Coldcard (Coinkite) seed entropy flaw hack — July 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 30, 2026 |
| Target type | Wallet software or provider |
| Loss | $88,600,000Published estimates range $70,200,000 to $89,000,000Price at time of incident |
| Method | Private key compromiseA 2021 firmware build fell back to a software PRNG, leaving seeds with too little entropy to resist offline enumeration |
| Chains | Bitcoin |
| Outcome | Unresolved |
What happened
Holders of Coldcard hardware wallets began losing bitcoin on 30 July 2026 to an attack that never touched a device. Galaxy Research traced 1,082.65 BTC, about $70.2 million at the time, leaving 1,196 addresses in a single 41-minute sweep between 01:10 and 01:51 UTC. Further waves brought the total to 1,367.05 BTC, roughly $88.6 million, across 4,585 addresses; Galaxy cautioned that the third wave should not be assumed to involve the same attacker.
The cause was a firmware defect dating to March 2021. A build-configuration macro was tested for existence rather than for its value, so the cryptographic library concluded the hardware random number generator was in use and bound instead to a software fallback seeded from the chip's unique identifier and its clock registers. Seeds generated on affected firmware therefore carried far less entropy than the 128 bits advertised, few enough that private keys could be reconstructed offline from nothing but the public addresses.
Coinkite's advisory places seeds generated on Mk2 or Mk3 firmware 4.0.1 through 4.1.9 at risk, and states that Mk4, Q and Mk5 seeds generated before the fixed releases carry about 72 bits of entropy rather than 128. Researchers at Block put the vulnerable range slightly wider, from 4.0.0, and dispute how the remaining entropy should be characterised. Updating firmware does not repair a seed already created; funds have to be moved to a newly generated one.
This incident is unresolved and the figures are still moving. No attribution has been established: Galaxy found no earlier transactions matching the sweep's fee and change pattern.
Sources
- CoinkitePrimary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- The Hacker NewsSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
Official post-mortem: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Coldcard (Coinkite) seed entropy flaw hack — July 2026", iTokenly, accessed 2026-08-03, https://itokenly.com/hacks/coldcard-seed-entropy-flawhttps://itokenly.com/hacks/coldcard-seed-entropy-flawPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.