Incident record · disclosed 30 July 2026
For more than five years, affected COLDCARD firmware created seeds without its hardware random number generator.
A COLDCARD is intended to create recovery words using the STM32 hardware random number generator on its main chip. In affected releases from March 2021 until fixes on 31 July 2026, a build-configuration error sent seed creation to a deterministic software generator instead. Seeds generated in that window can have far fewer possible values than intended.
How much fewer depends on the model. On Mk2 and Mk3 the software generator received no cryptographic entropy at all. On Mk4, Mk5 and Q a secure-element reseed carried at most 32 bits into it, one input among several rather than the whole of the remaining strength: Coinkite estimates about 72 bits of effective search space for those models, against the 128 bits intended.
About 594 BTC moved in the attributed 30 July sweep. After identifying a third wave on 1 August, Galaxy Research put the wider attributed total at 1,367.05 BTC across 4,585 addresses, and says it has not tested whether those addresses were in fact generated with low entropy. How much of that movement the flaw itself caused is not established from public evidence.
Start here
Are your coins affected?
Six questions at most. Your answers are processed by code running in your browser and are not transmitted. This site never asks for seed words, passphrases or extended private keys.
Explore the incident
Six paths cover exposure, migration, firmware mechanics, the evidence record, the wider response and seed hygiene.
Your risk
Published attack-cost models and their assumptions, by configuration. Passphrases, multisig thresholds, dice, and the migration itself.
02Moving funds
The ordered procedure for getting funds off an affected seed: verify the new wallet first, test, sweep, retire the old words. Multisig wallets get their own migration page.
03How it broke
The guard, the two generators, the truncated reseed, and how the fix works. Code claims cite checks against the source repositories.
04Evidence
134 snapshots across 59 sources, with diffs. Who said what, when they revised it, and what the earlier version said.
05The response
What Coinkite, Block, independent developers and researchers said and shipped, the legal posture, and the evidence around claimed AI-assisted discovery and post-disclosure reproduction.
06Seed safety
What never to do with recovery words during an incident, whoever is asking, and how to assess incident-themed requests that could expose recovery material.
How this is evidenced
This is an independent explainer and source archive. Material claims and claim groups state how they are known and link to their evidence. Advisories can change during an incident, so earlier versions are retained: 45 reviewed changes to published source content so far, across 59 sources, alongside 24 further detected differences reviewed as capture noise or collection corrections and preserved separately.