Coldcard / Coinkite — Firmware Seed Entropy Exploit (Multi-Actor, August 2026)
Summary
A build-integration defect introduced in Coldcard firmware version 4.0.1 (March 2021) silently routed BIP-39 seed generation to a weak software pseudorandom number generator instead of the device's STM32 hardware random number generator, reducing effective entropy from the intended 128 bits to as low as 40 bits on Mk3 devices and approximately 72 bits on Mk4, Mk5, and Q models. Beginning July 30, 2026, at least 15 independent threat actors exploited the flaw to brute-force private keys offline and sweep affected wallets without physical device access. As of August 10, 2026, losses exceed 2,055 BTC (approximately $130 million USD) across more than 7,700 addresses, making this the largest hardware wallet exploit on record.
Connected Entities
1 entitiesTimeline(8 events)
2021-03-01
Coldcard firmware version 4.0.1 released, introducing the build-integration defect that routes seed generation to MicroPython's Yasmarang software PRNG instead of the STM32 hardware RNG.
COLDCARD Security Disclosure History — Coinkite2026-07-30
First confirmed attack wave begins. Approximately 1,082.65 BTC ($70.2 million) drained from 1,196 addresses within 41 minutes using offline brute-force seed recovery. Coinkite publishes initial security advisory.
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News2026-07-31
Coinkite CEO Rodolfo Novak (NVK) issues public apology, accepts full corporate responsibility. Emergency patched firmware released at 9:33 AM EDT for all affected model lines (Mk2/Mk3 v4.2.0, Mk4/Mk5 v5.6.0, Q v1.5.0Q, Edge variants). Second confirmed theft wave recorded. CoinDesk reports approximately $38 million stolen in the initial period.
Coldcard Security Advisory — COINKITE Blog; CoinDesk2026-08-01
Third wave of thefts identified over the weekend of August 1–2. Cumulative losses approach $89 million per Fox Business reporting.
Coldcard bitcoin hardware wallet flaw linked to $89M bitcoin theft — Fox Business2026-08-03
Fortune publishes in-depth coverage. TRM Labs and Galaxy Research estimate losses at approximately 1,816 BTC ($116 million) across 5,200+ addresses. Fortune confirms Block Engineering published the technical RNG analysis and Galaxy Research mapped attack patterns.
Bitcoin owners rocked by $116 million hack — Fortune2026-08-04
Fourth wave of thefts detected. Galaxy Research's Alex Thorn publicly states at least 15 independent attackers are now exploiting the vulnerability. A 64.9 BTC Wasabi Wallet coinjoin deposit and approximately 200 ETH to Tornado Cash observed, indicating early laundering activity. Galaxy confirms 1,596 BTC stolen across approximately 7,300 addresses; estimates up to 2,055 BTC ($130 million) including unconfirmed fourth wave. TechCrunch reports total losses exceed $130 million. Galaxy begins supplying attacker/victim address clusters to federal law enforcement.
15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — Crypto Times; TechCrunch2026-08-05
TRM Labs publishes comprehensive incident report, classifying the event as the third-largest crypto hack of 2026 and the largest hardware wallet exploit on record.
The Largest Hardware Wallet Exploit of 2026 — TRM Labs2026-08-10
Coinkite's internal tracking logs exceed 2,000 BTC in total stolen funds. Approximately 90% of stolen Bitcoin remains unmoved on-chain. No formal class action or regulatory action filed as of this date. Investigation ongoing.
Coinkite firmware update tracking; Galaxy Research ongoing reportingDecision Log
- #1publish⛓ pending8/10/2026, 11:06:51 PMhash: Gaa9YCNcjXyNEkZXKfv8F6Xd6sFJ6p9rcmPtLmBkpqFA
21 of 23 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/10/2026, 11:06:36 PM
last updated: 8/11/2026, 10:02:25 AM
avoid.net — verified advice for a post-truth world