Skip to main content
AVOID.NET

Coldcard Hardware Wallet

avoid.net/coldcard-hardware-wallet→32/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·5YTKzm…Xpho

Summary

Coldcard is a Bitcoin-only hardware wallet manufactured by Canadian company Coinkite, long regarded as one of the most security-focused consumer Bitcoin signing devices available. In July 2026, a five-year-old firmware flaw introduced in March 2021 was exploited to drain approximately 1,816 BTC (~$116 million) from more than 5,200 affected wallet addresses — the largest hardware wallet exploit in recorded history. Coinkite published a security advisory, issued patched firmware, and suspended its standard customer-data deletion policy pending anticipated legal proceedings; no formal class action had been filed as of the date of this investigation.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Coldcard Hardware Wallet?

Timeline(11 events)

1 March 2021

Firmware version 4.0.1 released. A build configuration error routes seed generation through a software PRNG (Yasmarang via libngu) rather than the hardware RNG, reducing entropy to as low as 40 bits on Mk2/Mk3 devices and ~72 bits on Mk4/Mk5/Q.

COINKITE Blog — Coldcard Security Advisory

1 May 2025

Bitcoin developer James O'Beirne reportedly warns Coinkite about the flawed randomness code. According to Phemex reporting, Coinkite dismisses the concern, arguing the flaw would have surfaced already if genuine. Coinkite has not publicly confirmed or denied this notification.

Coinkite Was Warned 14 Months Early About the Coldcard Flaw — Phemex

30 July 2026

Exploitation begins. In approximately 25 minutes, attackers drain ~594 BTC (~$38 million) from roughly 500 wallet addresses in the first wave. Coinkite publishes its initial security advisory the same day.

The Largest Hardware Wallet Exploit of 2026 — TRM Labs

31 July 2026

CoinDesk reports cumulative losses have reached ~$38 million across multiple wallets, describing the incident as shaking faith in Bitcoin self-custody.

Coldcard Exploit Reignites Bitcoin Self-Custody Debate After $38 Million Theft — CoinDesk

3 August 2026

Theft waves 2 through 4 complete. Total losses reach approximately 1,816 BTC (~$116 million) across more than 5,200 addresses — the largest hardware wallet exploit in recorded history.

The Largest Hardware Wallet Exploit of 2026 — TRM Labs

4 August 2026

TechCrunch reports total losses exceeding $130 million. Fox Business reports approximately 1,200 affected addresses with ~$89 million drained.

Hackers Steal Over $130M by Exploiting Bug in Offline Hardware Wallets — TechCrunch

6 August 2026

Bloomberg reports that Coinkite declined to publicly estimate total losses from the exploit.

Bitcoin Wallet Maker Coinkite Won't Estimate Losses From Coldcard Hack — Bloomberg

7 August 2026

Coinkite suspends its standard 120-day customer data deletion policy, citing anticipated legal proceedings. Customers may individually request an exemption.

Update on Customer Data Retention — COINKITE Blog

1 August 2026

Coinkite releases patched firmware: version 5.6.1 for Mk4/Mk5 and 1.5.1Q for Q series. Patched firmware does not remediate already-generated vulnerable seeds.

Coldcard Issues Enhanced Firmware Update Amid Ongoing Bitcoin Theft Fallout — Crowdfund Insider

20 August 2026

Coinkite's public disclosure history records 30 security-relevant events total, including 13 with evidence of coordinated disclosure, updated to reflect the 2026 entropy incident.

COLDCARD Security Disclosure History — Coinkite

1 September 2026

Pre-litigation victim coordination ongoing. Thomas Braziel of 117 Partners is collecting loss documentation across multiple jurisdictions. No formal class action has been filed as of this date.

A Class Action Is Looming Against Coinkite After the COLDCARD Wallets Hacking — Cointribune
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 22 of 24 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 9/26/2026, 11:07:48 PM

last updated: 9/27/2026, 9:16:27 AM

avoid.net — verified advice for a post-truth world