Gray through GPG signature analysis: 58 commits authored under the pseudonym 'Switck' carry valid GPG signatures matching the same personal key Gray used for commits under his real name in the same repository. Coinkite has not publicly addressed this identity claim.\n\nSignificantly, O'Beirne stated that he flagged the flawed randomness code to Coinkite in May 2025 — approximately 14 months before the exploits began. According to O'Beirne, Coinkite's response was, in effect, that if a flaw existed it would probably have already surfaced in the wild; the response amounted to an argument from absence rather than a technical rebuttal of the concern. Coinkite has not publicly confirmed or denied the content of this reported exchange.\n\nIt is important to note that accusing Peter Gray of misconduct based on authorship of code and a disputed prior-warning exchange carries significant limitations: authoring code that contained a bug is not itself evidence of intentional wrongdoing, and the characterization of Coinkite's response to the May 2025 warning comes from O'Beirne's own account and has not been corroborated by a second party or documentary evidence published as of this writing. Some outlets used the framing 'insider job' in their headlines; no evidence of intentional misconduct by any Coinkite employee has been publicly established.","heading":"Attribution and Prior Warning","severity":"high","sources":[{"credibility":2,"name":"Coinkite CTO Peter Gray linked to the code behind the $114M Coldcard hack | Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/"},{"credibility":2,"name":"Coinkite CTO Accused Of Ignoring Prior Warning On Coldcard Code Flaw | Bitcoin World","type":"news_article","url":"https://bitcoinworld.co.in/coinkite-cto-ignored-warning-coldcard-flaw/"},{"credibility":2,"name":"Coinkite Was Warned 14 Months Early About the Coldcard Flaw | Phemex","type":"news_article","url":"https://phemex.com/academy/coldcard-security-flaw-warning"}]},{"content":"As of September 7, 2026, approximately 82% of the stolen Bitcoin remained in attacker-controlled wallets without having been moved to exchanges or conversion services. Approximately $7.8 million had been laundered through THORChain and CoinJoin mixing services.\n\nTRM Labs noted minimal layering in the early days: only 64.9 BTC went to Wasabi Coinjoin and approximately 200 ETH-equivalent value to Tornado Cash as of August 4. Galaxy Research found that of the 1,778 BTC then confirmed stolen, approximately 1,531 BTC had not moved, with roughly 246 BTC flowing through mixing.\n\nTransaction patterns across waves differed significantly, and TRM Labs explicitly declined to attribute the theft to a specific actor. The laundering behavior was described as exploratory rather than matching the fast, aggressive patterns typical of state-sponsored groups such as North Korea's TraderTraitor cluster.","heading":"Stolen Funds: On-Chain Status and Laundering","severity":"high","sources":[{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack | TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":2,"name":"Coldcard Bitcoin Exploit: Latest Theft and Laundering Update | Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/09/07/coldcard-bitcoin-exploit-theft/"}]},{"content":"Galaxy Research assessed with stated 'high confidence' that at least some of the attackers used AI models without cybersecurity safeguards to discover or carry out the exploit. The report cited the recently released open-source Kimi K3 model as an example of the type of system it believes was used, and suggested attackers may have relied on Chinese open-source models for both vulnerability discovery and attack execution.\n\nGalaxy's analysis is described as primarily circumstantial: it rests on attack sophistication and the practical availability of unrestricted AI tools, not on intercepted communications, recovered code artifacts, or other direct forensic evidence linking specific AI systems to the intrusion. This should therefore be read as an analytical hypothesis rather than a forensically demonstrated fact.\n\nGalaxy noted an asymmetry: security defenders faced restrictions from U.S. AI labs' safety policies, leaving protective teams dependent on the same category of Chinese open-source models as the alleged attackers. Rob Hamilton of Anchorwatch was quoted as noting this asymmetry in the context of hardware wallet security reviews.","heading":"Alleged Use of AI in the Attack","severity":"medium","sources":[{"credibility":2,"name":"Coldcard Attackers Likely Used Unrestricted AI Models, Galaxy Says | Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/15/coldcard-attackers-likely-used-unrestricted-ai-models-galaxy-says/"},{"credibility":2,"name":"Galaxy Research Confirms $111M Stolen Funds in Coldcard Exploit | Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/08/galaxy-research-confirms-111m-stolen-funds-in-coldcard-exploit/"}]},{"content":"Coinkite published a security advisory on July 30, 2026, updated August 1, 2026. The company shipped emergency patched firmware on July 31, 2026: version 5.6.1 for Mk4 and Mk5, and version 1.5.1Q for Coldcard Q. The fixed firmware requires newly generated seeds to incorporate user-supplied entropy through at least 65 keypresses with unpredictable timing, 50 dice rolls, or 128 coin flips.\n\nCoinkite's advisory was explicit that updating firmware does not repair seeds already generated on vulnerable firmware versions. All users who generated seeds during the affected firmware period were directed to: (1) install fixed firmware, (2) generate a new seed on patched firmware, (3) verify backups, (4) test with a small transaction, and (5) gradually migrate funds to the new seed before discarding the old backup.\n\nCoinkite described the underlying issue plainly as a firmware defect: 'Attackers exploited those weak seeds offline by regenerating the corresponding private keys and stealing funds.' The company has not made any statement about compensation for victims.","heading":"Coinkite's Response and Remediation","severity":"high","sources":[{"credibility":1,"name":"Coldcard Security Advisory | COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":2,"name":"Coldcard Security Upgrade Strengthens Seed Phrase Generation | CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/coldcard-upgrade-strengthen-seed-phrase-generation"}]},{"content":"As of early August 2026, victims had threatened class-action litigation against Coinkite, the Toronto-based manufacturer of Coldcard devices. Legal analysis published by WeirFoulds LLP (a Toronto law firm, dated August 6, 2026) and by UK firm Fieldfisher identified two potential recovery routes for victims: pursuing the attackers themselves through blockchain tracing and asset recovery, and pursuing Coinkite through civil litigation.\n\nA Canadian litigation theory would likely be grounded in negligence — that Coinkite failed its duty of care to customers by permitting a known-class software defect to exist, remain undetected for five years, and persist despite an alleged 2025 warning — and in breach of contract or product liability claims.\n\nLegal experts were described as 'sharply divided' on Coinkite's liability prospects, citing Coinkite's product terms and warranty disclaimers as a complicating factor.\n\nAs of the date of this investigation (September 2026), no formal class-action lawsuit had been reported as filed in any court. The litigation threat remains at the organizing and consultation stage based on available public sources. No regulatory action by any government body (SEC, CFTC, or Canadian equivalents) had been announced.","heading":"Legal Exposure: Class-Action Threat Against Coinkite","severity":"medium","sources":[{"credibility":2,"name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery | WeirFoulds LLP","type":"other","url":"https://www.weirfoulds.com/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery"},{"credibility":2,"name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery | Mondaq","type":"other","url":"https://www.mondaq.com/canada/arbitration-dispute-resolution/1827776/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery"},{"credibility":2,"name":"Coinkite Faces Class Action Threat as Bitcoin Wallet Bug Costs Users Over 1,300 BTC | Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/"},{"credibility":2,"name":"Coldcard hack: what happened and what victims can do to recover | Fieldfisher","type":"other","url":"https://www.fieldfisher.com/en/insights/coinkite-coldcard-hack-what-victims-need-to-know"}]},{"content":"This exploit is the largest hardware wallet theft in recorded cryptocurrency history and ranks as the third-largest cryptocurrency hack of 2026 overall, according to DefiLlama data cited by Crypto Times. TRM Labs reported year-to-date crypto losses through early August 2026 exceeding $1.2 billion across 276 incidents.\n\nThe incident prompted a wider debate about self-custody security practices, third-party firmware auditing, and the supply-chain risks inherent in any hardware wallet's build pipeline. The exploit required no physical access to any device — the entire attack was conducted offline by reconstructing weak seeds from publicly accessible blockchain data.\n\nCoinDesk noted in its initial coverage that the event may push some retail investors toward Bitcoin ETFs rather than direct self-custody, reversing a trend that accelerated following the 2022 FTX collapse.","heading":"Broader Context and Self-Custody Implications","severity":"medium","sources":[{"credibility":2,"name":"Coldcard hack: how a build flag drained 116M in bitcoin | crypto.news","type":"news_article","url":"https://crypto.news/coldcard-hack-bitcoin-self-custody-entropy/"},{"credibility":1,"name":"Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit | Fortune","type":"news_article","url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/"},{"credibility":1,"name":"Hackers steal over $130M by exploiting bug in offline hardware wallets | TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"}]}],"sources_used":[{"credibility":1,"name":"Coldcard Security Advisory | COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":1,"name":"Technical Deep Dive into the Entropy Issue | COINKITE Blog","type":"official","url":"https://blog.coinkite.com/entropy-technical-backgrounder/"},{"credibility":1,"name":"COLDCARD Security Disclosure History – Coinkite","type":"official","url":"https://coinkite.com/historical-disclosures"},{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack | TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes | The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"credibility":2,"name":"Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft | CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"credibility":2,"name":"Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million | CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million"},{"credibility":2,"name":"Galaxy Finds $115M Lost in Coldcard Exploit Across 8,865 Addresses | Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/galaxy-finds-115m-lost-in-coldcard-exploit-across-8865-addresses/"},{"credibility":2,"name":"Coldcard Hack Tops $88.6M as Galaxy Finds Third Attack Wave | Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/02/coldcard-hack-tops-88-6m-as-galaxy-finds-third-attack-wave/"},{"credibility":2,"name":"Galaxy Research Confirms $111M Stolen Funds in Coldcard Exploit | Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/08/galaxy-research-confirms-111m-stolen-funds-in-coldcard-exploit/"},{"credibility":2,"name":"Coldcard Attackers Likely Used Unrestricted AI Models, Galaxy Says | Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/15/coldcard-attackers-likely-used-unrestricted-ai-models-galaxy-says/"},{"credibility":2,"name":"Galaxy Research: 1,778 BTC Stolen in Coldcard Exploit | SpendNode","type":"news_article","url":"https://www.spendnode.io/blog/galaxy-research-1778-btc-coldcard-exploit-august-2026/"},{"credibility":2,"name":"Coldcard Bitcoin Exploit Enters Fourth Wave With 462 New Suspected Victims | BeInCrypto","type":"news_article","url":"https://beincrypto.com/coldcard-fourth-attack-wave-bitcoin/"},{"credibility":2,"name":"Coinkite CTO Peter Gray linked to the code behind the $114M Coldcard hack | Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/"},{"credibility":2,"name":"Coinkite CTO Accused Of Ignoring Prior Warning On Coldcard Code Flaw | Bitcoin World","type":"news_article","url":"https://bitcoinworld.co.in/coinkite-cto-ignored-warning-coldcard-flaw/"},{"credibility":2,"name":"Coinkite Was Warned 14 Months Early About the Coldcard Flaw | Phemex","type":"news_article","url":"https://phemex.com/academy/coldcard-security-flaw-warning"},{"credibility":2,"name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery | WeirFoulds LLP","type":"other","url":"https://www.weirfoulds.com/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery"},{"credibility":2,"name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery | Mondaq","type":"other","url":"https://www.mondaq.com/canada/arbitration-dispute-resolution/1827776/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery"},{"credibility":2,"name":"Coinkite Faces Class Action Threat as Bitcoin Wallet Bug Costs Users Over 1,300 BTC | Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/"},{"credibility":2,"name":"Coldcard hack: what happened and what victims can do to recover | Fieldfisher","type":"other","url":"https://www.fieldfisher.com/en/insights/coinkite-coldcard-hack-what-victims-need-to-know"},{"credibility":2,"name":"Coldcard Security Upgrade Strengthens Seed Phrase Generation | CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/coldcard-upgrade-strengthen-seed-phrase-generation"},{"credibility":2,"name":"Coldcard hack: how a build flag drained 116M in bitcoin | crypto.news","type":"news_article","url":"https://crypto.news/coldcard-hack-bitcoin-self-custody-entropy/"},{"credibility":2,"name":"Coldcard Bitcoin Exploit: Latest Theft and Laundering Update | Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/09/07/coldcard-bitcoin-exploit-theft/"},{"credibility":1,"name":"Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit | Fortune","type":"news_article","url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/"},{"credibility":1,"name":"Hackers steal over $130M by exploiting bug in offline hardware wallets | TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"credibility":2,"name":"Coldcard Hardware Wallet Hack Drains $89m: What It Means | IG UK","type":"news_article","url":"https://www.ig.com/uk/trading-strategies/coldcard-hardware-wallet-hack-self-custody-260803"}],"summary":"Beginning July 30, 2026, attackers exploited a five-year-old build-flag error in Coinkite's Coldcard hardware wallet firmware (versions 4.0.1–4.1.9) that caused seed generation to use a weak software pseudorandom number generator (PRNG) instead of the device's hardware entropy source, reducing effective key strength to as low as 40 bits. Multiple attack waves across four days drained approximately 1,789–1,816 BTC (roughly $114–116 million) from more than 5,200 Bitcoin addresses, making it the largest hardware wallet exploit in recorded history. As of September 2026, approximately 82% of stolen funds remain in attacker-controlled wallets with limited laundering activity; no formal criminal charges or regulatory actions had been announced, and class-action litigation against Coinkite was threatened but not yet formally filed.","timeline":[{"date":"2021-03-01","event":"A commit attributed by researcher James O'Beirne to Coinkite CTO Peter Gray (via GPG signature) replaces a hardware RNG call with MicroPython's Yasmarang software PRNG in the libNgU library, introducing the entropy vulnerability.","source":"Cryptopolitan / Coinkite Technical Blog","source_url":"https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/"},{"date":"2021-03-17","event":"Coldcard firmware version 4.0.1 is publicly released, incorporating the vulnerable seed generation path. Affected devices begin generating seeds with reduced entropy.","source":"COINKITE Blog / The Hacker News","source_url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"date":"2025-05-01","event":"Bitcoin developer James O'Beirne reportedly flags the flawed randomness code to Coinkite after auditing the firmware repository, describing libNgU as a low-star, single-maintainer dependency. According to O'Beirne, Coinkite responded that the issue would likely have surfaced by now if real. Coinkite has not publicly confirmed or denied this account.","source":"Cryptopolitan / Bitcoin World","source_url":"https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/"},{"date":"2026-07-30","event":"First attack wave begins. Attackers drain approximately 594 BTC (~$38 million) from roughly 500 addresses in approximately 25 minutes (first reporting figure). Separately, Hacker News and TRM report 1,082.65 BTC removed from 1,196 addresses in 41 minutes — the discrepancy reflects differing wave-boundary definitions.","source":"CoinDesk / The Hacker News / TRM Labs","source_url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"date":"2026-07-30","event":"Coinkite publishes its security advisory disclosing the vulnerability, directing all users who generated seeds on affected firmware to migrate funds immediately.","source":"COINKITE Blog","source_url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"date":"2026-07-31","event":"Coinkite ships emergency patched firmware: version 5.6.1 for Mk4/Mk5 and 1.5.1Q for the Coldcard Q. Patched firmware requires user-supplied entropy for new seed generation. Existing seeds remain compromised.","source":"CoinTelegraph / COINKITE Blog","source_url":"https://cointelegraph.com/news/coldcard-upgrade-strengthen-seed-phrase-generation"},{"date":"2026-08-01","event":"Coinkite updates its security advisory with additional technical detail. Attack waves continue.","source":"COINKITE Blog","source_url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"date":"2026-08-02","event":"Galaxy Research identifies a third attack wave, with cumulative losses reaching 1,367 BTC (~$88.6 million) across 4,585 addresses.","source":"Crypto Times / CoinDesk","source_url":"https://www.cryptotimes.io/2026/08/02/coldcard-hack-tops-88-6m-as-galaxy-finds-third-attack-wave/"},{"date":"2026-08-04","event":"Forbes and TechCrunch publish wider-audience coverage. TRM Labs reports minimal laundering activity: 64.9 BTC to Wasabi CoinJoin and minimal ETH-side movement.","source":"Forbes / TechCrunch / TRM Labs","source_url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"date":"2026-08-06","event":"No confirmed new attack activity observed after this date, according to Galaxy Research.","source":"Galaxy Research via Crypto Times","source_url":"https://www.cryptotimes.io/2026/08/24/galaxy-finds-115m-lost-in-coldcard-exploit-across-8865-addresses/"},{"date":"2026-08-06","event":"WeirFoulds LLP (Toronto) publishes legal analysis of victim recovery options, noting class-action litigation against Coinkite was being organized. No formal filing reported.","source":"WeirFoulds LLP","source_url":"https://www.weirfoulds.com/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery"},{"date":"2026-08-09","event":"Cryptopolitan and others report O'Beirne's GPG-based attribution of the vulnerable commit to Peter Gray, Coinkite CTO. Coinkite does not publicly respond to the attribution.","source":"Cryptopolitan","source_url":"https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/"},{"date":"2026-08-14","event":"Galaxy Research report confirms 1,778 BTC stolen (~$112 million at theft prices) across 8,865+ addresses.","source":"Galaxy Research via Crypto Times","source_url":"https://www.cryptotimes.io/2026/08/08/galaxy-research-confirms-111m-stolen-funds-in-coldcard-exploit/"},{"date":"2026-08-15","event":"Galaxy Research publishes assessment that attackers likely used unrestricted AI models (citing Kimi K3 as an example) to discover and exploit the vulnerability, based on circumstantial analysis of attack sophistication. Assessed as speculative rather than forensically proven.","source":"Crypto Times","source_url":"https://www.cryptotimes.io/2026/08/15/coldcard-attackers-likely-used-unrestricted-ai-models-galaxy-says/"},{"date":"2026-08-24","event":"Galaxy Research updates final estimate to 1,789.28 BTC stolen across 8,865 addresses ($114.7 million at time of theft, approximately $138.8 million at then-current prices).","source":"Crypto Times","source_url":"https://www.cryptotimes.io/2026/08/24/galaxy-finds-115m-lost-in-coldcard-exploit-across-8865-addresses/"},{"date":"2026-09-07","event":"Approximately 82% of stolen Bitcoin reported as still frozen in attacker-controlled wallets. Approximately $7.8 million laundered through THORChain and CoinJoin. No new attack waves or criminal charges reported.","source":"Cryptonomist","source_url":"https://en.cryptonomist.ch/2026/09/07/coldcard-bitcoin-exploit-theft/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 532d261c-bdd4-4353-add9-ebf09865548c
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.