Skip to main content
Sign in

Coldcard / Coinkite — Firmware Seed Entropy Exploit (Multi-Actor, August 2026)

avoid.net/coldcard-coinkite-firmware-seed-entropy-exploit-multi-actor-august-202618/100·91% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

A build-integration defect introduced in Coldcard firmware version 4.0.1 (March 2021) silently routed BIP-39 seed generation to a weak software pseudorandom number generator instead of the device's STM32 hardware random number generator, reducing effective entropy from the intended 128 bits to as low as 40 bits on Mk3 devices and approximately 72 bits on Mk4, Mk5, and Q models. Beginning July 30, 2026, at least 15 independent threat actors exploited the flaw to brute-force private keys offline and sweep affected wallets without physical device access. As of August 10, 2026, losses exceed 2,055 BTC (approximately $130 million USD) across more than 7,700 addresses, making this the largest hardware wallet exploit on record.

Connected Entities

1 entities
Tokens
Coldcard / Coinkite — Firmware Seed Entropy Exploit (Multi-Actor, August 2026)
Relationships
    Have evidence about Coldcard / Coinkite — Firmware Seed Entropy Exploit (Multi-Actor, August 2026)?

    Timeline(8 events)

    2021-03-01

    Coldcard firmware version 4.0.1 released, introducing the build-integration defect that routes seed generation to MicroPython's Yasmarang software PRNG instead of the STM32 hardware RNG.

    COLDCARD Security Disclosure History — Coinkite

    2026-07-30

    First confirmed attack wave begins. Approximately 1,082.65 BTC ($70.2 million) drained from 1,196 addresses within 41 minutes using offline brute-force seed recovery. Coinkite publishes initial security advisory.

    Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News

    2026-07-31

    Coinkite CEO Rodolfo Novak (NVK) issues public apology, accepts full corporate responsibility. Emergency patched firmware released at 9:33 AM EDT for all affected model lines (Mk2/Mk3 v4.2.0, Mk4/Mk5 v5.6.0, Q v1.5.0Q, Edge variants). Second confirmed theft wave recorded. CoinDesk reports approximately $38 million stolen in the initial period.

    Coldcard Security Advisory — COINKITE Blog; CoinDesk

    2026-08-01

    Third wave of thefts identified over the weekend of August 1–2. Cumulative losses approach $89 million per Fox Business reporting.

    Coldcard bitcoin hardware wallet flaw linked to $89M bitcoin theft — Fox Business

    2026-08-03

    Fortune publishes in-depth coverage. TRM Labs and Galaxy Research estimate losses at approximately 1,816 BTC ($116 million) across 5,200+ addresses. Fortune confirms Block Engineering published the technical RNG analysis and Galaxy Research mapped attack patterns.

    Bitcoin owners rocked by $116 million hack — Fortune

    2026-08-04

    Fourth wave of thefts detected. Galaxy Research's Alex Thorn publicly states at least 15 independent attackers are now exploiting the vulnerability. A 64.9 BTC Wasabi Wallet coinjoin deposit and approximately 200 ETH to Tornado Cash observed, indicating early laundering activity. Galaxy confirms 1,596 BTC stolen across approximately 7,300 addresses; estimates up to 2,055 BTC ($130 million) including unconfirmed fourth wave. TechCrunch reports total losses exceed $130 million. Galaxy begins supplying attacker/victim address clusters to federal law enforcement.

    15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — Crypto Times; TechCrunch

    2026-08-05

    TRM Labs publishes comprehensive incident report, classifying the event as the third-largest crypto hack of 2026 and the largest hardware wallet exploit on record.

    The Largest Hardware Wallet Exploit of 2026 — TRM Labs

    2026-08-10

    Coinkite's internal tracking logs exceed 2,000 BTC in total stolen funds. Approximately 90% of stolen Bitcoin remains unmoved on-chain. No formal class action or regulatory action filed as of this date. Investigation ongoing.

    Coinkite firmware update tracking; Galaxy Research ongoing reporting
    Provenance & Audit Trail
    21 Wayback Archives

    Decision Log

    • #1publish⛓ pending8/10/2026, 11:06:51 PM
      hash: Gaa9YCNcjXyNEkZXKfv8F6Xd6sFJ6p9rcmPtLmBkpqFA

    21 of 23 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 8/10/2026, 11:06:36 PM

    last updated: 8/11/2026, 10:02:25 AM

    avoid.net — verified advice for a post-truth world