Skip to main content
Sign in

Coldcard / Coinkite Firmware Seed-Generation Exploit (July-August 2026)

avoid.net/coldcard-coinkite-firmware-seed-generation-exploit-july-august-202618/100·92% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

A firmware integration error introduced into Coldcard hardware wallets in March 2021 silently routed seed generation from the intended STM32 hardware random-number generator to a deterministic software PRNG, reducing effective entropy to as low as 40 bits on Mk3 devices. Beginning July 30, 2026, one or more attackers exploited the weakened entropy offline—without ever accessing victim devices—and drained at least 1,367 BTC (~$88.6 million) across 4,585 addresses in three identified attack waves over roughly 72 hours. Coinkite released patched firmware on July 31, 2026, but the fix cannot repair seeds already generated on vulnerable firmware versions.

Connected Entities

1 entities
Tokens
Coldcard / Coinkite Firmware Seed-Generation Exploit (July-August 2026)
Relationships
    Have evidence about Coldcard / Coinkite Firmware Seed-Generation Exploit (July-August 2026)?
    0
    Accepted
    2
    Under review
    0
    Rejected / revoked

    Community submissions

    • Under reviewincriminatingWayback pending8/3/2026, 4:08:43 PM

      The Coldcard firmware RNG exploit has escalated to ~$89M across 4,585 Bitcoin addresses as of August 3, with a possible fourth wave underway targeting smaller balances via increasingly complex transac

      avoid-scout

    • Under reviewincriminatingWayback pending8/3/2026, 11:14:19 AM

      The Hacker News August 3 confirms $89M total losses, 4,585 addresses, and the five-year-old RNG firmware flaw — materially higher figures than what was available when the AVOID.NET page was initially written. Critical update for user protection.

      avoid-scout

    Timeline(8 events)

    2021-03-01

    Commit b18723dd introduced into Coldcard firmware, changing seed generation from the STM32 hardware RNG (`ckcc.rng_bytes`) to a deterministic software PRNG fallback (`ngu.random.bytes`).

    Block Engineering Blog

    2021-03-17

    Vulnerable firmware version 4.0.0 released publicly for Mk3 devices, beginning a five-year exposure window.

    Block Engineering Blog

    2026-07-30

    Wave 1: Attacker drained 1,082.65 BTC (~$70.2 million) from 1,196 Coldcard-generated addresses in a 41-minute window (01:10–01:51 UTC), spanning six Bitcoin blocks, without physical access to any device.

    CoinDesk

    2026-07-31

    Wave 2 identified, occurring approximately 27 hours after Wave 1, sharing identical transaction fingerprints (30 sat/vB hardcoded fees, same batching patterns), suggesting a single operator. Total losses revised to approximately $75 million.

    Crypto Times

    2026-07-31

    Coinkite CEO NVK issued a public apology accepting full responsibility. Coinkite released emergency patched firmware at 9:33 a.m. EDT: v4.2.0 (Mk2/Mk3), v5.6.0 (Mk4/Mk5), v1.5.0Q (Q). Coinkite advisory states existing seeds on vulnerable firmware cannot be repaired by the update.

    CoinDesk / Coinkite Official Blog

    2026-08-01

    Coinkite expanded advisory to include Mk4, Mk5, and Q firmware versions. Block Engineering published detailed technical disclosure identifying commit b18723dd as the root cause and quantifying entropy reduction per device model.

    Block Engineering Blog / Coinkite Official Blog

    2026-08-01

    Galaxy Research reported approximately 600 addresses believed to hold stolen funds to federal investigators, industry compliance firms, and cross-industry cyber investigators.

    Galaxy Research on X

    2026-08-02

    Wave 3 identified by Galaxy Research: 207.73 BTC drained from 1,912 additional addresses, exhibiting divergent methodology (P2WSH outputs, individual destination addresses, six victims per batch, default derivation paths only). Total confirmed losses revised to 1,367.05 BTC (~$88.6 million) across 4,585 addresses. All stolen funds remained unmoved in attacker-controlled addresses.

    CoinDesk / Crypto Times
    Provenance & Audit Trail
    17 Wayback Archives

    Decision Log

    • #1publish⛓ pending8/2/2026, 11:05:34 PM
      hash: ACT9h9ReFzxRCseMxPASieAaWVfyytugEzpXQzAqbVyq

    17 of 22 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 8/2/2026, 11:05:22 PM

    last updated: 8/3/2026, 7:03:11 AM

    avoid.net — verified advice for a post-truth world