COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Record updated 15 Aug 2026 · sources re-captured on a schedule

The public record of the COLDCARD entropy incident.

A COLDCARD is a small device that keeps the keys to your bitcoin off the internet. Setting one up creates seed words. They can rebuild the wallet, anyone who learns them can take the money, and they are supposed to be impossible to guess. On firmware released from March 2021 until the fixes on 31 July 2026, they did not come from the randomness the device was designed to use, so seed words made on that firmware can be worked out by somebody with a computer and time. On the older models that has been done; on the newer ones the researchers who have looked disagree about how hard it would be. R1 R2

On 30 July 2026 somebody did exactly that: about 594 BTC was emptied out of 500 source addresses in a matter of minutes, and researchers have since attributed more than 1,000 BTC of wider movements to the incident. R3 R4

That changing understanding is part of the incident record. Advisories have been revised, scope statements have changed, the people studying the theft publish different totals, and public discussion has included speculation and conspiracy theories. Preserving those successive states for posterity is a core purpose of this project. The chronology dates and attributes those views rather than treating them as evidence. The archive keeps every earlier version, publishes every change, and grades each material claim against evidence you can re-check, rather than reconciling them into one answer.

This record covers the two weeks after the incident broke on 30 July 2026. The project stopped collecting on 15 August 2026: everything here stays online as published, but nothing is being added or refreshed.

Inside the record

An independent archive of what has been published about this incident, preserved as it was published. Every figure here is a capture taken at a stated moment, not a live number.

Sources are re-captured on a schedule. Last capture about an hour ago.

Latest in the record

  1. · source content changed Full panic - one of my wallets was drained r/Bitcoin
  2. Captured screenshot: COLDCARD ATTACKS EASE, BUT LOSSES CLIMB captured · X post COLDCARD ATTACKS EASE, BUT LOSSES CLIMB @glxyresearch
  3. Captured screenshot: Attacker had sophisticated intel but crude sweeping methods captured · X post Attacker had sophisticated intel but crude sweeping methods @bitcoinnewscom
Evidence on this page 4 items
  1. R1
    Reported · contested

    The statement on this page that seed words made on affected firmware can be worked out, and that published estimates of the difficulty disagree for the Mk4-class devices

    Source Published candidate-space models from Block, LLFOURN, otaliptus and Coinkite. They broadly agree on the Mk2 and Mk3 spaces, which have also been reproduced on-device, and differ by orders of magnitude on Mk4, Mk5 and Q, where no drain has been confirmed in this incident's July 2026 waves

  2. R2
    Reported

    The claim on this page that affected seed generation did not use the hardware randomness the device was designed to use, on firmware released from March 2021 until the 31 July 2026 fixes

    Source Coinkite's published entropy technical backgrounder, which states that a series of bugs kept seed generation on a software fallback instead of the hardware RNG while the hardware generator stayed in the firmware for other callers; held capture of 1 Aug 2026

  3. R3
    Reported

    The about 594 BTC 30 July sweep total quoted on this page

    Source TFTC's published first-collector receipt for the 500-transaction set, captured 31 Jul 2026

  4. R4
    Reported

    The statement on this page that researchers have attributed more than 1,000 BTC of wider movements to the incident, resting on Galaxy Research's 3 August confirmed total of 1,596 BTC across about 7,300 addresses

    Source Galaxy's captured 3 August thread; the underlying transaction and address lists are not published