Coldcard / Coinkite Hardware Wallet Firmware Exploit
Summary
A firmware entropy bug silently present in Coldcard hardware wallets since March 2021 caused affected devices to bypass their hardware random number generator (TRNG) and fall back to a software-based pseudo-random generator seeded by non-secret chip data, reducing seed entropy from the intended 128 bits to approximately 40 bits on Mk3 devices and 72 bits on Mk4/Mk5/Q devices. On July 31, 2026, an unknown attacker exploited the vulnerability to sweep approximately 594 BTC (roughly $38 million) from around 500 single-signature wallets in approximately 25 minutes; Galaxy Research subsequently documented total losses of approximately 1,082 BTC (~$70 million) across a broader attack window. Firmware updates do not retroactively repair already-generated seeds, meaning any wallet seed created under affected firmware versions remains at risk until funds are migrated to a new wallet generated on patched firmware.
Connected Entities
1 entities · 10 linked investigationsTimeline(8 events)
2021-03-01
Coldcard firmware 4.0.0 / 4.0.1 released for Mk3, introducing the seed-generation defect that replaced the hardware TRNG call (ckcc.rng_bytes) with a software PRNG path (ngu.random.bytes / Yasmarang), reducing effective entropy to approximately 40 bits on Mk3 devices.
COINKITE Blog Security Advisory; CryptoTimes2021-03-01
Mk4, Mk5, and Q devices begin shipping with firmware that similarly reduced seed entropy to approximately 72 bits, with the flaw present in all versions prior to the patched releases.
Bitcoin Well; COINKITE Blog2026-07-30
Coinkite publishes a security advisory disclosing the firmware entropy vulnerability affecting Coldcard Mk3 devices (firmware 4.0.1 through 4.1.9) and Mk4/Mk5/Q devices (seeds generated before patched firmware versions). Fixed firmware versions released: 4.2.0+ for Mk3, 5.6.0+ for Mk4/Mk5, 1.5.0Q+ for Q.
COINKITE Blog Security Advisory2026-07-31
Between approximately 01:31 and 01:56 UTC, an unknown attacker sweeps approximately 594 BTC (~$38 million) from roughly 500 single-signature wallets across three blockchain blocks in approximately 25 minutes. All drained wallets are single-signature; affected coins include UTXOs dormant since 2021.
CoinDesk; crypto.news2026-07-31
Coinkite CEO NVK issues public apology, accepts full responsibility, and urgently advises all users who generated seeds on affected firmware to migrate funds immediately. NVK alleges the vulnerability may have been discovered by the attacker using artificial intelligence.
Bitcoin Magazine; Bitcoin.com News2026-07-31
Galaxy Research documents total losses of approximately 1,082.65 BTC (~$70 million) across 1,196 addresses, with an attack window spanning blocks 960,183 through 960,191 (approximately 41 minutes). Researcher Clay Garrett identifies approximately 695 earlier matching transactions indicating broader scope.
The Block; Bitcoin Magazine2026-07-31
Bitcoin Core developer Gregory Sanders reproduces the attack using Mk3 setup button-press counts, confirming impact on Mk3 and Mk2 models. Kevin Loaec (Wizardsardine) and Rob Hamilton (AnchorWatch) are among early public alerts.
TFTC; CryptoTimes2026-08-01
Investigation date. No regulatory actions or class action lawsuits against Coinkite publicly confirmed. Attacker identity remains unknown. Stolen BTC remains in attacker-controlled addresses per available on-chain data.
AVOID.NET investigationDecision Log
- #1publish⛓ pending8/1/2026, 12:07:49 PMhash: 4hSYPvDB6KTtZ6YyvXuXsFWwhs68cpCkfDYtNxUKPjkN
9 of 13 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/1/2026, 12:07:40 PM
last updated: 8/1/2026, 6:52:21 PM
avoid.net — verified advice for a post-truth world