COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Coldcard Seed Flaw ($38M)

blockchainunmasked-prior-warning

https://www.blockchainunmasked.com/post/coldcard-seed-flaw-38m

Latest reviewed change

source content difference between and

The page replaced one related-post headline with another at the bottom of the article.

seen +1 -1 full history below
 The moment it moves toward liquidity, we'll be watching.
 Recent Posts
 See All
-Beyond MetaMask: Public Git History Links a SEAL Registry-Listed Identity to Commits Across Dozens of Repositories
+Petitions for Remission in Crypto Asset Cases: The Gap Between Frozen and Returned
 The War Room
 84 Partnerships, 51 Jurisdictions: The FATF's New Report Puts Information Sharing at the Center of the Fight
 Subscribe to our newsletter
Organisation
Blockchain Unmasked
Evidence role
Independent primary analysis
Published
2026-07-31
Source changes
2
Detected differences
7
Unreviewed
0
Copies held
8

Blockchain Unmasked's first-hand account of investigating earlier victim reports and warning Coinkite and public agencies before the July 2026 sweep. It describes its own 2024 investigation, correspondence and hypothesis development. Those historical claims are reported testimony from the organisation and are not independently verified here.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +1 -1

    The page replaced one related-post headline with another at the bottom of the article.

    seen · Captured here 5,644 chars
    What changed from the previous capture 2 lines
     The moment it moves toward liquidity, we'll be watching.
     Recent Posts
     See All
    -Beyond MetaMask: Public Git History Links a SEAL Registry-Listed Identity to Commits Across Dozens of Repositories
    +Petitions for Remission in Crypto Asset Cases: The Gap Between Frozen and Returned
     The War Room
     84 Partnerships, 51 Jurisdictions: The FATF's New Report Puts Information Sharing at the Center of the Fight
     Subscribe to our newsletter
    
    Extracted text as captured
    top of page
    Products
    Industries
    Insights
    Report scam
    Book consultation
    Blockchain intelligence &
    investigations
    Report scam
    Actionable crypto intelligence for Law Enforcement, legal teams, and financial institutions.
    Book consultation
    Products
    Industries
    Insights
    Report scam
    Book consultation
    Coldcard Seed Flaw ($38M)
    Blockchain Unmasked
    Jul 31
    3 min read
    Two days ago, 594 BTC, about $38 million, was swept from roughly 500 wallets in 25 minutes.
    We flagged this vulnerability two years ago to Coldcard, local, state, and federal agencies.
    In 2024, several victims came to us with the same story. Bitcoin gone from a Coldcard wallet.
    No malware, no phishing, backups never left the safe. At first, we began to think this could only be an inside job. How else, in a properly designed entropy system, could anyone be brute forcing wallets? And why would a hardware wallet company ever allow weak entropy creation? Why even offer that to users? Why put the integrity of your hardware wallet in the hands of less educated people? Shouldn't the hardware company offer MAXIMUM entropy, and therefore maximum security, by default? It didn't make sense.
    We also knew enough to know this wasn't a user device issue, or malware, or phishing. When thefts keep happening with no visible attack surface, you stop looking at the victim's computer and start looking at the keys.
    Our analysis pointed to weak seed entropy on the devices themselves. We took our findings to Coldcard, and we filed a complete report with local, state and federal agencies.
    This week, that same weakness was exploited at scale. Almost $40 million gone.
    The flaw goes back to March 2021. Coldcard devices carry a dedicated hardware chip whose entire purpose is producing true randomness for seed generation. A build error in firmware 4.0.0 cut that chip out of the process. A compile-time check tested whether a setting existed instead of what it was set to, and the firmware silently fell back on a software random number generator.
    Nobody caught it, including the manufacturer. Or, they chose to look the other way. Reddit threads showed many users with the same story and an active denial but the hardware company.
    The damage varies by model. On Mk2 and Mk3 devices running firmware 4.0.0 through 5.0.3, no hardware entropy fed key creation at all. On Mk4, Mk5 and Q, the firmware tried to mix in randomness from the secure element at boot but truncated it to 32 bits. Instead of the 128 bits a 12-word seed is supposed to carry, effective randomness collapsed to somewhere between 32 and 40 bits.
    2^40 is about a trillion possibilities. That sounds like a lot. 2 years ago, it may have been a lot given the state of AI. Today, it isn't. An attacker can regenerate every candidate seed offline, derive the standard address paths for each one, and scan the blockchain for funded matches. No contact with the device, ever. The PIN doesn't matter. The air gap doesn't matter. By the time a funded address matches, the attacker already holds the private key.
    On chain, the sweep moved 1,324 pieces of bitcoin across 500 transactions inside three blocks, then consolidated most of it into a single address, where it still sits.
    The bug sat in open source firmware for five years, and anyone could have read that code at any time. What changed is cost and technology. AI tools can now read years of firmware history and surface exactly this class of flaw, and ordinary hardware can brute force a 40-bit keyspace in a practical timeframe. Coinkite itself said it assumes AI was used to find the bug. The tools got cheap.
    The weak keys were already out there, waiting for technology to catch up. How many more instances like this will occur in the near future? Is hardware no longer safe? Do you have full confidence in your hardware wallet provider?
    If you generated a seed on an affected Coldcard, updating the firmware fixes nothing. The seed was born weak and stays weak. Generate a new seed on patched or unaffected hardware and migrate your funds carefully. Seeds created with 50 or more dice rolls, or protected by a strong BIP-39 passphrase, are in far better shape.
    And for the victims: this money is on chain, and it is being watched.
    The moment it moves toward liquidity, we'll be watching.
    Recent Posts
    See All
    Petitions for Remission in Crypto Asset Cases: The Gap Between Frozen and Returned

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +1 -1

    The page changed the headline of a related article from a specific repository count to a generic public-git-history framing.

    seen · Captured here 5,676 chars
    What changed from the previous capture 2 lines
     The moment it moves toward liquidity, we'll be watching.
     Recent Posts
     See All
    -Beyond MetaMask: 68 repositories, 17 organizations, all reached by one catalogued DPRK IT-worker.
    +Beyond MetaMask: Public Git History Links a SEAL Registry-Listed Identity to Commits Across Dozens of Repositories
     The War Room
     84 Partnerships, 51 Jurisdictions: The FATF's New Report Puts Information Sharing at the Center of the Fight
     Subscribe to our newsletter
    
    Extracted text as captured
    top of page
    Products
    Industries
    Insights
    Report scam
    Book consultation
    Blockchain intelligence &
    investigations
    Report scam
    Actionable crypto intelligence for Law Enforcement, legal teams, and financial institutions.
    Book consultation
    Products
    Industries
    Insights
    Report scam
    Book consultation
    Coldcard Seed Flaw ($38M)
    Blockchain Unmasked
    Jul 31
    3 min read
    Two days ago, 594 BTC, about $38 million, was swept from roughly 500 wallets in 25 minutes.
    We flagged this vulnerability two years ago to Coldcard, local, state, and federal agencies.
    In 2024, several victims came to us with the same story. Bitcoin gone from a Coldcard wallet.
    No malware, no phishing, backups never left the safe. At first, we began to think this could only be an inside job. How else, in a properly designed entropy system, could anyone be brute forcing wallets? And why would a hardware wallet company ever allow weak entropy creation? Why even offer that to users? Why put the integrity of your hardware wallet in the hands of less educated people? Shouldn't the hardware company offer MAXIMUM entropy, and therefore maximum security, by default? It didn't make sense.
    We also knew enough to know this wasn't a user device issue, or malware, or phishing. When thefts keep happening with no visible attack surface, you stop looking at the victim's computer and start looking at the keys.
    Our analysis pointed to weak seed entropy on the devices themselves. We took our findings to Coldcard, and we filed a complete report with local, state and federal agencies.
    This week, that same weakness was exploited at scale. Almost $40 million gone.
    The flaw goes back to March 2021. Coldcard devices carry a dedicated hardware chip whose entire purpose is producing true randomness for seed generation. A build error in firmware 4.0.0 cut that chip out of the process. A compile-time check tested whether a setting existed instead of what it was set to, and the firmware silently fell back on a software random number generator.
    Nobody caught it, including the manufacturer. Or, they chose to look the other way. Reddit threads showed many users with the same story and an active denial but the hardware company.
    The damage varies by model. On Mk2 and Mk3 devices running firmware 4.0.0 through 5.0.3, no hardware entropy fed key creation at all. On Mk4, Mk5 and Q, the firmware tried to mix in randomness from the secure element at boot but truncated it to 32 bits. Instead of the 128 bits a 12-word seed is supposed to carry, effective randomness collapsed to somewhere between 32 and 40 bits.
    2^40 is about a trillion possibilities. That sounds like a lot. 2 years ago, it may have been a lot given the state of AI. Today, it isn't. An attacker can regenerate every candidate seed offline, derive the standard address paths for each one, and scan the blockchain for funded matches. No contact with the device, ever. The PIN doesn't matter. The air gap doesn't matter. By the time a funded address matches, the attacker already holds the private key.
    On chain, the sweep moved 1,324 pieces of bitcoin across 500 transactions inside three blocks, then consolidated most of it into a single address, where it still sits.
    The bug sat in open source firmware for five years, and anyone could have read that code at any time. What changed is cost and technology. AI tools can now read years of firmware history and surface exactly this class of flaw, and ordinary hardware can brute force a 40-bit keyspace in a practical timeframe. Coinkite itself said it assumes AI was used to find the bug. The tools got cheap.
    The weak keys were already out there, waiting for technology to catch up. How many more instances like this will occur in the near future? Is hardware no longer safe? Do you have full confidence in your hardware wallet provider?
    If you generated a seed on an affected Coldcard, updating the firmware fixes nothing. The seed was born weak and stays weak. Generate a new seed on patched or unaffected hardware and migrate your funds carefully. Seeds created with 50 or more dice rolls, or protected by a strong BIP-39 passphrase, are in far better shape.
    And for the victims: this money is on chain, and it is being watched.
    The moment it moves toward liquidity, we'll be watching.
    Recent Posts
    See All
    Beyond MetaMask: Public Git History Links a SEAL Registry-Listed Identity to Commits Across Dozens of Repositories

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. Earliest copy held
    seen · Captured here 5,607 chars
    Extracted text as captured
    top of page
    Products
    Industries
    Insights
    Report scam
    Book consultation
    Blockchain intelligence &
    investigations
    Report scam
    Actionable crypto intelligence for Law Enforcement, legal teams, and financial institutions.
    Book consultation
    Products
    Industries
    Insights
    Report scam
    Book consultation
    Coldcard Seed Flaw ($38M)
    Blockchain Unmasked
    3 days ago
    3 min read
    Two days ago, 594 BTC, about $38 million, was swept from roughly 500 wallets in 25 minutes.
    We flagged this vulnerability two years ago to Coldcard, local, state, and federal agencies.
    In 2024, several victims came to us with the same story. Bitcoin gone from a Coldcard wallet.
    No malware, no phishing, backups never left the safe. At first, we began to think this could only be an inside job. How else, in a properly designed entropy system, could anyone be brute forcing wallets? And why would a hardware wallet company ever allow weak entropy creation? Why even offer that to users? Why put the integrity of your hardware wallet in the hands of less educated people? Shouldn't the hardware company offer MAXIMUM entropy, and therefore maximum security, by default? It didn't make sense.
    We also knew enough to know this wasn't a user device issue, or malware, or phishing. When thefts keep happening with no visible attack surface, you stop looking at the victim's computer and start looking at the keys.
    Our analysis pointed to weak seed entropy on the devices themselves. We took our findings to Coldcard, and we filed a complete report with local, state and federal agencies.
    This week, that same weakness was exploited at scale. Almost $40 million gone.
    The flaw goes back to March 2021. Coldcard devices carry a dedicated hardware chip whose entire purpose is producing true randomness for seed generation. A build error in firmware 4.0.0 cut that chip out of the process. A compile-time check tested whether a setting existed instead of what it was set to, and the firmware silently fell back on a software random number generator.
    Nobody caught it, including the manufacturer. Or, they chose to look the other way. Reddit threads showed many users with the same story and an active denial but the hardware company.
    The damage varies by model. On Mk2 and Mk3 devices running firmware 4.0.0 through 5.0.3, no hardware entropy fed key creation at all. On Mk4, Mk5 and Q, the firmware tried to mix in randomness from the secure element at boot but truncated it to 32 bits. Instead of the 128 bits a 12-word seed is supposed to carry, effective randomness collapsed to somewhere between 32 and 40 bits.
    2^40 is about a trillion possibilities. That sounds like a lot. 2 years ago, it may have been a lot given the state of AI. Today, it isn't. An attacker can regenerate every candidate seed offline, derive the standard address paths for each one, and scan the blockchain for funded matches. No contact with the device, ever. The PIN doesn't matter. The air gap doesn't matter. By the time a funded address matches, the attacker already holds the private key.
    On chain, the sweep moved 1,324 pieces of bitcoin across 500 transactions inside three blocks, then consolidated most of it into a single address, where it still sits.
    The bug sat in open source firmware for five years, and anyone could have read that code at any time. What changed is cost and technology. AI tools can now read years of firmware history and surface exactly this class of flaw, and ordinary hardware can brute force a 40-bit keyspace in a practical timeframe. Coinkite itself said it assumes AI was used to find the bug. The tools got cheap.
    The weak keys were already out there, waiting for technology to catch up. How many more instances like this will occur in the near future? Is hardware no longer safe? Do you have full confidence in your hardware wallet provider?
    If you generated a seed on an affected Coldcard, updating the firmware fixes nothing. The seed was born weak and stays weak. Generate a new seed on patched or unaffected hardware and migrate your funds carefully. Seeds created with 50 or more dice rolls, or protected by a strong BIP-39 passphrase, are in far better shape.
    And for the victims: this money is on chain, and it is being watched.
    The moment it moves toward liquidity, we'll be watching.
    Recent Posts
    See All
    The War Room

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

5 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
  • +2 -2 Only the relative-age label changed from '3 days ago' to 'Jul 31' and adjacent article links appeared; the first-hand account text was unchanged.
  • +1 -1 Only a relative date marker rolled from 'Jul 31' to '3 days ago'.
  • +1 -1 Only the page's relative publish date changed from 3 days ago to Jul 31.
  • +1 -1 Live relative-date counter flapping: the age label changed back from "5 days ago" to "3 days ago"; the article text itself is unchanged.
  • +1 -1 Live relative-date counter: the article's age label changed from "3 days ago" to "5 days ago"; the article text itself is unchanged.
How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.