Skip to main content
Sign in

Coldcard / Coinkite Hardware Wallet Firmware Exploit

avoid.net/coldcard-coinkite-hardware-wallet-firmware-exploit18/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

A firmware entropy bug silently present in Coldcard hardware wallets since March 2021 caused affected devices to bypass their hardware random number generator (TRNG) and fall back to a software-based pseudo-random generator seeded by non-secret chip data, reducing seed entropy from the intended 128 bits to approximately 40 bits on Mk3 devices and 72 bits on Mk4/Mk5/Q devices. On July 31, 2026, an unknown attacker exploited the vulnerability to sweep approximately 594 BTC (roughly $38 million) from around 500 single-signature wallets in approximately 25 minutes; Galaxy Research subsequently documented total losses of approximately 1,082 BTC (~$70 million) across a broader attack window. Firmware updates do not retroactively repair already-generated seeds, meaning any wallet seed created under affected firmware versions remains at risk until funds are migrated to a new wallet generated on patched firmware.

Have evidence about Coldcard / Coinkite Hardware Wallet Firmware Exploit?

Timeline(8 events)

2021-03-01

Coldcard firmware 4.0.0 / 4.0.1 released for Mk3, introducing the seed-generation defect that replaced the hardware TRNG call (ckcc.rng_bytes) with a software PRNG path (ngu.random.bytes / Yasmarang), reducing effective entropy to approximately 40 bits on Mk3 devices.

COINKITE Blog Security Advisory; CryptoTimes

2021-03-01

Mk4, Mk5, and Q devices begin shipping with firmware that similarly reduced seed entropy to approximately 72 bits, with the flaw present in all versions prior to the patched releases.

Bitcoin Well; COINKITE Blog

2026-07-30

Coinkite publishes a security advisory disclosing the firmware entropy vulnerability affecting Coldcard Mk3 devices (firmware 4.0.1 through 4.1.9) and Mk4/Mk5/Q devices (seeds generated before patched firmware versions). Fixed firmware versions released: 4.2.0+ for Mk3, 5.6.0+ for Mk4/Mk5, 1.5.0Q+ for Q.

COINKITE Blog Security Advisory

2026-07-31

Between approximately 01:31 and 01:56 UTC, an unknown attacker sweeps approximately 594 BTC (~$38 million) from roughly 500 single-signature wallets across three blockchain blocks in approximately 25 minutes. All drained wallets are single-signature; affected coins include UTXOs dormant since 2021.

CoinDesk; crypto.news

2026-07-31

Coinkite CEO NVK issues public apology, accepts full responsibility, and urgently advises all users who generated seeds on affected firmware to migrate funds immediately. NVK alleges the vulnerability may have been discovered by the attacker using artificial intelligence.

Bitcoin Magazine; Bitcoin.com News

2026-07-31

Galaxy Research documents total losses of approximately 1,082.65 BTC (~$70 million) across 1,196 addresses, with an attack window spanning blocks 960,183 through 960,191 (approximately 41 minutes). Researcher Clay Garrett identifies approximately 695 earlier matching transactions indicating broader scope.

The Block; Bitcoin Magazine

2026-07-31

Bitcoin Core developer Gregory Sanders reproduces the attack using Mk3 setup button-press counts, confirming impact on Mk3 and Mk2 models. Kevin Loaec (Wizardsardine) and Rob Hamilton (AnchorWatch) are among early public alerts.

TFTC; CryptoTimes

2026-08-01

Investigation date. No regulatory actions or class action lawsuits against Coinkite publicly confirmed. Attacker identity remains unknown. Stolen BTC remains in attacker-controlled addresses per available on-chain data.

AVOID.NET investigation
Provenance & Audit Trail
9 Wayback Archives

Decision Log

  • #1publish⛓ pending8/1/2026, 12:07:49 PM
    hash: 4hSYPvDB6KTtZ6YyvXuXsFWwhs68cpCkfDYtNxUKPjkN

9 of 13 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/1/2026, 12:07:40 PM

last updated: 8/1/2026, 6:52:21 PM

avoid.net — verified advice for a post-truth world