Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
publish · Coldcard Hardware Wallet
- Sequence
- #1
- Score
- →
- Cluster
- mainnet-beta
- Slot
- 450817828
- Off-chain at
- 2026-09-26T23:07:59.001Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 8SSZqX4Ws6KTi5TmW5grJDp266PHBu9ZfdPZfC6pqGLw
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (26269 chars)
{"actor":"system:backfill","investigation_id":"1dfb8799-9cd7-4d79-8502-751f5b77eb62","kind":"publish","page_slug":"coldcard-hardware-wallet","published_at":"2026-09-26T23:07:58.913Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Coldcard Hardware Wallet","sections":[{"content":"Coldcard is a Bitcoin-only hardware wallet produced by Coinkite, a Canadian company founded by Rodolfo Novak and Peter Gray. The device is designed for advanced Bitcoin users prioritizing operational security. Its architecture uses dual secure elements from different manufacturers (Microchip ATECC608 and Maxim DS28C36B) alongside a main microcontroller, so that an attacker would need to compromise all three chips simultaneously to extract a stored seed. The firmware is open-source and Coinkite publishes reproducible build instructions, enabling independent binary verification. Coldcard is Bitcoin-only and does not support other cryptocurrencies. The product line as of 2026 includes the Mk4, Mk5, and Q models. Related Coinkite products — TAPSIGNER, OPENDIME, and SATSCARD — were not affected by the 2026 entropy vulnerability.","heading":"Company and Product Overview","severity":"low","sources":[{"credibility":2,"name":"Coldcard Mk4 Review 2026 — Coin Bureau","type":"news_article","url":"https://coinbureau.com/review/coldcard-wallet-review"},{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"}]},{"content":"A build configuration error introduced in firmware version 4.0.1 (released March 2021) caused affected Coldcard devices to generate wallet seeds using a software pseudorandom number generator — specifically a library called libngu falling back to an algorithm named Yasmarang seeded from public, hardcoded constants — rather than the device's dedicated hardware random number generator. This reduced effective seed entropy from the intended 128 bits to as low as 40 bits on older Mk2/Mk3 models, and approximately 72 bits on Mk4/Mk5/Q models using the flawed firmware. Seeds with such reduced entropy can be reconstructed offline by brute force, without physical access to the device.\n\nAffected firmware versions are: Mk2 and Mk3 versions 4.0.1 through 4.1.9; Mk4/Mk5 standard versions before 5.6.0; Mk4/Mk5 Edge versions before 6.6.0X; Q standard versions before 1.5.0Q; and Q Edge versions before 6.6.0QX. Seeds generated outside this firmware window — for example, seeds created entirely by private dice rolls — are not affected.\n\nCoinkite confirmed the vulnerability in a security advisory first published July 30, 2026. Patched firmware (version 5.6.1 for Mk4/Mk5 and 1.5.1Q for the Q series) was released in early August 2026. Critically, installing the patched firmware does not remediate seeds already generated under vulnerable firmware; affected users must generate entirely new seeds on the patched device and migrate funds.","heading":"Critical Firmware Vulnerability: Seed Entropy Failure (2021-2026)","severity":"critical","sources":[{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026 — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"credibility":2,"name":"Critical Coldcard Flaw: What Happened, Who Is Affected, and What to Do — Wizardsardine","type":"research","url":"https://wizardsardine.com/blog/coldcard-rng-vulnerability/"},{"credibility":2,"name":"The 2026 Coldcard Entropy Vulnerability Explained — Crypto University","type":"news_article","url":"https://cryptouniversity.network/news/the-2026-coldcard-entropy-vulnerability-explained"}]},{"content":"Beginning July 30, 2026, one or more attackers exploited the seed entropy flaw to drain Bitcoin from wallets whose seeds had been generated under vulnerable firmware. The attack required no physical access to affected devices. According to TRM Labs, which analyzed on-chain activity, the theft proceeded in at least four waves. The first wave alone removed approximately 594 BTC (~$38 million) from roughly 500 wallet addresses in approximately 25 minutes. By August 3, 2026, cumulative losses had reached approximately 1,816 BTC (~$116 million) across more than 5,200 affected addresses, making the incident the largest hardware wallet exploit in recorded history and, according to TRM Labs, the third-largest crypto theft of 2026.\n\nTRM Labs noted minimal laundering activity — one Wasabi CoinJoin deposit of 64.9 BTC and approximately 200 ETH deposited to Tornado Cash — a pattern inconsistent with state-sponsored actors such as North Korea's Lazarus Group. As of the date of this investigation, no attacker or group has been publicly identified or charged. CBC News and TechCrunch reported on the incident; Bloomberg reported that Coinkite declined to estimate total losses publicly.","heading":"July-August 2026 Exploitation and Theft","severity":"critical","sources":[{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026 — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":1,"name":"Hackers Steal Over $130M by Exploiting Bug in Offline Hardware Wallets — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"credibility":1,"name":"What We Know About Ongoing Coldcard Hack — CBC News","type":"news_article","url":"https://www.cbc.ca/news/world/bitcoin-coinkite-security-hack-9.7295582"},{"credibility":1,"name":"Bitcoin Wallet Maker Coinkite Won't Estimate Losses From Coldcard Hack — Bloomberg","type":"news_article","url":"https://www.bloomberg.com/news/articles/2026-08-06/hacked-bitcoin-wallet-maker-declines-to-estimate-amount-lost"},{"credibility":2,"name":"A Timeline of Coldcard's $85M Bitcoin Theft — Protos","type":"news_article","url":"https://protos.com/a-timeline-of-coldcards-85m-bitcoin-theft/"}]},{"content":"According to reporting by Phemex and Bitcoinworld.co.in, Bitcoin developer James O'Beirne raised concerns about the flawed randomness code directly with Coinkite in May 2025, approximately fourteen months before the flaw was publicly disclosed and exploited. According to those reports, Coinkite's response was not a technical rebuttal but an argument from absence — that the issue would likely have surfaced already if it were genuine. Coinkite has not publicly confirmed or denied the specifics of this prior notification. Because seeds generated under the flawed firmware produce fully functional wallets with no observable defect, the bug was invisible to users and would not naturally surface without targeted brute-force search.\n\nCoinkite CTO Peter Gray was separately identified in reporting by Cryptopolitan as the individual whose code change in March 2021 introduced the vulnerable path, though the reporting did not allege intentional wrongdoing. These are published allegations; no court or regulatory body has made any finding regarding Coinkite's handling of the prior warning.","heading":"Prior Warning and Disclosure Response","severity":"high","sources":[{"credibility":2,"name":"Coinkite Was Warned 14 Months Early About the Coldcard Flaw — Phemex","type":"news_article","url":"https://phemex.com/academy/coldcard-security-flaw-warning"},{"credibility":2,"name":"Coinkite CTO Accused of Ignoring Prior Warning on Coldcard Code Flaw — Bitcoinworld.co.in","type":"news_article","url":"https://bitcoinworld.co.in/coinkite-cto-ignored-warning-coldcard-flaw/"},{"credibility":2,"name":"Coinkite CTO Peter Gray Linked to the Code Behind the $114M Coldcard Hack — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/"}]},{"content":"As of September 2026, no formal class action has been filed against Coinkite. Thomas Braziel, founder of 117 Partners, is reportedly coordinating information-gathering from victims internationally as a pre-litigation step. Legal analysis published by Canadian law firm Weir Foulds and on Mondaq identifies two potential recovery routes for affected users: pursuing the unknown attacker(s) through blockchain tracing and asset recovery, and pursuing a product liability or negligence claim against Coinkite in Canada, where the company is registered. Legal experts cited by those publications are divided on whether a negligence claim against Coinkite would succeed, with the central question being whether Coinkite could have reasonably foreseen this class of attack. Cointribune also reported the pre-litigation organizing efforts.\n\nIn Brazil, at least one individual victim — Felipe Ojeda — filed a police complaint. No criminal charges against Coinkite have been publicly announced in any jurisdiction as of this writing.","heading":"Legal Proceedings and Liability","severity":"high","sources":[{"credibility":2,"name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery — Weir Foulds","type":"other","url":"https://www.weirfoulds.com/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery"},{"credibility":2,"name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery — Mondaq","type":"other","url":"https://www.mondaq.com/canada/arbitration-dispute-resolution/1827776/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery"},{"credibility":2,"name":"A Class Action Is Looming Against Coinkite After the COLDCARD Wallets Hacking — Cointribune","type":"news_article","url":"https://www.cointribune.com/en/a-class-action-is-looming-against-coinkite-after-the-coldcard-wallets-hacking/"},{"credibility":2,"name":"Coldcard Hack: What Happened and What Victims Can Do to Recover — Fieldfisher","type":"other","url":"https://www.fieldfisher.com/en/insights/coinkite-coldcard-hack-what-victims-need-to-know"}]},{"content":"Coinkite's standard data handling practice had been to automatically delete most customer records after 120 days, retaining only email address and country of residence. In August 2026, following the exploit and in anticipation of legal proceedings, Coinkite suspended this automated deletion process. Per Coinkite's published statement, retained data would be stored securely with access restricted to authorized personnel and used only for legal compliance purposes. Customers seeking deletion could request an individual exemption. The suspension drew criticism from some privacy-focused users who cited the conflict between the company's prior privacy positioning and the decision to preserve records. No finding of any legal violation regarding the policy change has been made.","heading":"Data Retention Policy Change","severity":"medium","sources":[{"credibility":1,"name":"Update on Customer Data Retention — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/update-on-customer-data-retention/"},{"credibility":2,"name":"Coldcard Overhauls Data Retention Policy, Prepares for Legal Obligations — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/coldcard-overhauls-data-retention-policy/"},{"credibility":2,"name":"Coinkite Under Fire for Retaining Customer Emails After $88M Coldcard Hack — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/coinkite-under-fire-for-retaining-customer-emails-after-88m-coldcard-hack/"}]},{"content":"Coinkite maintained a public security disclosure history documenting 30 security-relevant events as of August 2026, spanning 2019 through 2025. Thirteen of these records include public evidence of coordinated disclosure. Prior to the 2026 entropy incident, no widespread exploitation or theft had been publicly attributed to any Coldcard vulnerability. Notable pre-2026 disclosures include: a multisig xpub substitution vulnerability (reported November 2020, fixed before publication); a USB serial port REPL debug regression in firmware 4.0.0 (corrected in 4.0.1 before public distribution); a 2019 short-PIN man-in-the-middle issue requiring invasive physical interposer; and a 2023 Ledger Donjon demonstration of a physical laser-fault chain on an Mk3 device recovering one seed in a specialist laboratory. All physical-access-dependent vulnerabilities documented prior to 2026 required specialized equipment unavailable to remote attackers. The 2026 entropy flaw is categorically different in that it required no physical access and could be exploited entirely offline.","heading":"Pre-2026 Security Disclosure History","severity":"low","sources":[{"credibility":1,"name":"COLDCARD Security Disclosure History — Coinkite","type":"official","url":"https://coinkite.com/historical-disclosures"},{"credibility":2,"name":"Explained: The Coldcard Hack (July 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-coldcard-hack-july-2026"}]},{"content":"No SEC enforcement actions, CFTC proceedings, OFAC sanctions designations, or criminal charges from any government authority against Coinkite or the Coldcard product have been identified through this investigation. Coinkite is a Canadian company and is not a registered financial institution or securities issuer in any jurisdiction identified. The absence of regulatory action as of this writing does not preclude future proceedings; legal analysis suggests that if class action litigation is filed, it would most likely be grounded in Canadian courts.","heading":"Regulatory Standing","severity":"low","sources":[{"credibility":2,"name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery — Weir Foulds","type":"other","url":"https://www.weirfoulds.com/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery"}]},{"content":"As of September 2026, patched firmware is available for all current Coldcard models. Coinkite's security advisory recommends that any user who generated a seed on affected firmware (Mk2/Mk3 versions 4.0.1 through 4.1.9; Mk4/Mk5 standard before 5.6.0; Q standard before 1.5.0Q) treat that seed as potentially compromised and migrate to a freshly generated seed on patched firmware. Seeds created using at least 50 independent private dice rolls may provide sufficient additional entropy to offset the firmware defect. Coinkite's advisory states that related products (TAPSIGNER, OPENDIME, SATSCARD) are unaffected. Independent security researchers at Wizardsardine published a technical breakdown corroborating Coinkite's root-cause analysis.","heading":"Current Status and User Guidance","severity":"high","sources":[{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":2,"name":"Coldcard Issues Enhanced Firmware Update Amid Ongoing Bitcoin Theft Fallout — Crowdfund Insider","type":"news_article","url":"https://www.crowdfundinsider.com/2026/08/300062-coldcard-issues-enhanced-firmware-update-amid-ongoing-bitcoin-btc-theft-fallout/"},{"credibility":2,"name":"Critical Coldcard Flaw: What Happened, Who Is Affected, and What to Do — Wizardsardine","type":"research","url":"https://wizardsardine.com/blog/coldcard-rng-vulnerability/"}]}],"sources_used":[{"credibility":1,"name":"Coldcard Security Advisory — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026 — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":1,"name":"Hackers Steal Over $130M by Exploiting Bug in Offline Hardware Wallets — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"credibility":1,"name":"What We Know About Ongoing Coldcard Hack — CBC News","type":"news_article","url":"https://www.cbc.ca/news/world/bitcoin-coinkite-security-hack-9.7295582"},{"credibility":1,"name":"Bitcoin Wallet Maker Coinkite Won't Estimate Losses From Coldcard Hack — Bloomberg","type":"news_article","url":"https://www.bloomberg.com/news/articles/2026-08-06/hacked-bitcoin-wallet-maker-declines-to-estimate-amount-lost"},{"credibility":2,"name":"Coldcard Exploit Reignites Bitcoin Self-Custody Debate After $38 Million Theft — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"credibility":1,"name":"Coldcard Bitcoin Hardware Wallet Flaw Linked to $89M Bitcoin Theft — Fox Business","type":"news_article","url":"https://www.foxbusiness.com/fox-news-tech/coldcard-wallet-attack-drains-up-89m-bitcoin-from-1200-addresses"},{"credibility":2,"name":"Coinkite Was Warned 14 Months Early About the Coldcard Flaw — Phemex","type":"news_article","url":"https://phemex.com/academy/coldcard-security-flaw-warning"},{"credibility":2,"name":"Coinkite CTO Accused of Ignoring Prior Warning on Coldcard Code Flaw — Bitcoinworld.co.in","type":"news_article","url":"https://bitcoinworld.co.in/coinkite-cto-ignored-warning-coldcard-flaw/"},{"credibility":2,"name":"Coinkite CTO Peter Gray Linked to the Code Behind the $114M Coldcard Hack — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/"},{"credibility":2,"name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery — Weir Foulds","type":"other","url":"https://www.weirfoulds.com/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery"},{"credibility":2,"name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery — Mondaq","type":"other","url":"https://www.mondaq.com/canada/arbitration-dispute-resolution/1827776/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery"},{"credibility":2,"name":"A Class Action Is Looming Against Coinkite After the COLDCARD Wallets Hacking — Cointribune","type":"news_article","url":"https://www.cointribune.com/en/a-class-action-is-looming-against-coinkite-after-the-coldcard-wallets-hacking/"},{"credibility":2,"name":"Coldcard Hack: What Happened and What Victims Can Do to Recover — Fieldfisher","type":"other","url":"https://www.fieldfisher.com/en/insights/coinkite-coldcard-hack-what-victims-need-to-know"},{"credibility":2,"name":"Coinkite Faces Class Action Threat as Bitcoin Wallet Bug Costs Users Over 1,300 BTC — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/"},{"credibility":1,"name":"Update on Customer Data Retention — COINKITE Blog","type":"official","url":"https://blog.coinkite.com/update-on-customer-data-retention/"},{"credibility":2,"name":"Coldcard Overhauls Data Retention Policy, Prepares for Legal Obligations — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/coldcard-overhauls-data-retention-policy/"},{"credibility":1,"name":"COLDCARD Security Disclosure History — Coinkite","type":"official","url":"https://coinkite.com/historical-disclosures"},{"credibility":2,"name":"Critical Coldcard Flaw: What Happened, Who Is Affected, and What to Do — Wizardsardine","type":"research","url":"https://wizardsardine.com/blog/coldcard-rng-vulnerability/"},{"credibility":2,"name":"Explained: The Coldcard Hack (July 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-coldcard-hack-july-2026"},{"credibility":2,"name":"Coldcard Issues Enhanced Firmware Update Amid Ongoing Bitcoin Theft Fallout — Crowdfund Insider","type":"news_article","url":"https://www.crowdfundinsider.com/2026/08/300062-coldcard-issues-enhanced-firmware-update-amid-ongoing-bitcoin-btc-theft-fallout/"},{"credibility":2,"name":"A Five-Year-Old Coldcard Bug Let Hackers Guess Bitcoin Wallet Keys, Coinkite Confirms — Blockhead","type":"news_article","url":"https://www.blockhead.co/2026/08/03/coldcard-hardware-wallets-shipped-with-broken-randomness-for-five-years-coinkite-confirms/"},{"credibility":2,"name":"Coldcard Seed Flaw: Firmware Fix and Safe Migration — Gridinsoft","type":"news_article","url":"https://blog.gridinsoft.com/coldcard-seed-generation-flaw-migration/"}],"summary":"Coldcard is a Bitcoin-only hardware wallet manufactured by Canadian company Coinkite, long regarded as one of the most security-focused consumer Bitcoin signing devices available. In July 2026, a five-year-old firmware flaw introduced in March 2021 was exploited to drain approximately 1,816 BTC (~$116 million) from more than 5,200 affected wallet addresses — the largest hardware wallet exploit in recorded history. Coinkite published a security advisory, issued patched firmware, and suspended its standard customer-data deletion policy pending anticipated legal proceedings; no formal class action had been filed as of the date of this investigation.","timeline":[{"date":"2021-03-01","event":"Firmware version 4.0.1 released. A build configuration error routes seed generation through a software PRNG (Yasmarang via libngu) rather than the hardware RNG, reducing entropy to as low as 40 bits on Mk2/Mk3 devices and ~72 bits on Mk4/Mk5/Q.","source":"COINKITE Blog — Coldcard Security Advisory","source_url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"},{"date":"2025-05-01","event":"Bitcoin developer James O'Beirne reportedly warns Coinkite about the flawed randomness code. According to Phemex reporting, Coinkite dismisses the concern, arguing the flaw would have surfaced already if genuine. Coinkite has not publicly confirmed or denied this notification.","source":"Coinkite Was Warned 14 Months Early About the Coldcard Flaw — Phemex","source_url":"https://phemex.com/academy/coldcard-security-flaw-warning"},{"date":"2026-07-30","event":"Exploitation begins. In approximately 25 minutes, attackers drain ~594 BTC (~$38 million) from roughly 500 wallet addresses in the first wave. Coinkite publishes its initial security advisory the same day.","source":"The Largest Hardware Wallet Exploit of 2026 — TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"date":"2026-07-31","event":"CoinDesk reports cumulative losses have reached ~$38 million across multiple wallets, describing the incident as shaking faith in Bitcoin self-custody.","source":"Coldcard Exploit Reignites Bitcoin Self-Custody Debate After $38 Million Theft — CoinDesk","source_url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"date":"2026-08-03","event":"Theft waves 2 through 4 complete. Total losses reach approximately 1,816 BTC (~$116 million) across more than 5,200 addresses — the largest hardware wallet exploit in recorded history.","source":"The Largest Hardware Wallet Exploit of 2026 — TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"date":"2026-08-04","event":"TechCrunch reports total losses exceeding $130 million. Fox Business reports approximately 1,200 affected addresses with ~$89 million drained.","source":"Hackers Steal Over $130M by Exploiting Bug in Offline Hardware Wallets — TechCrunch","source_url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"date":"2026-08-06","event":"Bloomberg reports that Coinkite declined to publicly estimate total losses from the exploit.","source":"Bitcoin Wallet Maker Coinkite Won't Estimate Losses From Coldcard Hack — Bloomberg","source_url":"https://www.bloomberg.com/news/articles/2026-08-06/hacked-bitcoin-wallet-maker-declines-to-estimate-amount-lost"},{"date":"2026-08-07","event":"Coinkite suspends its standard 120-day customer data deletion policy, citing anticipated legal proceedings. Customers may individually request an exemption.","source":"Update on Customer Data Retention — COINKITE Blog","source_url":"https://blog.coinkite.com/update-on-customer-data-retention/"},{"date":"2026-08-01","event":"Coinkite releases patched firmware: version 5.6.1 for Mk4/Mk5 and 1.5.1Q for Q series. Patched firmware does not remediate already-generated vulnerable seeds.","source":"Coldcard Issues Enhanced Firmware Update Amid Ongoing Bitcoin Theft Fallout — Crowdfund Insider","source_url":"https://www.crowdfundinsider.com/2026/08/300062-coldcard-issues-enhanced-firmware-update-amid-ongoing-bitcoin-btc-theft-fallout/"},{"date":"2026-08-20","event":"Coinkite's public disclosure history records 30 security-relevant events total, including 13 with evidence of coordinated disclosure, updated to reflect the 2026 entropy incident.","source":"COLDCARD Security Disclosure History — Coinkite","source_url":"https://coinkite.com/historical-disclosures"},{"date":"2026-09-01","event":"Pre-litigation victim coordination ongoing. Thomas Braziel of 117 Partners is collecting loss documentation across multiple jurisdictions. No formal class action has been filed as of this date.","source":"A Class Action Is Looming Against Coinkite After the COLDCARD Wallets Hacking — Cointribune","source_url":"https://www.cointribune.com/en/a-class-action-is-looming-against-coinkite-after-the-coldcard-wallets-hacking/"}]},"v":1}