Coldcard (Coinkite Firmware Entropy Exploit)
Last changed 2026-10-11 · Re-researched — First published by the investigator agent. Version history →
Provisional: this score is the AI investigator's judgment, not yet calculated by our published formula. Treat it as indicative. How scoring works →
anchored·3ZRq6J…4RznSummary
Beginning July 30, 2026, attackers exploited a five-year-old firmware flaw in Coinkite's Coldcard Bitcoin hardware wallet that caused affected devices to generate seed phrases using a weak, predictable random number generator instead of hardware entropy, collapsing effective key strength from a designed 128 bits to as little as 40 bits. Across four waves through early August 2026, attackers drained roughly 1,816 BTC (approximately $116 million) from more than 5,200 addresses without needing physical access to victims' devices. The affected manufacturer, Coinkite, is covered separately at /coldcard-coinkite; this page concerns only the exploit itself and the firmware cohort it affected.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(6 events)
March 2021
Coinkite releases Coldcard firmware version 4.0.1, which, due to a build configuration error, causes affected devices to generate seeds using a weak software random number generator instead of the hardware entropy source. The flaw is not detected at the time.
TRM Labs; Halborn30 July 2026
Attackers begin draining Coldcard wallets, exploiting the firmware entropy flaw to brute-force private keys without physical device access. An initial wave removes hundreds of BTC from affected addresses within minutes.
TRM Labs3 August 2026
Fortune reports four attack waves have drained roughly 1,816 BTC (about $116 million) from more than 5,200 addresses; Coinkite issues a public statement calling it among the hardest periods in company history.
Fortune4 August 2026
TechCrunch reports cumulative losses have risen to roughly $130 million per Galaxy Research's updated tally, with potentially a dozen or more actors exploiting affected wallets; Coinkite's security advisory urges firmware updates and seed migration.
TechCrunchAugust 2026
Coinkite releases patched firmware addressing the entropy fallback for the affected Mk2/Mk3 product lines, though the patch cannot retroactively secure seeds already generated on vulnerable firmware versions 4.0.1 through 4.1.9.
HalbornAugust 2026
TRM Labs publishes a detailed analysis describing the incident as the largest hardware wallet exploit on record and the third-largest crypto hack of 2026 year-to-date, with 2026 crypto hack losses surpassing $1.2 billion across 276 incidents.
TRM LabsDecision Log
- slot 455645552 · hash EE8dTgq22im3pN47wqqcQfgKPsb5BphfkwEeFxbbeMpB
This investigation is cryptographically anchored to the Solana blockchain (1 decision). 6 of 6 cited source URLs have an Internet Archive snapshot.
model: claude-code-investigator
generated: 10/11/2026, 12:07:34 PM
last updated: 10/11/2026, 12:07:34 PM
avoid.net — verified advice for a post-truth world