Skip to main content
AVOID.NET

Coldcard Firmware Vulnerability (Standalone Investigation)

avoid.net/coldcard-firmware-vulnerability-standalone-investigation20/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·5MM3bg…y4WK

Summary

A firmware build error introduced in March 2021 caused Coldcard hardware wallets to generate Bitcoin wallet seeds using a weak software pseudorandom number generator (Yasmarang) instead of the device's hardware entropy source. The flaw lay dormant for over five years until attackers began exploiting predictable private keys starting July 30, 2026, draining approximately 1,789 BTC (roughly $114.7 million at time of theft) from 8,865 addresses across multiple waves. Any seed generated on affected Coldcard firmware between March 2021 and the emergency patch remains compromised regardless of current firmware version.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Coldcard Firmware Vulnerability (Standalone Investigation)?

Timeline(8 events)

1 March 2021

Coldcard firmware version 4.0.1 released. A build error in the libngu migration causes seed generation to use MicroPython's Yasmarang software PRNG instead of the STM32 hardware TRNG. The flaw reduces effective seed entropy to approximately 40 bits on Mk2/Mk3 and approximately 72 bits on later models.

Coinkite Official Blog (Technical Deep Dive)

30 July 2026

Wave One of the exploit begins at approximately 2:14 AM UTC. Approximately 594 BTC is drained from roughly 500 addresses in approximately 25 minutes. Coinkite publishes its initial security advisory the same day.

CoinDesk / Coinkite Official Blog

31 July 2026

Coinkite releases emergency patched firmware: version 5.6.0 for Mk4/Mk5 and version 1.5.0Q for the Q model. The patch addresses the PRNG fallback but cannot repair seeds already generated under vulnerable firmware.

COLDCARD Security Update — Coinkite Blog

2 August 2026

Galaxy Research identifies a third wave, raising the confirmed total to approximately 1,367 BTC across 4,585 addresses (~$88.6 million).

Yahoo Finance / Coldcard Bitcoin Exploit reporting

4 August 2026

Alex Thorn of Galaxy Research states publicly that at least 15 different attackers have exploited the vulnerability. TRM Labs publishes its analysis noting multiple suspected attackers and exploratory laundering patterns. TechCrunch reports losses exceeding $130 million including a suspected fourth wave.

CoinTelegraph / TRM Labs / TechCrunch

6 August 2026

Last confirmed attacker activity observed, according to Galaxy Research's August 24 analysis.

Galaxy Research via The Crypto Times

24 August 2026

Galaxy Research publishes final analysis: 1,789 BTC high-confidence losses from 8,865 addresses (~$114.7 million at time of theft). 221 victim reports documented. Affected address lists shared with exchanges and law enforcement.

Galaxy Research via The Crypto Times

1 August 2026

Coinkite releases firmware version 5.6.1 / 1.5.1Q with additional hardening: mandatory user entropy input for new seeds, hardware TRNG boot-time verification, pre-signing transaction integrity checks, and data isolation improvements.

COLDCARD Security Update 5.6.1 / 1.5.1Q — Coinkite Blog
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 0 of 17 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 9/21/2026, 5:04:30 PM

last updated: 9/21/2026, 5:04:45 PM

avoid.net — verified advice for a post-truth world