Skip to main content
AVOID.NET

Audit log

Every state-changing event for Coldcard Firmware Vulnerability (Standalone Investigation): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-21 17:04:45Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 449,117,320
    sig
    5MM3bgCJBM7n…Wj3py4WKexplorer ↗
    hash
    DEumASneJJgd…vpsCpnGmsha256 → base58
    verifying row…full verify ↗
    canonical bytes (23337 B) ▸
    {"actor":"system:backfill","investigation_id":"2e8494c6-57c9-4f11-b28f-f16c12c1151e","kind":"publish","page_slug":"coldcard-firmware-vulnerability-standalone-investigation","published_at":"2026-09-21T17:04:45.502Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Coldcard Firmware Vulnerability (Standalone Investigation)","sections":[{"content":"The vulnerability originated in Coldcard firmware version 4.0.1, released by Coinkite in March 2021, when the codebase was migrated to the libngu cryptographic library. During this migration, seed generation was routed through the ngu.random.bytes() call in libngu. A preprocessor guard in libngu's build system used the directive #ifndef MICROPY_HW_ENABLE_RNG to decide whether to use hardware or software randomness. Coinkite had set MICROPY_HW_ENABLE_RNG=0 in the production board configuration, intending to disable the software fallback. However, #ifndef tests only whether a macro is defined, not its value. Because the macro was defined (as zero), the guard condition evaluated to false, the intended #error halt was never triggered, and the linker silently resolved ngu.random.bytes() to MicroPython's built-in Yasmarang pseudorandom number generator rather than the STM32 hardware true random number generator (TRNG). According to Coinkite's technical backgrounder, after Yasmarang is initialized on its first call, no new entropy is collected; every subsequent output is a deterministic state transition from that initial state. On Mk2 and Mk3 devices, which lacked additional entropy sources, effective key strength was reduced to approximately 40 bits. On Mk4, Mk5, and Q devices, the firmware mixed in entropy from two secure elements (SE1 and SE2), but Block's independent engineering analysis found this reseeding retained only four bytes (32 bits) of the secure-element output, raising the ceiling to approximately 72 bits rather than the intended 128 bits. Both figures fall well below the 128-bit security level specified by BIP-39. Block's analysis determined that for Mk2/Mk3 devices with a known device UID and timing state, wallet generation is effectively deterministic; the practical search space for those devices was estimated at approximately 2^16 to 2^32 candidate seeds depending on how much state information an attacker could constrain.","heading":"Vulnerability Overview","severity":"critical","sources":[{"credibility":1,"name":"Coldcard Security Advisory — Coinkite Official Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":1,"name":"Technical Deep Dive into the Entropy Issue — Coinkite Blog","type":"official","url":"https://blog.coinkite.com/entropy-technical-backgrounder/"},{"credibility":2,"name":"Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware — Block Engineering Blog","type":"research","url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware"}]},{"content":"According to Coinkite's official security advisory, the affected firmware ranges are: Mk2 and Mk3 devices running versions 4.0.1 through 4.1.9 inclusive; Mk4 and Mk5 devices running any version before 5.6.0 (standard) or 6.6.0X (Edge builds); and Q model devices running any version before 1.5.0Q (standard) or 6.6.0QX (Edge builds). Coinkite stated that Mk4, Mk5, and Q devices have the higher effective entropy floor (~72 bits) due to the secure-element mixing, while Mk2 and Mk3 devices are more severely affected (~40 bits). Coinkite also stated that other products in its lineup — TAPSIGNER, OPENDIME, and SATSCARD — are not affected. Crucially, Coinkite emphasized that a firmware update cannot repair a seed that was already generated under vulnerable firmware; the compromise is in the seed, not the device. The flaw is mitigated if the user added at least 50 independent, private dice rolls when initially creating the seed, or if the wallet is protected by a strong, unique BIP-39 passphrase that was not itself generated by the vulnerable device.","heading":"Affected Devices and Firmware Versions","severity":"critical","sources":[{"credibility":1,"name":"Coldcard Security Advisory — Coinkite Official Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"}]},{"content":"The exploit began on July 30, 2026. Wave One, identified by Galaxy Research, saw approximately 594 BTC drained from roughly 500 addresses in approximately 25 minutes beginning around 2:14 AM UTC, with transactions exhibiting a uniform 30 sat/vB fee rate and no change outputs. A second wave within 48 hours brought the cumulative total to approximately 1,082 BTC across 1,196 addresses. Galaxy Research identified a third wave on approximately August 2 that raised the confirmed total to approximately 1,367 BTC across 4,585 addresses, worth approximately $88.6 million at the time. A suspected fourth wave on or around August 4 was also identified. Galaxy Research's final published analysis, dated August 24, 2026, identified a high-confidence total of approximately 1,789 BTC stolen from 8,865 addresses, worth approximately $114.7 million at time of theft; the same report noted a broader estimate of up to 1,824 BTC including medium-confidence cases, with a mark-to-market value of approximately $138.8 million at August 24 prices. TRM Labs published a separate analysis titling the incident the third-largest cryptocurrency hack of 2026 and citing a figure of approximately $116 million, consistent with Galaxy's high-confidence range. No confirmed attacker activity was observed after August 6, 2026, according to Galaxy Research. Galaxy Research documented 221 victim reports covering losses of approximately 790.72 BTC — approximately 44.2 percent of the total identified — and shared affected address lists with exchanges, compliance firms, and law enforcement to prevent laundering through centralized intermediaries.","heading":"Attack Timeline and Financial Losses","severity":"critical","sources":[{"credibility":2,"name":"Galaxy Finds $115M Lost in Coldcard Exploit Across 8,865 Addresses — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/galaxy-finds-115m-lost-in-coldcard-exploit-across-8865-addresses/"},{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":2,"name":"Major Bitcoin Wallet Flaw Drains 594 BTC in 25-Minute Sweep — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep"},{"credibility":2,"name":"Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/coldcard-bitcoin-exploit-balloons-88-171851804.html"}]},{"content":"No specific threat actor group has been attributed to the exploit by law enforcement or regulators as of the time of this investigation. TRM Labs stated in its August 2026 analysis that transaction construction differed across the four waves, suggesting more than one attacker was involved, but explicitly declined to assign the theft to any particular threat group. TRM noted that the observed laundering pattern — limited consolidation, a single deposit of 64.9 BTC to Wasabi CoinJoin, and approximately 200 ETH transferred to Tornado Cash on August 4 — appeared more exploratory than the fast, aggressive laundering typical of organized groups such as North Korea's TraderTraitor cluster. Galaxy Research's head of research, Alex Thorn, stated on August 4, 2026, that at least 15 different attackers had exploited the vulnerability. Thorn identified additional attackers through individual victim reports, noting that one victim's report of less than 1 BTC stolen led to identification of a new attack wave that had siphoned 12 BTC from 126 addresses. Galaxy Research's final August 24 report identified at least 33 additional transaction footprints beyond the major waves, though it could not confirm whether all belonged to distinct actors. Bitcoin Magazine reported that AI tools may have been involved in identifying or exploiting the vulnerability, citing suggestions that AI models could rediscover the flaw in under 20 minutes once the public disclosure provided a starting point; this claim has not been independently verified by a Tier 1 source. Approximately 1,531 BTC remained unmoved in attacker-controlled addresses as of Galaxy's August 24 analysis; approximately 246 BTC had circulated, with about 65 percent of that flowing through CoinJoin transactions.","heading":"Threat Actor Attribution","severity":"high","sources":[{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":2,"name":"At Least 15 Attackers Exploited Coldcard Vulnerability: Galaxy — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/15-attackers-exploited-coldcard-vulnerability-galaxy"},{"credibility":2,"name":"15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/coldcard-exploit-15-attackers-130m-losses-galaxy/"},{"credibility":2,"name":"Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved in the Breach — Bitcoin Magazine","type":"news_article","url":"https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack"}]},{"content":"Coinkite published a security advisory disclosing the vulnerability on July 30, 2026. Emergency patched firmware was released on July 31, 2026. Fixed versions are: 5.6.0 or later for Mk4/Mk5 (standard); 6.6.0X or later for Mk4/Mk5 (Edge builds); 1.5.0Q or later for Q model (standard); 6.6.0QX or later for Q model (Edge builds). A subsequent update, version 5.6.1 / 1.5.1Q, was released approximately three weeks later with additional hardening measures. The 5.6.1 update requires user-supplied entropy for all new seeds (65 keypresses, 50 dice rolls, or 128 coin flips), combines this with multiple hardware entropy sources through double SHA-256 mixing, adds boot-time verification that the firmware code path reaches the intended hardware TRNG read, and implements pre-signing transaction verification to flag modifications made after the user reviewed a transaction. Coinkite stated clearly that a firmware update alone does not secure funds controlled by a seed generated under vulnerable firmware; users must generate a new seed on patched firmware and transfer funds to the new wallet. The company advised users to verify backups with a test transaction before moving the full balance. Coinkite also stated that the devices themselves were not remotely accessed or taken over; the vulnerability was confined to the seed generation process at wallet creation time.","heading":"Official Response and Patch","severity":"high","sources":[{"credibility":1,"name":"Coldcard Security Advisory — Coinkite Official Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":1,"name":"COLDCARD Security Update 5.6.1 / 1.5.1Q — Coinkite Blog","type":"official","url":"https://blog.coinkite.com/coldcard-security-update-5.6.1-1.5.1q/"}]},{"content":"The window of affected seed generation runs from March 2021 (firmware 4.0.1) through July 30, 2026, the date of public disclosure and emergency patch release. Any Coldcard user who generated a new seed on a device running firmware in this range should treat that seed as cryptographically compromised regardless of what firmware version the device currently runs, because the weakness is in the seed itself. The risk is not mitigated by updating firmware; it is only mitigated by migrating funds to a freshly generated seed on patched firmware. Coinkite specified two conditions under which the original seed may be sufficiently secure despite the firmware flaw: the user added at least 50 independent, private dice rolls as additional entropy at seed creation time, or the wallet is protected by a strong, unique BIP-39 passphrase. Users who restored an existing seed phrase from paper backup onto a compromised device carry the same risk; the vulnerability affects seed generation, not restoration. As of Galaxy Research's August 24, 2026 report, a substantial portion of vulnerable addresses had not yet been swept by attackers, meaning funds in unmigrated wallets remained at ongoing risk. Bitcoin Well published a user-facing advisory reiterating these migration steps.","heading":"Ongoing User Risk","severity":"critical","sources":[{"credibility":1,"name":"Coldcard Security Advisory — Coinkite Official Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":2,"name":"COLDCARD Vulnerability: What Owners Need to Know — Bitcoin Well","type":"news_article","url":"https://bitcoinwell.com/coldcard-vulnerability"},{"credibility":2,"name":"Galaxy Finds $115M Lost in Coldcard Exploit Across 8,865 Addresses — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/galaxy-finds-115m-lost-in-coldcard-exploit-across-8865-addresses/"}]},{"content":"Block's engineering team published an independent technical analysis of the vulnerability, confirming the macro guard failure and providing its own entropy calculations. Block found that for Mk4/Q/Mk5 devices, even with the secure-element reseeding, the implementation hashed the secure-element output and retained only four bytes before reseeding, restricting the search space to at most 2^32 securely distinguished output streams. Block's analysis estimated approximately 2^31 candidate trials for average enumeration on current devices, which it described as insufficient for cryptographic security in modern threat models. Blocksec also published a forensic analysis of the vulnerability titled 'COLDCARD Incident: When a Wallet's Random Seed Wasn't Random.' A separate audit reportedly conducted with AI tooling identified 85 additional critical bugs across Bitcoin wallet firmware in the aftermath of the Coldcard disclosure, according to Crypto News; those findings are described as being across multiple wallet implementations and have not been independently verified as of this writing.","heading":"Independent Security Research","severity":"medium","sources":[{"credibility":2,"name":"Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware — Block Engineering Blog","type":"research","url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware"},{"credibility":2,"name":"COLDCARD Incident: When a Wallet's 'Random' Seed Wasn't Random — Blocksec","type":"research","url":"https://blocksec.com/blog/coldcard-entropy-failure-seed-recovery"},{"credibility":2,"name":"Coldcard's RNG Flaw Is Still Draining Wallets, and an AI Audit Just Found 85 More Critical Bugs — Crypto News","type":"news_article","url":"https://crypto.news/coldcard-rng-flaw-bitcoin-wallet-ai-audit/"}]}],"sources_used":[{"credibility":1,"name":"Coldcard Security Advisory — Coinkite Official Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":1,"name":"Technical Deep Dive into the Entropy Issue — Coinkite Blog","type":"official","url":"https://blog.coinkite.com/entropy-technical-backgrounder/"},{"credibility":1,"name":"COLDCARD Security Update 5.6.1 / 1.5.1Q — Coinkite Blog","type":"official","url":"https://blog.coinkite.com/coldcard-security-update-5.6.1-1.5.1q/"},{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":2,"name":"Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware — Block Engineering Blog","type":"research","url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware"},{"credibility":2,"name":"Galaxy Finds $115M Lost in Coldcard Exploit Across 8,865 Addresses — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/galaxy-finds-115m-lost-in-coldcard-exploit-across-8865-addresses/"},{"credibility":2,"name":"At Least 15 Attackers Exploited Coldcard Vulnerability: Galaxy — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/15-attackers-exploited-coldcard-vulnerability-galaxy"},{"credibility":2,"name":"15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/coldcard-exploit-15-attackers-130m-losses-galaxy/"},{"credibility":2,"name":"Major Bitcoin Wallet Flaw Drains 594 BTC in 25-Minute Sweep — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"credibility":2,"name":"Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/coldcard-bitcoin-exploit-balloons-88-171851804.html"},{"credibility":2,"name":"Hackers Steal Over $130M by Exploiting Bug in Offline Hardware Wallets — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"credibility":2,"name":"COLDCARD Vulnerability: What Owners Need to Know — Bitcoin Well","type":"news_article","url":"https://bitcoinwell.com/coldcard-vulnerability"},{"credibility":2,"name":"COLDCARD Incident: When a Wallet's 'Random' Seed Wasn't Random — Blocksec","type":"research","url":"https://blocksec.com/blog/coldcard-entropy-failure-seed-recovery"},{"credibility":2,"name":"Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved in the Breach — Bitcoin Magazine","type":"news_article","url":"https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack"},{"credibility":2,"name":"Coldcard Hack: How a Build Flag Drained $116M in Bitcoin — Crypto News","type":"news_article","url":"https://crypto.news/coldcard-hack-bitcoin-self-custody-entropy/"},{"credibility":2,"name":"Coldcard's RNG Flaw Is Still Draining Wallets — Crypto News","type":"news_article","url":"https://crypto.news/coldcard-rng-flaw-bitcoin-wallet-ai-audit/"}],"summary":"A firmware build error introduced in March 2021 caused Coldcard hardware wallets to generate Bitcoin wallet seeds using a weak software pseudorandom number generator (Yasmarang) instead of the device's hardware entropy source. The flaw lay dormant for over five years until attackers began exploiting predictable private keys starting July 30, 2026, draining approximately 1,789 BTC (roughly $114.7 million at time of theft) from 8,865 addresses across multiple waves. Any seed generated on affected Coldcard firmware between March 2021 and the emergency patch remains compromised regardless of current firmware version.","timeline":[{"date":"2021-03-01","event":"Coldcard firmware version 4.0.1 released. A build error in the libngu migration causes seed generation to use MicroPython's Yasmarang software PRNG instead of the STM32 hardware TRNG. The flaw reduces effective seed entropy to approximately 40 bits on Mk2/Mk3 and approximately 72 bits on later models.","source":"Coinkite Official Blog (Technical Deep Dive)","source_url":"https://blog.coinkite.com/entropy-technical-backgrounder/"},{"date":"2026-07-30","event":"Wave One of the exploit begins at approximately 2:14 AM UTC. Approximately 594 BTC is drained from roughly 500 addresses in approximately 25 minutes. Coinkite publishes its initial security advisory the same day.","source":"CoinDesk / Coinkite Official Blog","source_url":"https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep"},{"date":"2026-07-31","event":"Coinkite releases emergency patched firmware: version 5.6.0 for Mk4/Mk5 and version 1.5.0Q for the Q model. The patch addresses the PRNG fallback but cannot repair seeds already generated under vulnerable firmware.","source":"COLDCARD Security Update — Coinkite Blog","source_url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"date":"2026-08-02","event":"Galaxy Research identifies a third wave, raising the confirmed total to approximately 1,367 BTC across 4,585 addresses (~$88.6 million).","source":"Yahoo Finance / Coldcard Bitcoin Exploit reporting","source_url":"https://finance.yahoo.com/markets/crypto/articles/coldcard-bitcoin-exploit-balloons-88-171851804.html"},{"date":"2026-08-04","event":"Alex Thorn of Galaxy Research states publicly that at least 15 different attackers have exploited the vulnerability. TRM Labs publishes its analysis noting multiple suspected attackers and exploratory laundering patterns. TechCrunch reports losses exceeding $130 million including a suspected fourth wave.","source":"CoinTelegraph / TRM Labs / TechCrunch","source_url":"https://cointelegraph.com/news/15-attackers-exploited-coldcard-vulnerability-galaxy"},{"date":"2026-08-06","event":"Last confirmed attacker activity observed, according to Galaxy Research's August 24 analysis.","source":"Galaxy Research via The Crypto Times","source_url":"https://www.cryptotimes.io/2026/08/24/galaxy-finds-115m-lost-in-coldcard-exploit-across-8865-addresses/"},{"date":"2026-08-24","event":"Galaxy Research publishes final analysis: 1,789 BTC high-confidence losses from 8,865 addresses (~$114.7 million at time of theft). 221 victim reports documented. Affected address lists shared with exchanges and law enforcement.","source":"Galaxy Research via The Crypto Times","source_url":"https://www.cryptotimes.io/2026/08/24/galaxy-finds-115m-lost-in-coldcard-exploit-across-8865-addresses/"},{"date":"2026-08-01","event":"Coinkite releases firmware version 5.6.1 / 1.5.1Q with additional hardening: mandatory user entropy input for new seeds, hardware TRNG boot-time verification, pre-signing transaction integrity checks, and data isolation improvements.","source":"COLDCARD Security Update 5.6.1 / 1.5.1Q — Coinkite Blog","source_url":"https://blog.coinkite.com/coldcard-security-update-5.6.1-1.5.1q/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision d6bb177e-75bf-4b9e-b654-9d86dbf2ea15
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.