Skip to main content
AVOID.NET

Coldcard (Coinkite Hardware Wallet Exploit)

avoid.net/coldcard-coinkite-hardware-wallet-exploit12/100·85% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·61yszM…Pv6f

Summary

Coldcard is a Bitcoin-only hardware wallet produced by Toronto-based Coinkite Inc. Beginning July 30, 2026, attackers exploited a firmware build error introduced in March 2021 that caused seed generation to fall back on a weak software pseudorandom number generator instead of the device's hardware entropy source, reducing effective key strength to as little as 40 bits on older models. Across four attack waves spanning several days, roughly 1,816 BTC (approximately $116 million) was drained from over 5,200 addresses without any physical access to the affected devices, making it the largest hardware wallet exploit on record.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Coldcard (Coinkite Hardware Wallet Exploit)?

Timeline(14 events)

28 January 2021

Vulnerable macro check exists in the libngu library, predating its integration into Coldcard firmware.

Block Engineering Blog

1 March 2021

Coldcard firmware migrates to the libngu cryptographic library, introducing the vulnerable code path.

Block Engineering Blog

17 March 2021

Firmware version 4.0.0 released with the RNG fallback bug active; seed generation silently begins using weak Yasmarang PRNG on Mk2/Mk3 devices.

Block Engineering Blog

11 March 2022

A 32-bit reseed API is added to libngu.

Block Engineering Blog

14 March 2022

Mk4 firmware v5.0.0 released including 32-bit reseed; Mk4/Q/Mk5 seeds carry ~72-bit effective entropy rather than 40 bits, but remain below the intended 128-bit security level.

Block Engineering Blog

1 May 2025

Bitcoin developer James O'Beirne reportedly flags the flawed randomness code to Coinkite. According to third-party reporting, CTO Peter Gray responds with an argument from absence rather than a technical review.

Phemex — Coinkite Was Warned 14 Months Early About the Coldcard Flaw

30 July 2026

Wave 1 attack: approximately 1,082.65 BTC drained from ~1,196 addresses in approximately 41 minutes. Coinkite issues a security advisory the same day.

TRM Labs

31 July 2026

Wave 2 attack: ~594 BTC drained from ~500 addresses in ~25 minutes. Coinkite CEO Rodolfo Novak publishes public apology. Emergency patched firmware released for all models.

CoinDesk / TRM Labs

1 August 2026

Wave 3: approximately 208 BTC drained from ~1,912 addresses.

Fortune

3 August 2026

Wave 4 detected; cumulative total reaches approximately 1,816 BTC (~$116 million) from over 5,200 addresses.

Fortune / TRM Labs

4 August 2026

Limited laundering activity detected: 64.9 BTC deposited to Wasabi Wallet; 200 ETH deposited to Tornado Cash after BTC converted via THORChain.

CryptoTimes

4 August 2026

Coinkite reverses policy of automatically deleting customer records, citing anticipated legal obligations from the incident.

Cryptopolitan

7 August 2026

Roughly 90% of stolen BTC remains unmoved; ~600 flagged attacker addresses shared with exchanges and law enforcement. No arrest or fund seizure announced.

TRM Labs

1 August 2026

Coinkite releases hardened follow-up firmware (v5.6.1 for Mk4/Mk5, v1.5.1Q for Q) approximately three weeks after initial emergency patch, following a comprehensive post-incident audit.

Crowdfund Insider
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 0 of 22 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 9/23/2026, 5:05:15 PM

last updated: 9/23/2026, 5:05:34 PM

avoid.net — verified advice for a post-truth world