Coldcard Hardware Wallet Firmware Seed Entropy Exploit
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
Summary
A build-configuration error introduced into Coldcard hardware wallet firmware (made by Toronto-based Coinkite) in March 2021 caused affected devices to generate wallet seeds using a weak, deterministic software pseudorandom number generator instead of dedicated hardware entropy sources. Beginning July 30, 2026, attackers exploited the flaw to brute-force and sweep an estimated 1,816+ BTC (~$116 million) from more than 5,200 addresses across four waves, in what researchers describe as the largest hardware wallet exploit on record. Bitcoin developer James O'Beirne says he flagged the underlying randomness defect to Coinkite roughly 14 months earlier, in May 2025, and was told the problem would likely already have surfaced if it were real; he later published cryptographic evidence tying the vulnerable code's pseudonymous author to Coinkite co-founder and CTO Peter Gray.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(9 events)
17 March 2021
Coldcard firmware version 4.0.0, containing the defective libngu RNG-fallback logic, is released, beginning the period during which affected devices generated seeds with critically weakened entropy.
Block Engineering BlogMay 2025
Bitcoin developer James O'Beirne says he identified the flawed randomness code in Coldcard's libngu library during an audit and warned Coinkite; he states the company dismissed the concern, saying a genuine problem would likely have already surfaced.
CoinDesk30 July 2026
Attackers begin sweeping bitcoin from Coldcard-generated addresses in the first of four coordinated waves, exploiting the weak-entropy seed vulnerability.
TRM LabsJuly 2026
Coinkite publishes an initial security advisory regarding the Coldcard seed-generation vulnerability.
Coinkite Blog1 August 2026
Coinkite updates its public security advisory with additional detail on affected firmware versions and remediation steps.
Coinkite Blog4 August 2026
Cumulative reported losses reach over $130 million (subsequently converging on a widely cited total of roughly 1,816 BTC / $116 million) from more than 5,200 addresses across four waves; TechCrunch and other outlets report Coinkite has not provided detailed comment.
TechCrunchAugust 2026
James O'Beirne publishes cryptographic analysis alleging that the pseudonymous author of the vulnerable libngu code, known as 'Switch,' is Coinkite co-founder and CTO Peter Gray, based on matching GPG commit signatures.
Cryptopolitan17 August 2026
CoinDesk publishes retrospective reporting and opinion analysis on how the bug went unnoticed for years and what it reveals about reputation-based trust in hardware wallet security.
CoinDeskAugust 2026
Victims begin organizing toward a potential class-action lawsuit against Coinkite, coordinated in part by 117 Partners; no lawsuit has been formally filed as of the most recent available reporting.
Cointribunemodel: claude-code-investigator
generated: 9/22/2026, 5:05:14 PM
last updated: 9/22/2026, 9:21:15 PM
avoid.net — verified advice for a post-truth world