Skip to main content
AVOID.NET

Coldcard Hardware Wallet Firmware Seed Entropy Exploit

avoid.net/coldcard-hardware-wallet-firmware-seed-entropy-exploit8/100·85% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

Summary

A build-configuration error introduced into Coldcard hardware wallet firmware (made by Toronto-based Coinkite) in March 2021 caused affected devices to generate wallet seeds using a weak, deterministic software pseudorandom number generator instead of dedicated hardware entropy sources. Beginning July 30, 2026, attackers exploited the flaw to brute-force and sweep an estimated 1,816+ BTC (~$116 million) from more than 5,200 addresses across four waves, in what researchers describe as the largest hardware wallet exploit on record. Bitcoin developer James O'Beirne says he flagged the underlying randomness defect to Coinkite roughly 14 months earlier, in May 2025, and was told the problem would likely already have surfaced if it were real; he later published cryptographic evidence tying the vulnerable code's pseudonymous author to Coinkite co-founder and CTO Peter Gray.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Coldcard Hardware Wallet Firmware Seed Entropy Exploit?

Timeline(9 events)

17 March 2021

Coldcard firmware version 4.0.0, containing the defective libngu RNG-fallback logic, is released, beginning the period during which affected devices generated seeds with critically weakened entropy.

Block Engineering Blog

May 2025

Bitcoin developer James O'Beirne says he identified the flawed randomness code in Coldcard's libngu library during an audit and warned Coinkite; he states the company dismissed the concern, saying a genuine problem would likely have already surfaced.

CoinDesk

30 July 2026

Attackers begin sweeping bitcoin from Coldcard-generated addresses in the first of four coordinated waves, exploiting the weak-entropy seed vulnerability.

TRM Labs

July 2026

Coinkite publishes an initial security advisory regarding the Coldcard seed-generation vulnerability.

Coinkite Blog

1 August 2026

Coinkite updates its public security advisory with additional detail on affected firmware versions and remediation steps.

Coinkite Blog

4 August 2026

Cumulative reported losses reach over $130 million (subsequently converging on a widely cited total of roughly 1,816 BTC / $116 million) from more than 5,200 addresses across four waves; TechCrunch and other outlets report Coinkite has not provided detailed comment.

TechCrunch

August 2026

James O'Beirne publishes cryptographic analysis alleging that the pseudonymous author of the vulnerable libngu code, known as 'Switch,' is Coinkite co-founder and CTO Peter Gray, based on matching GPG commit signatures.

Cryptopolitan

17 August 2026

CoinDesk publishes retrospective reporting and opinion analysis on how the bug went unnoticed for years and what it reveals about reputation-based trust in hardware wallet security.

CoinDesk

August 2026

Victims begin organizing toward a potential class-action lawsuit against Coinkite, coordinated in part by 117 Partners; no lawsuit has been formally filed as of the most recent available reporting.

Cointribune
Provenance & Audit Trail
13 Wayback Archives

13 of 13 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 9/22/2026, 5:05:14 PM

last updated: 9/22/2026, 9:21:15 PM

avoid.net — verified advice for a post-truth world