COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Chainabuse victim report 0f8d1d1c

chainabuse-0f8d1d1c

https://chainabuse.com/report/0f8d1d1c-556b-40e6-a819-c91c153497aa

Organisation
Chainabuse
Evidence role
Source
Published
2026-08-05
Source changes
0
Detected differences
0
Unreviewed
0
Copies held
1

First-hand victim report cited by the coldcard-hack-tracker community monitor as wave evidence. Registered under the operator's 8 August decision that author-published first-hand victim material is registerable. The claims are the reporter's own and are not verified here.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. Earliest copy held Current
    seen · Captured here 2,639 chars
    Extracted text as captured
    This website utilizes technologies such as cookies to enable essential site functionality, as well as for analytics, personalization, and targeted advertising. You may change your settings at any time or accept the default settings. You may close this banner to continue with only essential cookies. Privacy Policy
    
    Storage Preferences
    
    Targeted Advertising
    Personalization
    Analytics
    Save
    Accept All
    Reject Non-Essential
    
    Check addresses, URLs, IPs, emails, phones, or keywords
    
    Got Scammed?
    Safety Support Center
    API Docs
    Become a Partner
    We'll never ask for payment, passwords, or personal info you don't choose to share. Stay alert.
    Report a Scam
    Top Contributors
    View Reports
    Success Stories
    
    About
    
    LOGIN
    Scam Report
    
    Check addresses, URLs, IPs, emails, phones, or keywords
    
    Back to all results
    Crypto Hacks: Report and Stay Safe with Chainabuse
    1
    
    I was recently effected in the ColdCard mk3 hacks. My case was not one of the initial incidents that happened on 7/30/26. My wallet was drained of 5.39099821 BTC on 7/31/26 at 1:28 PM EST, which I believe makes it a good candidate for a successful recovery. As far as I can tell, it seems like this was a different, copy-cat attacker from the original.
    
    The initial wallet drain can be seen in the following transaction ID: a7a132a207e0edf3de321507905a314b48a05932bfe2a97848f9bf4f073191a3
    
    The attacker's original destination address being: bc1q4626d9knltp3eeuwmfhuqh4ez3py4rdq9nsck8
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.