COLDCARD wallet drain report
coin360-drain
https://coin360.com/news/coldcard-flaws-bitcoin-wallet-drain
- Organisation
- Coin360
- Evidence role
- Reporting
- Published
- 2026-07-31
- Source changes
- 0
- Detected differences
- 3
- Unreviewed
- 0
- Copies held
- 4
Carries a tabulated press estimate: 594.48 BTC / ~US$38.3M confirmed, 488.11 BTC earlier under investigation, 1,082.59 BTC combined 'not fully confirmed by Coinkite'. The article's own footer says it was 'refined and enhanced by ChatGPT'; provenance recorded, figures restate named sources.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked 2 Aug 2026, 01:00 UTC.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain victim addresses. Integrity hashes, capture times and reviewed change summaries remain available below.
-
A relative-age label the enabled normalizer did not match in its literal form; the article body is unchanged.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 2 lines
PublishedJul 31 2026 • UpdatedJul 31 2026 -yesterday4 minutes read +<relative-time>4 minutes read Predictable seed generation put multiple hardware-wallet generations at risk TL;DR Coinkite warned on July 30, 2026, that affected Coldcard devices could generate predictable Bitcoin seeds, enabling remote theft without physical access.Extracted text as captured
Dex News NewsNewsletter Learn How ToCrypto GlossaryTop ListsReviews About About Coin360AuthorsWidgetsMethodologyPartners Swap USD News/Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain Van Thanh Le • PublishedJul 31 2026 • UpdatedJul 31 2026 2 days ago4 minutes read Predictable seed generation put multiple hardware-wallet generations at risk TL;DR Coinkite warned on July 30, 2026, that affected Coldcard devices could generate predictable Bitcoin seeds, enabling remote theft without physical access. Attackers drained 594.48 BTC, valued at about $38.3 million, from roughly 500 single-signature wallets during a 25-minute sweep. Block identified two entropy weaknesses affecting older and newer Coldcard generations, while Peter Todd urged greater use of multisignature custody and independently reviewed systems. Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity. Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place! Trade on Jupiter! Coldcard hardware-wallet flaws allowed attackers to reconstruct weak Bitcoin seeds and drain 594.48 BTC from roughly 500 single-signature wallets, according to findings disclosed by Coldcard maker Coinkite and Block after the July 30, 2026, theft. The confirmed loss was valued at about $38.3 million, while additional transactions identified by Block raised the preliminary potential exposure beyond the amount directly tied to the main sweep. Coinkite issued an urgent security advisory after learning that Bitcoin seeds generated by affected Coldcard firmware could be predictable. The weakness meant attackers could derive private keys remotely without obtaining the physical hardware wallet. The incident centered on failures in entropy generation, the process that supplies the unpredictable randomness used to create a wallet’s seed phrase. The main theft occurred between 01:31 and 01:56 UTC on July 30, when the attacker emptied the identified wallets across a period of about 25 minutes. The targeted wallets reportedly held more than 0.15 BTC each, and many had remained inactive for years. Coins connected to affected wallet activity dated from 2021 through 2026. Rob Hamilton, CEO of AnchorWatch, said he tracked 1,324 spent transaction outputs across 500 transactions completed within three Bitcoin blocks. Hamilton also said approximately 562 BTC from the theft was later consolidated into a single Bitcoin address. Measurement Amount Status Main wallet sweep 594.48 BTC Confirmed theft total Estimated dollar value About $38.3 million Value at the time Earlier matching transactions 488.11 BTC Under investigation Combined preliminary exposure 1,082.59 BTC Not fully confirmed by Coinkite Block security engineer Clay Garrett identified 695 earlier transactions carrying the same apparent on-chain fingerprint as the confirmed thefts. Those transactions moved another 488.11 BTC. If all were connected to the same exploitation campaign, Block’s preliminary estimate would raise the potentially stolen total to 1,082.59 BTC. Coinkite had not confirmed that every suspected transaction resulted from the disclosed firmware flaws, leaving the larger total unresolved. Firmware flaw weakened Coldcard seed generation Block’s Bitcoin engineering and security teams began investigating after receiving reports of remotely stolen Bitcoin from wallets unrelated to Block’s Bitkey product. The investigation linked the affected wallets to Coldcard devices and identified two separate weaknesses in the process used to generate wallet seeds. Older Coldcard firmware contained the more serious flaw. On affected Mk2 and Mk3 devices, a firmware configuration disabled the built-in hardware random number generator. A supporting software library checked whether the RNG configuration existed but did not verify that the RNG was actually enabled. Seed generation then fell back to a software method drawing from predictable device information, including the Coldcard serial number and internal clock registers or boot timing. Because those values were not cryptographically secure sources of randomness, an attacker could generate possible seeds until one produced a public address matching the intended target. Attackers did not need to touch the affected Coldcard. A visible Bitcoin address, wallet descriptor or exported public key could provide enough information to test candidate seeds. Once a candidate generated the same address as the victim’s wallet, the attacker could derive the corresponding private key and authorize transactions.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Only the article's relative-time label changed, this time to the word 'yesterday', which the existing relative-time normalizer does not match. The article body was unchanged.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 2 lines
PublishedJul 31 2026 • UpdatedJul 31 2026 -<relative-time>4 minutes read +yesterday4 minutes read Predictable seed generation put multiple hardware-wallet generations at risk TL;DR Coinkite warned on July 30, 2026, that affected Coldcard devices could generate predictable Bitcoin seeds, enabling remote theft without physical access.Extracted text as captured
Dex News NewsNewsletter Learn How ToCrypto GlossaryTop ListsReviews About About Coin360AuthorsWidgetsMethodologyPartners Swap USD News/Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain Van Thanh Le • PublishedJul 31 2026 • UpdatedJul 31 2026 yesterday4 minutes read Predictable seed generation put multiple hardware-wallet generations at risk TL;DR Coinkite warned on July 30, 2026, that affected Coldcard devices could generate predictable Bitcoin seeds, enabling remote theft without physical access. Attackers drained 594.48 BTC, valued at about $38.3 million, from roughly 500 single-signature wallets during a 25-minute sweep. Block identified two entropy weaknesses affecting older and newer Coldcard generations, while Peter Todd urged greater use of multisignature custody and independently reviewed systems. Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity. Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place! Trade on Jupiter! Coldcard hardware-wallet flaws allowed attackers to reconstruct weak Bitcoin seeds and drain 594.48 BTC from roughly 500 single-signature wallets, according to findings disclosed by Coldcard maker Coinkite and Block after the July 30, 2026, theft. The confirmed loss was valued at about $38.3 million, while additional transactions identified by Block raised the preliminary potential exposure beyond the amount directly tied to the main sweep. Coinkite issued an urgent security advisory after learning that Bitcoin seeds generated by affected Coldcard firmware could be predictable. The weakness meant attackers could derive private keys remotely without obtaining the physical hardware wallet. The incident centered on failures in entropy generation, the process that supplies the unpredictable randomness used to create a wallet’s seed phrase. The main theft occurred between 01:31 and 01:56 UTC on July 30, when the attacker emptied the identified wallets across a period of about 25 minutes. The targeted wallets reportedly held more than 0.15 BTC each, and many had remained inactive for years. Coins connected to affected wallet activity dated from 2021 through 2026. Rob Hamilton, CEO of AnchorWatch, said he tracked 1,324 spent transaction outputs across 500 transactions completed within three Bitcoin blocks. Hamilton also said approximately 562 BTC from the theft was later consolidated into a single Bitcoin address. Measurement Amount Status Main wallet sweep 594.48 BTC Confirmed theft total Estimated dollar value About $38.3 million Value at the time Earlier matching transactions 488.11 BTC Under investigation Combined preliminary exposure 1,082.59 BTC Not fully confirmed by Coinkite Block security engineer Clay Garrett identified 695 earlier transactions carrying the same apparent on-chain fingerprint as the confirmed thefts. Those transactions moved another 488.11 BTC. If all were connected to the same exploitation campaign, Block’s preliminary estimate would raise the potentially stolen total to 1,082.59 BTC. Coinkite had not confirmed that every suspected transaction resulted from the disclosed firmware flaws, leaving the larger total unresolved. Firmware flaw weakened Coldcard seed generation Block’s Bitcoin engineering and security teams began investigating after receiving reports of remotely stolen Bitcoin from wallets unrelated to Block’s Bitkey product. The investigation linked the affected wallets to Coldcard devices and identified two separate weaknesses in the process used to generate wallet seeds. Older Coldcard firmware contained the more serious flaw. On affected Mk2 and Mk3 devices, a firmware configuration disabled the built-in hardware random number generator. A supporting software library checked whether the RNG configuration existed but did not verify that the RNG was actually enabled. Seed generation then fell back to a software method drawing from predictable device information, including the Coldcard serial number and internal clock registers or boot timing. Because those values were not cryptographically secure sources of randomness, an attacker could generate possible seeds until one produced a public address matching the intended target. Attackers did not need to touch the affected Coldcard. A visible Bitcoin address, wallet descriptor or exported public key could provide enough information to test candidate seeds. Once a candidate generated the same address as the victim’s wallet, the attacker could derive the corresponding private key and authorize transactions.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Only the article's relative-time label changed from 15 hours to 16 hours.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 2 lines
PublishedJul 31 2026 • UpdatedJul 31 2026 -15 hours ago4 minutes read +16 hours ago4 minutes read Predictable seed generation put multiple hardware-wallet generations at risk TL;DR Coinkite warned on July 30, 2026, that affected Coldcard devices could generate predictable Bitcoin seeds, enabling remote theft without physical access.Extracted text as captured
Dex News NewsNewsletter Learn How ToCrypto GlossaryTop ListsReviews About About Coin360AuthorsWidgetsMethodologyPartners Swap USD News/Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain Van Thanh Le • PublishedJul 31 2026 • UpdatedJul 31 2026 16 hours ago4 minutes read Predictable seed generation put multiple hardware-wallet generations at risk TL;DR Coinkite warned on July 30, 2026, that affected Coldcard devices could generate predictable Bitcoin seeds, enabling remote theft without physical access. Attackers drained 594.48 BTC, valued at about $38.3 million, from roughly 500 single-signature wallets during a 25-minute sweep. Block identified two entropy weaknesses affecting older and newer Coldcard generations, while Peter Todd urged greater use of multisignature custody and independently reviewed systems. Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity. Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place! Trade on Jupiter! Coldcard hardware-wallet flaws allowed attackers to reconstruct weak Bitcoin seeds and drain 594.48 BTC from roughly 500 single-signature wallets, according to findings disclosed by Coldcard maker Coinkite and Block after the July 30, 2026, theft. The confirmed loss was valued at about $38.3 million, while additional transactions identified by Block raised the preliminary potential exposure beyond the amount directly tied to the main sweep. Coinkite issued an urgent security advisory after learning that Bitcoin seeds generated by affected Coldcard firmware could be predictable. The weakness meant attackers could derive private keys remotely without obtaining the physical hardware wallet. The incident centered on failures in entropy generation, the process that supplies the unpredictable randomness used to create a wallet’s seed phrase. The main theft occurred between 01:31 and 01:56 UTC on July 30, when the attacker emptied the identified wallets across a period of about 25 minutes. The targeted wallets reportedly held more than 0.15 BTC each, and many had remained inactive for years. Coins connected to affected wallet activity dated from 2021 through 2026. Rob Hamilton, CEO of AnchorWatch, said he tracked 1,324 spent transaction outputs across 500 transactions completed within three Bitcoin blocks. Hamilton also said approximately 562 BTC from the theft was later consolidated into a single Bitcoin address. Measurement Amount Status Main wallet sweep 594.48 BTC Confirmed theft total Estimated dollar value About $38.3 million Value at the time Earlier matching transactions 488.11 BTC Under investigation Combined preliminary exposure 1,082.59 BTC Not fully confirmed by Coinkite Block security engineer Clay Garrett identified 695 earlier transactions carrying the same apparent on-chain fingerprint as the confirmed thefts. Those transactions moved another 488.11 BTC. If all were connected to the same exploitation campaign, Block’s preliminary estimate would raise the potentially stolen total to 1,082.59 BTC. Coinkite had not confirmed that every suspected transaction resulted from the disclosed firmware flaws, leaving the larger total unresolved. Firmware flaw weakened Coldcard seed generation Block’s Bitcoin engineering and security teams began investigating after receiving reports of remotely stolen Bitcoin from wallets unrelated to Block’s Bitkey product. The investigation linked the affected wallets to Coldcard devices and identified two separate weaknesses in the process used to generate wallet seeds. Older Coldcard firmware contained the more serious flaw. On affected Mk2 and Mk3 devices, a firmware configuration disabled the built-in hardware random number generator. A supporting software library checked whether the RNG configuration existed but did not verify that the RNG was actually enabled. Seed generation then fell back to a software method drawing from predictable device information, including the Coldcard serial number and internal clock registers or boot timing. Because those values were not cryptographically secure sources of randomness, an attacker could generate possible seeds until one produced a public address matching the intended target. Attackers did not need to touch the affected Coldcard. A visible Bitcoin address, wallet descriptor or exported public key could provide enough information to test candidate seeds. Once a candidate generated the same address as the victim’s wallet, the attacker could derive the corresponding private key and authorize transactions.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
Dex News NewsNewsletter Learn How ToCrypto GlossaryTop ListsReviews About About Coin360AuthorsWidgetsMethodologyPartners Swap USD News/Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain Van Thanh Le • PublishedJul 31 2026 • UpdatedJul 31 2026 15 hours ago4 minutes read Predictable seed generation put multiple hardware-wallet generations at risk TL;DR Coinkite warned on July 30, 2026, that affected Coldcard devices could generate predictable Bitcoin seeds, enabling remote theft without physical access. Attackers drained 594.48 BTC, valued at about $38.3 million, from roughly 500 single-signature wallets during a 25-minute sweep. Block identified two entropy weaknesses affecting older and newer Coldcard generations, while Peter Todd urged greater use of multisignature custody and independently reviewed systems. Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity. Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place! Trade on Jupiter! Coldcard hardware-wallet flaws allowed attackers to reconstruct weak Bitcoin seeds and drain 594.48 BTC from roughly 500 single-signature wallets, according to findings disclosed by Coldcard maker Coinkite and Block after the July 30, 2026, theft. The confirmed loss was valued at about $38.3 million, while additional transactions identified by Block raised the preliminary potential exposure beyond the amount directly tied to the main sweep. Coinkite issued an urgent security advisory after learning that Bitcoin seeds generated by affected Coldcard firmware could be predictable. The weakness meant attackers could derive private keys remotely without obtaining the physical hardware wallet. The incident centered on failures in entropy generation, the process that supplies the unpredictable randomness used to create a wallet’s seed phrase. The main theft occurred between 01:31 and 01:56 UTC on July 30, when the attacker emptied the identified wallets across a period of about 25 minutes. The targeted wallets reportedly held more than 0.15 BTC each, and many had remained inactive for years. Coins connected to affected wallet activity dated from 2021 through 2026. Rob Hamilton, CEO of AnchorWatch, said he tracked 1,324 spent transaction outputs across 500 transactions completed within three Bitcoin blocks. Hamilton also said approximately 562 BTC from the theft was later consolidated into a single Bitcoin address. Measurement Amount Status Main wallet sweep 594.48 BTC Confirmed theft total Estimated dollar value About $38.3 million Value at the time Earlier matching transactions 488.11 BTC Under investigation Combined preliminary exposure 1,082.59 BTC Not fully confirmed by Coinkite Block security engineer Clay Garrett identified 695 earlier transactions carrying the same apparent on-chain fingerprint as the confirmed thefts. Those transactions moved another 488.11 BTC. If all were connected to the same exploitation campaign, Block’s preliminary estimate would raise the potentially stolen total to 1,082.59 BTC. Coinkite had not confirmed that every suspected transaction resulted from the disclosed firmware flaws, leaving the larger total unresolved. Firmware flaw weakened Coldcard seed generation Block’s Bitcoin engineering and security teams began investigating after receiving reports of remotely stolen Bitcoin from wallets unrelated to Block’s Bitkey product. The investigation linked the affected wallets to Coldcard devices and identified two separate weaknesses in the process used to generate wallet seeds. Older Coldcard firmware contained the more serious flaw. On affected Mk2 and Mk3 devices, a firmware configuration disabled the built-in hardware random number generator. A supporting software library checked whether the RNG configuration existed but did not verify that the RNG was actually enabled. Seed generation then fell back to a software method drawing from predictable device information, including the Coldcard serial number and internal clock registers or boot timing. Because those values were not cryptographically secure sources of randomness, an attacker could generate possible seeds until one produced a public address matching the intended target. Attackers did not need to touch the affected Coldcard. A visible Bitcoin address, wallet descriptor or exported public key could provide enough information to test candidate seeds. Once a candidate generated the same address as the victim’s wallet, the attacker could derive the corresponding private key and authorize transactions.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
Each copy above is identified by the SHA-256 of its extracted text, shown beside it, and the diffs are plain unified diffs. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
The SHA-256 prefixes above identify each held copy without turning this page into a mirror of somebody else's post. Compare a quotation against the original. If the post has since been edited or deleted, ask and the held copy can be produced.