Coldcard Firmware Vulnerability (Standalone Investigation)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·5MM3bg…y4WKSummary
A firmware build error introduced in March 2021 caused Coldcard hardware wallets to generate Bitcoin wallet seeds using a weak software pseudorandom number generator (Yasmarang) instead of the device's hardware entropy source. The flaw lay dormant for over five years until attackers began exploiting predictable private keys starting July 30, 2026, draining approximately 1,789 BTC (roughly $114.7 million at time of theft) from 8,865 addresses across multiple waves. Any seed generated on affected Coldcard firmware between March 2021 and the emergency patch remains compromised regardless of current firmware version.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(8 events)
1 March 2021
Coldcard firmware version 4.0.1 released. A build error in the libngu migration causes seed generation to use MicroPython's Yasmarang software PRNG instead of the STM32 hardware TRNG. The flaw reduces effective seed entropy to approximately 40 bits on Mk2/Mk3 and approximately 72 bits on later models.
Coinkite Official Blog (Technical Deep Dive)30 July 2026
Wave One of the exploit begins at approximately 2:14 AM UTC. Approximately 594 BTC is drained from roughly 500 addresses in approximately 25 minutes. Coinkite publishes its initial security advisory the same day.
CoinDesk / Coinkite Official Blog31 July 2026
Coinkite releases emergency patched firmware: version 5.6.0 for Mk4/Mk5 and version 1.5.0Q for the Q model. The patch addresses the PRNG fallback but cannot repair seeds already generated under vulnerable firmware.
COLDCARD Security Update — Coinkite Blog2 August 2026
Galaxy Research identifies a third wave, raising the confirmed total to approximately 1,367 BTC across 4,585 addresses (~$88.6 million).
Yahoo Finance / Coldcard Bitcoin Exploit reporting4 August 2026
Alex Thorn of Galaxy Research states publicly that at least 15 different attackers have exploited the vulnerability. TRM Labs publishes its analysis noting multiple suspected attackers and exploratory laundering patterns. TechCrunch reports losses exceeding $130 million including a suspected fourth wave.
CoinTelegraph / TRM Labs / TechCrunch6 August 2026
Last confirmed attacker activity observed, according to Galaxy Research's August 24 analysis.
Galaxy Research via The Crypto Times24 August 2026
Galaxy Research publishes final analysis: 1,789 BTC high-confidence losses from 8,865 addresses (~$114.7 million at time of theft). 221 victim reports documented. Affected address lists shared with exchanges and law enforcement.
Galaxy Research via The Crypto Times1 August 2026
Coinkite releases firmware version 5.6.1 / 1.5.1Q with additional hardening: mandatory user entropy input for new seeds, hardware TRNG boot-time verification, pre-signing transaction integrity checks, and data isolation improvements.
COLDCARD Security Update 5.6.1 / 1.5.1Q — Coinkite BlogDecision Log
- hash: DEumASneJJgdgTEaULbytQp3urFEhYmjfYzJvpsCpnGm
This investigation is cryptographically anchored to the Solana blockchain (1 event). 0 of 17 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/21/2026, 5:04:30 PM
last updated: 9/21/2026, 5:04:45 PM
avoid.net — verified advice for a post-truth world