COLDCARD vulnerability what happened, and what to do
Informational only, and this site never asks for your recovery words. details

Informational only. This is independent analysis and an evidence-backed explainer, not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite, Block, or any other party named here. Published estimates are attributed, and differing scenarios are kept separate with their assumptions. Act on your own judgement. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it. Deliberate recovery on independently verified offline equipment is a separate operation. Seed-word safety.

Plain language Updated 1 Aug 2026

Source change record

Every difference the archive holds between two states of a tracked page, classified and dated.

No code. Written to be actionable.

Newest first. A reviewed source-content difference means the relevant text served by the publisher changed between two captures. It does not verify the new claim. Dynamic page chrome, collection-method corrections, baselines and fetch errors remain preserved below without being presented as editorial revisions. Chain-monitor diff bodies remain local because they can contain victim addresses.

Some states here were not collected by this project. Where a difference involves a page state recovered from the Internet Archive, the entry carries an Internet Archive mark: on the later state when that state was inherited, and as a baseline note when the text being revised was the inherited one. As of 1 August 2026, 2 of the 74 recorded differences carry one of those marks. This keeps a recovered state from reading as a change this project caught live.

This record is part of the evidence section, which lists every tracked source and what is held for it. To follow it without revisiting the page, the same entries are published as a JSON feed at /record/changes.json, carrying the bounded revision window and provenance flags per item.

45reviewed source changes
5awaiting review
24collection differences
71baselines and errors
  1. 2 Aug 2026, 01:00 UTC Source of the community holdings tracker unreviewed +10 -4

    samsamskies-tracker-readme · SamSamskies / chain-monitor

    This detected difference has not yet been reviewed for capture noise.

  2. 2 Aug 2026, 00:59 UTC COLDCARD hack tracker unreviewed +1166 -26

    coldcard-hack-tracker · community tracker / chain-monitor

    This detected difference has not yet been reviewed for capture noise.

  3. 2 Aug 2026, 00:59 UTC COLDCARD funds flow monitor unreviewed +3 -3

    coldcard-watch · community tracker / chain-monitor

    This detected difference has not yet been reviewed for capture noise.

  4. 2 Aug 2026, 00:31 UTC COLDCARD hack tracker unreviewed +12 -36

    coldcard-hack-tracker · community tracker / chain-monitor

    This detected difference has not yet been reviewed for capture noise.

  5. 2 Aug 2026, 00:17 UTC COLDCARD hack tracker unreviewed +2 -2

    coldcard-hack-tracker · community tracker / chain-monitor

    This detected difference has not yet been reviewed for capture noise.

  6. 2 Aug 2026, 00:11 UTC COLDCARD hack tracker source content +56 -30

    coldcard-hack-tracker · community tracker / chain-monitor

    The operator rebuilt the tracker around a five-wave model: the July 31 entry split into Galaxy Wave 2 and a new Galaxy Wave 3 spanning Jul 31 to Aug 1, the headline total moved from 1,130.09411114 to 1,368.58411114 BTC, consolidated holdings from 1,130.00551671 to 1,160.19028 BTC, and the July 30 heading was renamed from Galaxy fingerprint to Galaxy Wave 1.

  7. 1 Aug 2026, 22:25 UTC Dettmer commit-history analysis of the entropy bug source content +9 -0

    btcpp-dettmer-commit-history · bitcoin++ Insider Edition / independent-analysis

    A reader comment from Frank Corva was added to the post's discussion, posted after the preceding capture rather than progressively rendered from it. Substack like and restack counters changed in the same capture. The guest post's own text was unchanged.

    +8
    +1
    +8
    +1
    +Frank Corva
    +34m
    +Great piece. Thank you, Rusty and Nifty.
    +Reply
    +Share
    
  8. 1 Aug 2026, 21:21 UTC COLDCARD hack tracker source content +2 -2

    coldcard-hack-tracker · community tracker / chain-monitor

    The evening-wave description gained a clause noting that the Kelbie vault also occurred on 31 July; the live fiat conversion changed in the same capture.

  9. 1 Aug 2026, 19:47 UTC COLDCARD hack tracker source content +14 -10

    coldcard-hack-tracker · community tracker / chain-monitor

    The tracked total rose to 1,130.09411114 BTC after a delayed 0.19 BTC victim consolidation joined the Aug 1 hop vault. The tracker also recorded an Ocean block-960511 miner payout that touched the hop address and was peeled off, listing it as a possible lead that it does not count as stolen.

  10. 1 Aug 2026, 19:47 UTC Wizardsardine post-mortem and user guidance source content +5 -5

    wizardsardine-postmortem · Wizardsardine / independent-analysis

    Wizardsardine added explicit Section 3 and Section 4 labels to two previously unlabelled headings and renumbered the two that followed from 3 and 4 to 5 and 6. In the same edit the TAPSIGNER, OPENDIME and SATSCARD paragraph changed from a flat statement that they are not affected to Coinkite's claim plus the qualification that their proprietary code prevents the authors stating with certainty that the devices are safe, while noting the architecture is not a MicroPython stack.

    -Who exactly is affected
    +Section 3: Who exactly is affected
    -TAPSIGNER, OPENDIME and SATSCARD are not affected, because they run on entirely different codebases.
    +For the TAPSIGNER, OPENDIME, and SATSCARD, Coinkite claims they are not affected, and it’s true that their architecture is completely different: they are not built on a MicroPython stack, whereas the bug specifically stems from a MicroPython compilation flag. However, since the code is proprietary, we cannot state with certainty that these devices are safe.
    -What to do now
    +Section 4: What to do now
    -Section 3: The knock-on consequences
    +Section 5: The knock-on consequences
    -Section 4: How to stop being exposed to this kind of flaw
    +Section 6: How to stop being exposed to this kind of flaw
    
  11. 1 Aug 2026, 19:16 UTC COLDCARD hack tracker source content +37 -5

    coldcard-hack-tracker · community tracker / chain-monitor

    The tracker added a 'TOTAL STOLEN' headline of 1,129.90257437 BTC with a four-wave breakdown chart, and raised the balance on watch to 1,130.00551671 BTC after a second UTXO reached the Aug 1 hop vault.

  12. 1 Aug 2026, 18:45 UTC COLDCARD hack tracker source content +27 -11

    coldcard-hack-tracker · community tracker / chain-monitor

    The tracked total rose from 1,129.31416148 to 1,129.81397994 BTC, a separate 'Aug 1 hop vault' holding was added to the evening-wave cluster, the risk checklist gained Mk3 5.0.1 to 5.0.3, a seed-origin item and revised passphrase wording, and WizardSardine and Kevin Loaec were added as sources.

  13. 1 Aug 2026, 18:44 UTC Mk3 security advisory source content +30 -29

    coinkite-mk3-advisory · Coinkite / vendor-advisory

    Fourth recorded revision of the advisory, and the one that resolves the Mk2 question this archive had tracked as open. The update stamp moved to August 1, 2026 at 2:35 p.m. EDT and every Mk3-only statement about the defect and its fix now names both models: the fixed-firmware list reads 'Mk2/Mk3: version 4.2.0 or later', the affected range reads 'The issue is present on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 inclusive', the at-risk sentence covers 'a seed generated on Mk2 or Mk3 version 4.0.1 (March 2021) through 4.1.9', and the release is described as 'Fixed Mk2/Mk3 firmware version 4.2.0' from the 'official Mk2/Mk3 download page'. The one-device migration section, the optional dice-only section and the closing migration steps were rewritten from Mk3-only to Mk2-or-Mk3 wording. Until this revision the vendor downloads-page listing was the only vendor evidence placing the Mk2 in the affected range or the hotfix. The published lower bound is unchanged at 4.0.1 for both models, so the v4.0.0 divergence recorded on the firmware page is untouched.

    -Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated
    +Updated August 1, 2026 at 2:35 p.m. EDT: Funds controlled by seeds generated
    -Mk3: version 4.2.0 or later
    +Mk2/Mk3: version 4.2.0 or later
    -Funds controlled by a seed generated on Mk3 version 4.0.1 (March 2021)
    -through 4.1.9 inclusive are at risk if the seed was created without at least 50
    -fair, independent, private dice rolls and the funded wallet is not protected by
    -a strong, unique BIP-39 passphrase.
    +Funds controlled by a seed generated on Mk2 or Mk3 version 4.0.1 (March
    +2021) through 4.1.9 inclusive are at risk if the seed was created without at
    +least 50 fair, independent, private dice rolls and the funded wallet is not
    +protected by a strong, unique BIP-39 passphrase.
    -The issue is present on Mk3 firmware versions 4.0.1 through 4.1.9
    +The issue is present on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9
    
  14. 1 Aug 2026, 18:44 UTC Entropy technical backgrounder source content +11 -10

    coinkite-backgrounder · Coinkite / vendor-advisory

    Coinkite moved the backgrounder's update stamp to August 1, 2026 at 2:35 p.m. EDT and replaced Mk3 with Mk2 or Mk3 throughout: the affected firmware range became 'The affected Mk2 and Mk3 firmware range is 4.0.1 through 4.1.9', the seeded-PRNG analysis became 'On Mk2 and Mk3, the active PRNG was seeded primarily from device and timing state', the hotfix list became 'Version 4.2.0 for Mk2 and Mk3', and the migration steps and the pointer to the dedicated advisory were rewritten the same way.

    -Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated
    +Updated August 1, 2026 at 2:35 p.m. EDT: Funds controlled by seeds generated
    -If your seed was generated on a Mk3 running firmware 4.0.1 through 4.1.9
    +If your seed was generated on a Mk2 or Mk3 running firmware 4.0.1 through 4.1.9
    -Update the Mk3 to firmware version 4.2.0 or
    +Update the Mk2 or Mk3 to firmware version 4.2.0 or
    -Generate a completely new seed on the updated Mk3.
    +Generate a completely new seed on the updated COLDCARD.
    -Follow the dedicated Mk3 Security Advisory and migration
    +Follow the dedicated Mk2/Mk3 Security Advisory and migration
    -On Mk3, the active PRNG was seeded primarily from device and timing
    +On Mk2 and Mk3, the active PRNG was seeded primarily from device and timing
    -The affected Mk3 firmware range is 4.0.1 through 4.1.9. Version 4.2.0 corrects
    -new seed generation. The eight-year figure therefore describes the age of the
    
  15. 1 Aug 2026, 17:43 UTC COLDCARD hack tracker source content +6 -17

    coldcard-hack-tracker · community tracker / chain-monitor

    The tracker restated its movement feed in terms of the reported consolidation only: the earlier outbound spend and unconfirmed hop were removed from the feed, last movement returned to 'Unmoved', and a note was added that later surplus passing through a vault is ignored while the reported balance remains.

  16. 1 Aug 2026, 17:43 UTC COLDCARD funds flow monitor source content +3 -3

    coldcard-watch · community tracker / chain-monitor

    The tracker's headline moved from 1,128.6633 BTC across 2,334 verified addresses to 1,158.8480 BTC across 2,686, and its address-check copy changed with it. The cluster description of three windows on 30 and 31 July was unchanged.

  17. 1 Aug 2026, 17:41 UTC COLDCARD firmware PR #691: pass the full secure-element digest source content +17 -9

    coldcard-firmware-pr-691 · Coinkite / repo-pr

    The author marked the pull request as a draft at 16:13 and rewrote its description. The submodule bump note became a re-pin to the companion RNG fix, and the stated dependency moved from switck/libngu#60 to #61, described as replacing the generator with a SHA-256 Hash-DRBG and making reseed() require a seed of at least 32 bytes, so this firmware change becomes a prerequisite for #61 booting on-device. GitHub edited-comment and loading-error chrome appeared in the same capture.

    -Open
    +Draft
    -Open
    +Draft
    +•
    +edited
    +Loading
    +Uh oh!
    +There was an error while loading. Please reload this page.
    -Bump external/libngu to the companion fix that makes reseed() absorb a
    -full-width seed into all generator state words.
    +Re-pin external/libngu to the companion RNG fix.
    -Requires switck/libngu#60 (the reseed() rework). Until that merges, the bumped
    -submodule commit exists only on the libngu fork, so firmware CI cannot fetch it
    
  18. 1 Aug 2026, 17:41 UTC libngu PR #60: full-width reseeding source content +1 -1

    libngu-pr-60 · switck / repo-pr

    The inline cross-reference to Coldcard/firmware#691 changed from Open to Draft, reflecting a real state change on that pull request rather than rendering variance. Nothing else moved: no discussion, review or patch text on this pull request changed. The underlying state change is captured directly on coldcard-firmware-pr-691 at 20260801T174121Z, so this entry is the same event seen from the linked repository.

    -Open
    +Draft
    
  19. 1 Aug 2026, 17:12 UTC COLDCARD hack tracker source content +8 -0

    coldcard-hack-tracker · community tracker / chain-monitor

    The tracker added an unconfirmed hop-1 movement of 0.4998206 BTC onward from the followed destination of the evening vault's first outbound spend.

  20. 1 Aug 2026, 17:12 UTC Chain-derived COLDCARD RNG postmortem source content +43 -3

    kelbie-rng-postmortem · Kelbie / independent-analysis

    The README added derivation sections on grouping waves into families by build traits rather than configuration dials, on fee pricing and its lack of correlation with value, on wave colour, and on re-applying Block's published seven-property fingerprint across the whole record, plus a new fingerprint script in the file map.

    -  those gives the same answer. The headline figures and the block cascade read the first episode;
    -  everything else carries all of it.
    +  those gives the same answer. The headline figures read the first episode; everything else carries
    +  all of it.
    +- **Which waves were built by the same program** — `fingerprints[]` splits what a transaction
    +  reveals into two kinds of evidence and groups the waves on the first kind only. A **build** trait
    +  is something the program does regardless of who runs it: the order it writes inputs in, where it
    +  gets a size estimate from, what it puts in nLockTime, whether it grinds its signatures. A
    +  **config** trait is a dial — fee rate, replace-by-fee, whether coins are pooled into a collector
    +  or scattered one address per sweep. Waves form a **family** when no build trait *either could
    +  show* disagrees, and split into **variants** inside it by their dials. Traits a wave cannot
    +  exhibit — input ordering, when every sweep spends one input — come back null and are skipped, so
    +  a small wave joins on the evidence it has rather than being split off for evidence it could never
    +  have produced. Where that leaves it fitting more than one family, `alsoFits` says so and the page
    
  21. 1 Aug 2026, 16:41 UTC COLDCARD hack tracker source content +12 -11

    coldcard-hack-tracker · community tracker / chain-monitor

    The tracker withdrew the Mk4 attribution for the 1 August morning wave, recording the seed as Mk3-origin, removed the 'Mk4 is in scope now' panel, and recorded the first outbound spend of 0.4099166 BTC from the evening vault at 16:33 UTC.

  22. 1 Aug 2026, 16:09 UTC Passport is not affected source content +4 -0

    passport-not-affected · Foundation / vendor-statement

    Foundation added a reply to the thread saying manual firmware updates outside Envoy are scheduled for the next but one release, with no definitive timeframe committed.

    +qna
    +August 1, 2026, 10:24am
    +5
    +This is currently scheduled for the next but one release, but our roadmap is always subject to change and as of right now, I do not have definitive time frame for this.
    
  23. 1 Aug 2026, 16:08 UTC Coinkite terms of sale source content +1 -1

    coinkite-terms · Coinkite / vendor-legal

    The site-wide advisory banner on the terms page hardened from 'Seeds generated on firmware 4.0.1 or later may be at risk' to 'Seeds generated on firmware 4.0.1 (2021 or later) are at risk', matching the downloads page.

    -Seeds generated on firmware 4.0.1 or later may be at risk.
    +Seeds generated on firmware 4.0.1 (2021 or later) are at risk.
    
  24. 1 Aug 2026, 16:08 UTC COLDCARD firmware PR #691: pass the full secure-element digest source content +12 -0

    coldcard-firmware-pr-691 · Coinkite / repo-pr

    The pull request gained a further comment repeating the request to raise the libngu changes as a separate pull request against the libngu repository, linking switck/libngu#60; reaction totals were normalized in the same capture.

    +<github-reactions>
    +ballance
    +commented
    +Aug 1, 2026
    +Copy link
    +Copy Markdown
    +Author
    +Can you please open libngu changes as separate PR against libngu repo? thanks
    +switck/libngu#60
    +Sorry, something went wrong.
    +Uh oh!
    +There was an error while loading. Please reload this page.
    
  25. 1 Aug 2026, 16:08 UTC libngu PR #60 patch source content +61 -1

    libngu-pr-60-patch · switck / repo-patch

    The published patch series gained a second commit adding a ValueError on an empty seed, a regression test and a comment documenting the generator's roughly 72-bit independent state.

    -Subject: [PATCH] fix: absorb full-width entropy in random.reseed()
    +Subject: [PATCH 1/2] fix: absorb full-width entropy in random.reseed()
    +From 6766258eae9a11e40fc77402af2dd9462938b2e6 Mon Sep 17 00:00:00 2001
    +From: Ballance <[email protected]>
    +Date: Sat, 1 Aug 2026 10:21:54 -0400
    +Subject: [PATCH 2/2] review: reject empty seed and document 72-bit state
    + ceiling
    +Address review feedback on switck/libngu#60:
    +- reseed() now raises ValueError on a zero-length seed instead of
    +  silently performing a no-op reseed; test_random.py covers it.
    +- Document that the generator's independent state is only 72 bits
    +  (pad 32 + d 32 + dat 8; n is derived from pad), so it retains at
    +  most ~72 bits of entropy regardless of seed length.
    +    An empty hand gives
    
  26. 1 Aug 2026, 16:08 UTC libngu PR #60: full-width reseeding source content +78 -7

    libngu-pr-60 · switck / repo-pr

    Two contributors reviewed the reseed change, the author pushed a second commit rejecting a zero-length seed and documenting a roughly 72-bit state ceiling, a reviewer argued for removing Yasmarang entirely and announced a competing pull request, and the author closed this one in favour of #61.

    -Open
    -ballance wants to merge 1 commit into
    +Closed
    +ballance wants to merge 2 commits into
    -ConversationCommits1 (1)ChecksFiles changed
    -Open
    +ConversationCommits2 (2)ChecksFiles changed
    +Closed
    -ballance wants to merge 1 commit into
    +ballance wants to merge 2 commits into
    -All reactions
    +<github-reactions>
    +doc-hex
    +commented
    
  27. 1 Aug 2026, 16:08 UTC libngu PR #59 source content +20 -2

    libngu-pr-59 · switck / repo-pr

    The pull request was closed by its author in favour of a three-pull-request stack (#62, #63 and #64) described as summing to a byte-identical tree, with a suggested review order and an offer to reopen.

    -Open
    +Closed
    -Open
    +Closed
    +jgmontoya
    +commented
    +Aug 1, 2026
    +Copy link
    +Copy Markdown
    +Author
    +Per your feedback that the diff was too big, I've split this into a stack of three PRs that sum to exactly this branch (byte-identical tree):
    +add HMAC_DRBG (SP 800-90A 10.1.2, SHA-256), verified against NIST CAVP vectors #62 — the HMAC_DRBG core + NIST CAVP test harness (pure addition, self-verifying, no behavior change to any build)
    +add entropy health rule as a pure, deterministically tested module #63 — the entropy health rule + its deterministic tests (pure addition)
    +random: fail-closed entropy backends; all output via HMAC_DRBG #64 — the random.c rework that composes them, with compile-gate regression tests and README (the part that fixes the advisory)
    
  28. 1 Aug 2026, 16:07 UTC COLDCARD hack tracker source content +3 -3

    coldcard-hack-tracker · community tracker / chain-monitor

    The tracker's watched balance rose from 1,129.31416148 BTC to 1,129.6240794 BTC and the evening vault's displayed balance and UTXO count changed, while the reported consolidated figure for that vault stayed at 0.50980268 BTC.

  29. 1 Aug 2026, 16:07 UTC Chain-derived COLDCARD RNG postmortem source content +4 -4

    kelbie-rng-postmortem · Kelbie / independent-analysis

    The README renamed waves from ordinal numbers to block heights throughout, so 'wave 3' became 'wave 960188' and Block's 'waves 1 and 2' became 'waves 960183 and 960185'.

    -The first report in the file yields wave 3's collector, wave 3's vault, and 500 victims.
    +The first report in the file yields wave 960188's collector, its vault, and 500 victims.
    -Block published waves 1 and 2 as a fingerprint match and said in the same thread that they "have not
    +Block published waves 960183 and 960185 as a fingerprint match and said in the same thread that they "have not
    -- **Labels** — "Wave 1 collector A" is generated from the wave and role, with a letter only where
    +- **Labels** — "Wave 960183 collector A" is generated from the wave and role, with a letter only where
    -The last one is decided by **time, not amount**. Wave 1 swept outputs worth 1,200 satoshis — smaller
    +The last one is decided by **time, not amount**. Wave 960183 swept outputs worth 1,200 satoshis — smaller
    
  30. 1 Aug 2026, 15:36 UTC COLDCARD hack tracker source content +25 -8

    coldcard-hack-tracker · community tracker / chain-monitor

    The tracker added an 'Aug 1 morning wave' cluster with a new vault address holding 0.33203236 BTC from 16 sweeps, described it as including a reported Mk4 RNG and duress-wallet honeypot attributed to Tomer Strolight while noting the device model is not visible on chain, added an 'Mk4 is in scope now' panel, and changed its headline to a running total.

  31. 1 Aug 2026, 15:05 UTC COLDCARD hack tracker source content +11 -3

    coldcard-hack-tracker · community tracker / chain-monitor

    The tracker replaced its likely-exposed paragraph with a per-model vulnerable and fixed version table covering Mk3, Mk4, Mk5, Q and both Edge tracks, and moved the evening vault's block reference from the row label into the cluster description.

  32. 1 Aug 2026, 14:34 UTC COLDCARD hack tracker source content +33 -15

    coldcard-hack-tracker · community tracker / chain-monitor

    The tracker rewrote its reader-guidance section against the August 1 advisory and Block's writeup, added a 'beyond the main seed' item covering paper-wallet keys, Seed XOR masks and Key Teleport, clone and Secure Notes material, moved the Galaxy scope figures into the cluster card, and replaced its short source labels with descriptive per-source summaries including CoinDesk and Clay Garrett. Holding 2's UTXO count also changed from one to two.

  33. 1 Aug 2026, 14:03 UTC COLDCARD hack tracker source content +29 -15

    coldcard-hack-tracker · community tracker / chain-monitor

    The tracker added a third cluster, an 'Evening wave' of 31 July with its own 0.50980268 BTC vault attributed to Evan Schoenberg, restated every holding at full satoshi precision, and changed its headline from 1,128.56 BTC across two clusters to 1,129.06986038 BTC across three.

  34. 1 Aug 2026, 14:03 UTC COLDCARD funds flow monitor source content +4 -3

    coldcard-watch · community tracker / chain-monitor

    The tracker moved from two episodes to three clusters by adding 13 addresses in block 960455, changed the destination set from four addresses to six, revised the same-block count for the last drained address from 250 to 237, and added an explanatory note about the two-scale timeline.

  35. 1 Aug 2026, 14:02 UTC COLDCARD firmware downloads source content +1 -1

    coldcard-downloads · Coinkite / vendor-releases

    The site-wide advisory banner hardened from 'Seeds generated on firmware 4.0.1 or later may be at risk' to 'Seeds generated on firmware 4.0.1 (2021 or later) are at risk'.

    -Seeds generated on firmware 4.0.1 or later may be at risk.
    +Seeds generated on firmware 4.0.1 (2021 or later) are at risk.
    
  36. 1 Aug 2026, 14:02 UTC Coinkite blog index source content +1 -1

    coinkite-blog-index · Coinkite / vendor-index

    The blog index excerpt for the advisory changed with the advisory itself, from 'Coinkite is warning users who generated a seed using a COLDCARD on firmware versions 4.0.1 throug...' to 'Funds from affected COLDCARD seeds are at risk if the seed lacks 50 independent, private dice rol...'.

    -Coinkite is warning users who generated a seed using a COLDCARD on firmware versions 4.0.1 throug...
    +Funds from affected COLDCARD seeds are at risk if the seed lacks 50 independent, private dice rol...
    
  37. 1 Aug 2026, 14:02 UTC Mk3 security advisory source content +19 -10

    coinkite-mk3-advisory · Coinkite / vendor-advisory

    Third recorded revision of the advisory. It now carries 'Updated August 1, 2026 at 9:35 a.m. EDT' and replaces the blanket warning that Mk3 4.0.1 to 4.1.9 users' funds 'may be at risk' with a conditional statement that funds are at risk unless the seed was created with at least 50 fair, independent, private dice rolls and the wallet is protected by a strong, unique BIP-39 passphrase. The passphrase section changed in both directions: it now states that reduced seed entropy alone is not enough to reach a passphrase wallet, and separately that a strong passphrase does not repair the seed, that passphrase users should also migrate, and that an uncertain passphrase means treating funds as at risk and migrating immediately.

    -Updated July 31, 2026 at 12:39 p.m. EDT: Fixed firmware is now available
    -for every affected model and release track:
    +Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated
    +on affected firmware are at risk if the seed was created without at least 50
    +independent, private dice rolls and the funded wallet is not protected by a
    +strong, unique BIP-39 passphrase.
    +Fixed firmware is now available for every affected model and release track:
    -Coinkite is warning all users who
    -generated a seed using a Mk3 on version 4.0.1 (March 2021) thru 4.1.9 (inclusive)
    -that their funds may be at risk.
    +Funds controlled by a seed generated on Mk3 version 4.0.1 (March 2021)
    +through 4.1.9 inclusive are at risk if the seed was created without at least 50
    +fair, independent, private dice rolls and the funded wallet is not protected by
    +a strong, unique BIP-39 passphrase.
    
  38. 1 Aug 2026, 14:02 UTC Entropy technical backgrounder source content +15 -3

    coinkite-backgrounder · Coinkite / vendor-advisory

    Coinkite replaced the backgrounder's fixed-firmware banner with an August 1 update stating that funds are at risk unless the seed was created with at least 50 independent private dice rolls and the wallet is protected by a strong, unique BIP-39 passphrase, added a paragraph qualifying what counts as such a passphrase, and added a sentence calling the reduced search space a direct security risk rather than a theoretical possibility for wallets meeting neither condition.

    -Updated July 31, 2026 at 12:39 p.m. EDT: Fixed firmware is now available
    -for every affected model and release track, including Edge firmware versions
    -6.6.0X for Mk4/Mk5 and 6.6.0QX for Q.
    +Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated
    +on affected firmware are at risk if the seed was created without at least 50
    +independent, private dice rolls and the funded wallet is not protected by a
    +strong, unique BIP-39 passphrase.
    +Fixed firmware is now available for every affected model and release track,
    +including Edge firmware versions 6.6.0X for Mk4/Mk5 and 6.6.0QX for Q.
    +The passphrase must be strong, unique, secret, and separate from the seed
    +backup. A short, common, patterned, quoted, reused, exposed, or uncertain
    +passphrase does not qualify; treat those funds as at risk. Even when a strong
    +passphrase reduces the immediate exposure, it does not repair an affected seed.
    +Unless the independent dice-entropy exception applies, replace the seed and
    
  39. 1 Aug 2026, 13:01 UTC COLDCARD hack tracker source content +1 -1

    coldcard-hack-tracker · community tracker / chain-monitor

    The monitor changed Holding 1's displayed UTXO count from ten to eleven while its BTC balance and held status remained unchanged.

  40. 1 Aug 2026, 13:01 UTC COLDCARD funds flow monitor source content +11 -6

    coldcard-watch · community tracker / chain-monitor

    The tracker added dashboard, address-list and methodology navigation, described its figures as verified minimums and a floor rather than totals, and changed its checkable address set from 2,321 to 2,334.

  41. 1 Aug 2026, 10:26 UTC COLDCARD hack tracker source content +1 -1

    coldcard-hack-tracker · community tracker / chain-monitor

    The monitor changed Holding 1's displayed UTXO count from nine to ten while its BTC balance and held status remained unchanged.

  42. 1 Aug 2026, 09:53 UTC COLDCARD hack tracker source content +1 -1

    coldcard-hack-tracker · community tracker / chain-monitor

    The monitor changed Holding 1's displayed UTXO count from eight to nine while its BTC balance and held status remained unchanged.

  43. 1 Aug 2026, 09:21 UTC Wallet drained timeline source content +10 -8

    reddit-drained-timeline · r/Bitcoin / victim-account

    The rendered thread added a comment linking to Gregory Sanders' reported reproduction; one comment present in the preceding capture was no longer rendered.

    +ViperG
    +•
    +<relative-time>
    +
    +Someone was able to replicate the rng exploit on mk2/mk3:
    +
    +https://x.com/i/status/2082958675975553224
    +
    +<engagement-count>
    +<more-replies>
    -artilekt
    -•
    -<relative-time>
    -
    
  44. 1 Aug 2026, 08:13 UTC COLDCARD hack tracker source content +1 -1

    coldcard-hack-tracker · community tracker / chain-monitor

    The monitor changed Holding 1's displayed UTXO count from seven to eight while its BTC balance and held status remained unchanged.

  45. 1 Aug 2026, 07:34 UTC COLDCARD firmware PR #691: pass the full secure-element digest source content +31 -2

    coldcard-firmware-pr-691 · Coinkite / repo-pr

    A COLDCARD firmware collaborator asked the author to move the libngu changes into a separate pull request; GitHub review metadata and navigation chrome also changed.

    +scgbckbone
    +reviewed
    +Aug 1, 2026
    +View reviewed changes
    +scgbckbone
    +left a comment
    +Copy link
    +Copy Markdown
    +Collaborator
    +There was a problem hiding this comment.
    +Choose a reason for hiding this comment
    +The reason will be displayed to describe this comment to others. Learn more.
    +Choose a reason
    +Spam
    
  46. 1 Aug 2026, 05:28 UTC COLDCARD funds flow monitor source content +9 -9

    coldcard-watch · community tracker / chain-monitor

    The tracker expanded from the first 1,195-address episode to two episodes totalling 2,321 addresses and changed its headline from 1,082.5696 BTC to 1,128.4717 BTC.

  47. 1 Aug 2026, 03:51 UTC COLDCARD hack tracker source content +64 -43

    coldcard-hack-tracker · community tracker / chain-monitor

    The tracker added a separately attributed 45.91 BTC post-scan cluster and changed its headline total; live fiat figures also changed in the same capture.

  48. 1 Aug 2026, 03:50 UTC libngu PR #59 source content +14 -2

    libngu-pr-59 · switck / repo-pr

    The pull-request author added a comment offering to split the proposal into three smaller changes; GitHub navigation counters also changed.

    -10
    +11
    -5
    +6
    +jgmontoya
    +commented
    +Aug 1, 2026
    +Copy link
    +Copy Markdown
    +Author
    +diff too big
    +I'd be happy to split into a 3-PR stack: two independent, self-verifying additions (DRBG+CAVP, health rule) and then the random.c rework as a much smaller final diff.
    +All reactions
    +Sorry, something went wrong.
    
  49. 1 Aug 2026, 00:17 UTC Mk3 security advisory source content +66 -53

    coinkite-mk3-advisory · Coinkite / vendor-advisory

    compared against an Internet Archive baseline

    Coinkite announced fixed firmware for every affected model and release track, including Mk3 4.2.0, and rewrote the one-device migration guidance.

    -Mk3 Security Advisory
    +Coldcard Security Advisory
    -Out of an abundance of caution, Coinkite is warning all users who
    -generated a seed using a Mk3 on version 4.0.1 (March 2021) or any
    -subsequent version that their funds may be at risk.
    +Updated July 31, 2026 at 12:39 p.m. EDT: Fixed firmware is now available
    +for every affected model and release track:
    +Mk3: version 4.2.0 or later
    +Mk4/Mk5 standard: version 5.6.0 or later
    +Q standard: version 1.5.0Q or later
    +Mk4/Mk5 Edge: version 6.6.0X or later
    +Q Edge: version 6.6.0QX or later
    +Standard and Edge are separate release tracks. If you use Edge, install the
    +fixed Edge release for your model. Do not assume an older Edge 6.x release is
    
  50. 31 Jul 2026, 07:30 UTC Mk3 security advisory source content Internet Archive +56 -19

    coinkite-mk3-advisory · Coinkite / vendor-advisory

    compared against an Internet Archive baseline

    Coinkite expanded the affected scope to Mk4, Mk5 and Q, added dice guidance, and revised the passphrase and migration sections.

    -Mk4, Q and Mk5 are not affected based on our early analysis of the issue.
    -The issue is present through firmware version 5.0.3,
    -the final release that supported Mk3.
    -Investigation Ongoing
    +Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also
    +affected, with about 72 bits of entropy rather than the expected 128 bits.
    +TAPSIGNER, OPENDIME and SATSCARD are not affected by this bug as they are different codebases
    +The issue is present on every Mk3 firmware version since
    +4.0.1. It also affects seeds generated on
    +Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on
    +Mk4, Mk5 and Q is not as severe but is still serious.
    +If You Added Dice When Creating the Seed
    +This issue affects the device-generated entropy. It does not remove independent
    +entropy that you supplied with dice.
    
Preserved collection differences 24

These diffs remain part of the record, but review found that they came from dynamic page chrome or a collection-method correction rather than a relevant edit by the publisher.

  1. 2 Aug 2026, 00:09 UTC COLDCARD wallet drain report capture noise +1 -1

    coin360-drain · Coin360 / reporting

    A relative-age label the enabled normalizer did not match in its literal form; the article body is unchanged.

  2. 1 Aug 2026, 22:26 UTC Galaxy loss estimate reporting capture noise +4 -4

    theblock-galaxy-total · The Block / reporting

    Only the site chrome's rotating latest-news list changed; the incident article text, including its Galaxy total, was unchanged.

  3. 1 Aug 2026, 21:52 UTC COLDCARD hack tracker capture noise +1 -1

    coldcard-hack-tracker · community tracker / chain-monitor

    Only the live fiat conversion changed; the BTC totals, cluster descriptions and movement state were unchanged.

  4. 1 Aug 2026, 20:50 UTC COLDCARD hack tracker capture noise +1 -1

    coldcard-hack-tracker · community tracker / chain-monitor

    Only the live fiat conversion changed; the BTC totals, cluster descriptions and movement state were unchanged.

  5. 1 Aug 2026, 20:18 UTC COLDCARD hack tracker capture noise +1 -1

    coldcard-hack-tracker · community tracker / chain-monitor

    Only the live fiat conversion changed; the BTC totals, cluster descriptions and movement state were unchanged.

  6. 1 Aug 2026, 18:13 UTC Wallet drained timeline capture noise +10 -10

    reddit-drained-timeline · r/Bitcoin / victim-account

    Two already-held comments swapped position in the rendered thread. No post or comment text was added, removed or altered, and the enabled normalizer already suppresses relative-time labels and engagement counts, so comment ordering is the only remaining difference. Reddit orders comments dynamically, so this is rendering variance rather than an edit by the author or moderators.

  7. 1 Aug 2026, 16:10 UTC COLDCARD wallet drain report capture noise +1 -1

    coin360-drain · Coin360 / reporting

    Only the article's relative-time label changed, this time to the word 'yesterday', which the existing relative-time normalizer does not match. The article body was unchanged.

  8. 1 Aug 2026, 16:10 UTC Galaxy loss estimate reporting capture noise +2 -2

    theblock-galaxy-total · The Block / reporting

    Only the site chrome's rotating latest-news list changed; the incident article text was unchanged.

  9. 1 Aug 2026, 09:58 UTC Wallet drained timeline capture noise +0 -83

    reddit-drained-timeline · r/Bitcoin / victim-account

    Fewer lazy-loaded comments were present in this capture than the previous one, and the 'Read more' control was absent. The thread body is unchanged; the missing replies include two that link to the Coinkite advisory. Reddit renders comments progressively, so this is capture variance rather than deletion by the author or moderators.

  10. 1 Aug 2026, 09:52 UTC Wallet drained timeline capture noise +83 -0

    reddit-drained-timeline · r/Bitcoin / victim-account

    More lazy-loaded comments were rendered in this capture than in the previous one, and the 'Read more' control was present again. This is the inverse of the 09:58:01Z capture and the same progressive-rendering variance; no post or comment text already held was altered.

  11. 1 Aug 2026, 08:35 UTC COLDCARD hack tracker capture correction +61 -14

    coldcard-hack-tracker · community tracker / chain-monitor

    The rendered capture again held the monitor's hydrated chain data after the preceding temporary loading-state capture.

  12. 1 Aug 2026, 08:18 UTC COLDCARD hack tracker capture noise +14 -61

    coldcard-hack-tracker · community tracker / chain-monitor

    The rendered capture held the monitor's temporary loading state instead of its hydrated chain data.

  13. 1 Aug 2026, 08:12 UTC Galaxy loss estimate reporting capture noise +1 -6

    theblock-galaxy-total · The Block / reporting

    The live market-ticker region was temporarily unavailable; the incident article text was unchanged.

  14. 1 Aug 2026, 08:11 UTC libngu PR #58 capture noise +3 -3

    libngu-pr-58 · switck / repo-pr

    Only the thumbs-up reaction total and reacting-account list changed; the pull-request discussion and patch text were unchanged.

  15. 1 Aug 2026, 07:01 UTC COLDCARD entropy FAQ capture noise +1 -1

    coldcard-docs-faq · Coinkite / vendor-docs

    Only the FAQ footer's Last update date changed from July 31 to August 1; no extracted FAQ answer changed.

  16. 1 Aug 2026, 03:51 UTC COLDCARD wallet drain report capture noise +1 -1

    coin360-drain · Coin360 / reporting

    Only the article's relative-time label changed from 15 hours to 16 hours.

  17. 1 Aug 2026, 03:50 UTC libngu PR #58 capture noise +2 -2

    libngu-pr-58 · switck / repo-pr

    Only GitHub repository navigation counters changed.

  18. 1 Aug 2026, 03:22 UTC COLDCARD hack tracker capture noise +6 -6

    coldcard-hack-tracker · community tracker / chain-monitor

    Only live fiat conversions changed; the BTC balances and movement state were unchanged.

  19. 1 Aug 2026, 03:22 UTC Galaxy loss estimate reporting capture noise +4 -4

    theblock-galaxy-total · The Block / reporting

    Only live cryptocurrency ticker values in the site navigation changed.

  20. 1 Aug 2026, 03:08 UTC Galaxy loss estimate reporting capture noise +5 -5

    theblock-galaxy-total · The Block / reporting

    Only live cryptocurrency ticker values in the site navigation changed.

  21. 1 Aug 2026, 03:08 UTC Who must move their coins capture noise +10 -10

    tftc-who-must-move · TFTC / analysis

    Only rotating related-content cards below the article changed.

  22. 1 Aug 2026, 03:05 UTC COLDCARD hack tracker capture noise +6 -6

    coldcard-hack-tracker · community tracker / chain-monitor

    Only live fiat conversions changed; the BTC balances and movement state were unchanged.

  23. 1 Aug 2026, 02:59 UTC COLDCARD hack tracker capture correction +105 -0

    coldcard-hack-tracker · community tracker / chain-monitor

    The browser capture obtained the rendered tracker after the initial scripted capture held an empty client-side shell.

  24. 1 Aug 2026, 02:59 UTC Wallet drained timeline capture correction +27 -27

    reddit-drained-timeline · r/Bitcoin / victim-account

    A newly enabled comparison normalizer replaced relative-time labels and engagement counts; the post and comment text did not change.

Collection baselines and fetch errors 71

Baselines establish the first copy held. Fetch errors describe this project's collection attempt, not a change at the source.

  1. 2 Aug 2026, 00:40 UTC Coinkite's pre-incident paper-spam warning baseline
  2. 2 Aug 2026, 00:26 UTC Collision demonstration and firmware guard scanner baseline
  3. 2 Aug 2026, 00:26 UTC End-to-end reproduction of the affected generator baseline
  4. 2 Aug 2026, 00:26 UTC Source of the community holdings tracker baseline
  5. 2 Aug 2026, 00:13 UTC COLDCARD hack tracker blocked
  6. 2 Aug 2026, 00:09 UTC COLDCARD hack tracker blocked
  7. 2 Aug 2026, 00:08 UTC COLDCARD hack tracker blocked
  8. 1 Aug 2026, 23:59 UTC COLDCARD hack tracker blocked
  9. 1 Aug 2026, 23:28 UTC COLDCARD hack tracker blocked
  10. 1 Aug 2026, 22:57 UTC COLDCARD hack tracker blocked
  11. 1 Aug 2026, 22:23 UTC COLDCARD hack tracker blocked
  12. 1 Aug 2026, 17:17 UTC Dettmer commit-history analysis of the entropy bug baseline
  13. 1 Aug 2026, 17:17 UTC Wizardsardine post-mortem and user guidance baseline
  14. 1 Aug 2026, 09:15 UTC CVE-2023-31290 vulnerability record baseline
  15. 1 Aug 2026, 09:15 UTC Disclosure of vulnerable Bitcoin wallet library baseline
  16. 1 Aug 2026, 09:15 UTC Milk Sad vulnerability disclosure baseline
  17. 1 Aug 2026, 09:15 UTC Some SecureRandom thoughts baseline
  18. 1 Aug 2026, 09:15 UTC Debian Security Advisory DSA-1571-1 baseline
  19. 1 Aug 2026, 09:15 UTC Consumer Protection Act, 2023 baseline
  20. 1 Aug 2026, 09:15 UTC MARA Slipstream API documentation baseline
  21. 1 Aug 2026, 09:15 UTC Consumer Protection Act, 2002 baseline
  22. 1 Aug 2026, 09:15 UTC MARA Slipstream transaction-submission portal baseline
  23. 1 Aug 2026, 06:39 UTC COLDCARD mainline RNG hotfix commit ca724637 baseline
  24. 1 Aug 2026, 06:39 UTC Mk3 bounded proof README at e17d833b baseline
  25. 1 Aug 2026, 06:39 UTC COLDCARD firmware PR #690 patch baseline
  26. 1 Aug 2026, 06:39 UTC COLDCARD firmware PR #689 patch baseline
  27. 1 Aug 2026, 06:39 UTC COLDCARD firmware PR #691 patch baseline
  28. 1 Aug 2026, 06:39 UTC libngu PR #60 patch baseline
  29. 1 Aug 2026, 06:39 UTC libngu PR #59 patch baseline
  30. 1 Aug 2026, 06:39 UTC libngu PR #58 patch baseline
  31. 1 Aug 2026, 06:25 UTC SeedSigner PR #962: withdrawn camera-entropy hardening proposal baseline
  32. 1 Aug 2026, 06:25 UTC SatSigner PR #468: entropy audit and hardening baseline
  33. 1 Aug 2026, 06:25 UTC Bitcoin.org PR #4905: remove COLDCARD listings baseline
  34. 1 Aug 2026, 06:23 UTC COLDCARD firmware PR #690: Edge RNG hotfix baseline
  35. 1 Aug 2026, 06:23 UTC COLDCARD firmware PR #689: Mk3 RNG hotfix baseline
  36. 1 Aug 2026, 06:21 UTC COLDCARD firmware PR #691: pass the full secure-element digest baseline
  37. 1 Aug 2026, 06:21 UTC libngu PR #60: full-width reseeding baseline
  38. 1 Aug 2026, 05:59 UTC Mk3 binary reversal and bounded proof of concept baseline
  39. 1 Aug 2026, 05:59 UTC Chain-derived COLDCARD RNG postmortem baseline
  40. 1 Aug 2026, 05:59 UTC Reproducible firmware and chain investigation baseline
  41. 1 Aug 2026, 03:51 UTC COLDCARD entropy FAQ baseline
  42. 1 Aug 2026, 03:50 UTC Galaxy loss estimate reporting fetch error Source check returned HTTP 403.
  43. 1 Aug 2026, 03:25 UTC Coinkite terms of sale baseline
  44. 1 Aug 2026, 03:25 UTC libngu PR #59 baseline
  45. 1 Aug 2026, 03:25 UTC libngu PR #58 baseline
  46. 1 Aug 2026, 02:53 UTC COLDCARD wallet drain report baseline
  47. 1 Aug 2026, 02:53 UTC COLDCARD Mk3 entropy reference baseline
  48. 1 Aug 2026, 02:53 UTC Bitcoin Optech Newsletter #416 baseline
  49. 1 Aug 2026, 02:45 UTC Wallet drained timeline baseline
  50. 1 Aug 2026, 02:34 UTC COLDCARD hack tracker baseline
  51. 1 Aug 2026, 02:34 UTC COLDCARD funds flow monitor baseline
  52. 1 Aug 2026, 01:22 UTC Wallet drained timeline blocked
  53. 1 Aug 2026, 00:46 UTC Galaxy loss estimate reporting baseline
  54. 1 Aug 2026, 00:46 UTC Who must move their coins baseline
  55. 1 Aug 2026, 00:46 UTC Coinkite releases fixed firmware baseline
  56. 1 Aug 2026, 00:46 UTC Passport is not affected baseline
  57. 1 Aug 2026, 00:46 UTC Jade is unaffected baseline
  58. 1 Aug 2026, 00:46 UTC BitBox is not affected baseline
  59. 1 Aug 2026, 00:23 UTC libngu random.c baseline
  60. 1 Aug 2026, 00:17 UTC Predictable RNG fallback and 32-bit reseed baseline
  61. 1 Aug 2026, 00:17 UTC COLDCARD firmware changelog baseline
  62. 1 Aug 2026, 00:17 UTC COLDCARD firmware downloads baseline
  63. 1 Aug 2026, 00:17 UTC Mk4 and Mk5 firmware history baseline
  64. 1 Aug 2026, 00:17 UTC Mk3 firmware history baseline
  65. 1 Aug 2026, 00:17 UTC Q firmware history baseline
  66. 1 Aug 2026, 00:17 UTC Entropy technical backgrounder baseline
  67. 1 Aug 2026, 00:17 UTC Coinkite blog index baseline
  68. 1 Aug 2026, 00:17 UTC Mk3 security advisory baseline
  69. 31 Jul 2026, 07:30 UTC Mk3 security advisory baseline
  70. 31 Jul 2026, 03:29 UTC Predictable RNG fallback and 32-bit reseed baseline
  71. 31 Jul 2026, 01:56 UTC Mk3 security advisory baseline

Back to the evidence index, or read the same differences as structured data in the JSON change feed.

Evidence and calculations are scoped beside the claims they support. Device-state attack-cost scenarios are compared in what an attack costs, with each source's assumptions written out. Where sources disagree, their scenarios are kept separate. If something here is wrong, say so.