Skip to main content
AVOID.NET

Coldcard Wallet (Coinkite Firmware Exploit)

avoid.net/coldcard-wallet-coinkite-firmware-exploit28/100·85% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·2STasa…Yxaz

Summary

Coldcard is a Bitcoin hardware wallet manufactured by Canadian company Coinkite. Beginning July 30, 2026, attackers exploited a five-year-old firmware bug that caused seed generation to use a weak software pseudorandom number generator instead of the device hardware entropy source, reducing effective key strength to as low as 40 bits on older models. Galaxy Research estimated total losses of approximately 1,816 to 2,417 BTC (roughly $116–$151 million USD) across more than 5,200 addresses, making it the largest hardware wallet exploit on record and the third-largest crypto hack of 2026. Coinkite published a security advisory and patched firmware but has not announced any compensation program for affected users.

Connected Entities

3 entities · 60 linked investigations
Tokens
CoinkiteBitcoin62Coldcard Wallet (Coinkite Firmware Exploit)
Relationships
  • Coldcard Wallet (Coinkite Firmware Exploit)mentioned withCoinkite(70%)
  • Coinkitementioned withBitcoin(70%)
  • Coinkitementioned withColdcard Wallet (Coinkite Firmware Exploit)(75%)
  • Coldcard Wallet (Coinkite Firmware Exploit)mentioned withBitcoin(70%)

Connected Through

3 shared actors · 490 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about Coldcard Wallet (Coinkite Firmware Exploit)?

Timeline(9 events)

17 March 2021

Coldcard firmware version 4.0.0 (followed shortly by 4.0.1) released, introducing the libngu library integration error that caused seed generation to fall back to the Yasmarang software PRNG instead of the STM32 hardware RNG. Bug lay dormant in open-source code.

Block Engineering Blog; Coinkite Technical Backgrounder

30 July 2026

First wave of exploitation begins. Approximately 1,082.65 BTC (~$70.2 million) drained from 1,196 addresses in roughly 41 minutes. Coinkite publishes security advisory the same day acknowledging the vulnerability and releasing initial patched firmware.

The Hacker News; Coinkite Security Advisory

31 July 2026

CoinDesk reports total losses at approximately $38 million with the exploit still ongoing. Coinkite confirms patched firmware versions available (Mk4/Mk5: 5.6.0+; Q: 1.5.0Q+; Mk3: 4.2.0+). Self-custody debate begins publicly.

CoinDesk

2 August 2026

Galaxy Research identifies approximately 1,367 BTC drained across 4,585 addresses. Class-action threats against Coinkite reported by Bitcoin.com News. Attack spreads reported by CoinDesk.

Crypto Briefing; Bitcoin.com News

4 August 2026

Galaxy Research identifies at least 15 independent attackers. TechCrunch reports losses exceeding $130 million across more than 7,700 addresses. TRM Labs publishes full analysis characterizing the event as the largest hardware wallet exploit on record and the third-largest crypto hack of 2026.

TechCrunch; TRM Labs

6 August 2026

Galaxy Research reports no confirmed attacker activity after this date. Approximately 1,531 BTC remains unmoved in attacker-controlled addresses.

CryptoTimes (citing Galaxy Research)

7 August 2026

Coinkite suspends its standard 120-day customer data deletion policy, citing legal preservation obligations arising from anticipated litigation. Opt-out mechanism offered to customers.

CryptoTimes

14 August 2026

Galaxy Research publishes update noting attack activity has halted. Potential total losses estimated at up to 2,417 BTC (~$151.3 million) including an unconfirmed fourth wave.

Decrypt; CryptoTimes

21 August 2026

Coinkite ships additional enhanced firmware update, stating that post-incident AI-assisted code review found additional unrelated vulnerabilities in transaction approval logic, USB handling, and firmware update validation.

CoinDesk
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 18 of 19 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 9/18/2026, 11:06:22 PM

last updated: 9/19/2026, 1:01:14 AM

avoid.net — verified advice for a post-truth world