Coldcard (Coinkite) seed entropy flaw hack — July 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 30, 2026 |
| Target type | Wallet software or provider |
| Loss | $116,000,000Published estimates range $114,000,000 to $130,000,000Price at time of incident |
| Method | Private key compromiseA 2021 firmware build fell back to a software PRNG, leaving seeds with too little entropy to resist offline enumeration |
| Chains | Bitcoin |
| Outcome | Unresolved |
What happened
Holders of Coldcard hardware wallets began losing bitcoin on 30 July 2026 to an attack that never touched a device. Galaxy Research traced roughly 594 BTC leaving about 500 addresses in the first sweep, and the total climbed across four waves over the following days to about 1,816 BTC, near $116 million, from more than 5,200 addresses.
The cause was a firmware defect dating to March 2021. A build-configuration macro was tested for existence rather than for its value, so the cryptographic library concluded the hardware random number generator was in use and bound instead to a software fallback seeded from the chip's unique identifier and its clock registers. Seeds generated on affected firmware therefore carried far less entropy than the 128 bits advertised, few enough that private keys could be reconstructed offline from nothing but the public addresses.
Coinkite's advisory places seeds generated on Mk2 or Mk3 firmware 4.0.1 through 4.1.9 at risk, and states that Mk4, Q and Mk5 seeds generated before the fixed releases carry about 72 bits of entropy rather than 128. Researchers at Block put the vulnerable range slightly wider, from 4.0.0, and dispute how the remaining entropy should be characterised. Updating firmware does not repair a seed already created; funds have to be moved to a newly generated one.
Figures still differ by source and by the date the count was taken: Bitcoin Magazine reported over $114 million, TRM Labs and Forbes about $116 million, and TechCrunch over $130 million. TRM described its own numbers as preliminary. No attribution has been established.
Sources
- CoinkitePrimary · retrieved 2026-08-09
- TRM LabsSecondary · retrieved 2026-08-09
- CoinDeskSecondary · retrieved 2026-08-09
- The Hacker NewsSecondary · retrieved 2026-08-09
- Bitcoin MagazineSecondary · retrieved 2026-08-09
Official post-mortem: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
Changes to this entry
- Loss raised from $88.6 million to $116 million. The original entry recorded Galaxy Research's tally of 1,367 BTC from 4,585 addresses, taken while the sweep was still running; a fourth wave followed and the running total reached about 1,816 BTC from more than 5,200 addresses. The range was widened to $114-130 million to span the figures different publishers now carry.
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Coldcard (Coinkite) seed entropy flaw hack — July 2026", iTokenly, accessed 2026-08-19, https://itokenly.com/hacks/coldcard-seed-entropy-flawhttps://itokenly.com/hacks/coldcard-seed-entropy-flawPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.