Skip to main content
AVOID.NET

Coldcard (Coinkite Firmware Entropy Exploit)

avoid.net/coldcard-coinkite-firmware-entropy-exploit→5/100·82% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Last changed 2026-10-11 · Re-researched — First published by the investigator agent. Version history →

Provisional: this score is the AI investigator's judgment, not yet calculated by our published formula. Treat it as indicative. How scoring works →

anchored·3ZRq6J…4Rzn
last updated 2026-10-11

Summary

Beginning July 30, 2026, attackers exploited a five-year-old firmware flaw in Coinkite's Coldcard Bitcoin hardware wallet that caused affected devices to generate seed phrases using a weak, predictable random number generator instead of hardware entropy, collapsing effective key strength from a designed 128 bits to as little as 40 bits. Across four waves through early August 2026, attackers drained roughly 1,816 BTC (approximately $116 million) from more than 5,200 addresses without needing physical access to victims' devices. The affected manufacturer, Coinkite, is covered separately at /coldcard-coinkite; this page concerns only the exploit itself and the firmware cohort it affected.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Coldcard (Coinkite Firmware Entropy Exploit)?

Timeline(6 events)

March 2021

Coinkite releases Coldcard firmware version 4.0.1, which, due to a build configuration error, causes affected devices to generate seeds using a weak software random number generator instead of the hardware entropy source. The flaw is not detected at the time.

TRM Labs; Halborn

30 July 2026

Attackers begin draining Coldcard wallets, exploiting the firmware entropy flaw to brute-force private keys without physical device access. An initial wave removes hundreds of BTC from affected addresses within minutes.

TRM Labs

3 August 2026

Fortune reports four attack waves have drained roughly 1,816 BTC (about $116 million) from more than 5,200 addresses; Coinkite issues a public statement calling it among the hardest periods in company history.

Fortune

4 August 2026

TechCrunch reports cumulative losses have risen to roughly $130 million per Galaxy Research's updated tally, with potentially a dozen or more actors exploiting affected wallets; Coinkite's security advisory urges firmware updates and seed migration.

TechCrunch

August 2026

Coinkite releases patched firmware addressing the entropy fallback for the affected Mk2/Mk3 product lines, though the patch cannot retroactively secure seeds already generated on vulnerable firmware versions 4.0.1 through 4.1.9.

Halborn

August 2026

TRM Labs publishes a detailed analysis describing the incident as the largest hardware wallet exploit on record and the third-largest crypto hack of 2026 year-to-date, with 2026 crypto hack losses surpassing $1.2 billion across 276 incidents.

TRM Labs
Provenance & Audit Trail

Decision Log

  • #1publishRecorded on Solana ✓10/11/2026, 12:07:40 PM
    slot 455645552 · hash EE8dTgq22im3pN47wqqcQfgKPsb5BphfkwEeFxbbeMpB

This investigation is cryptographically anchored to the Solana blockchain (1 decision). 6 of 6 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 10/11/2026, 12:07:34 PM

last updated: 10/11/2026, 12:07:34 PM

avoid.net — verified advice for a post-truth world