COLDCARD vulnerability what happened, and what to do
Informational only, and this site never asks for your recovery words. details

Informational only. This is independent analysis and an evidence-backed explainer, not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite, Block, or any other party named here. Published estimates are attributed, and differing scenarios are kept separate with their assumptions. Act on your own judgement. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it. Deliberate recovery on independently verified offline equipment is a separate operation. Seed-word safety.

COLDCARD wallet drain report

coin360-drain

https://coin360.com/news/coldcard-flaws-bitcoin-wallet-drain

Organisation
Coin360
Evidence role
Reporting
Published
2026-07-31
Source changes
0
Detected differences
3
Unreviewed
0
Copies held
4

Carries a tabulated press estimate: 594.48 BTC / ~US$38.3M confirmed, 488.11 BTC earlier under investigation, 1,082.59 BTC combined 'not fully confirmed by Coinkite'. The article's own footer says it was 'refined and enhanced by ChatGPT'; provenance recorded, figures restate named sources.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked 2 Aug 2026, 01:00 UTC.

  1. capture noise difference between 1 Aug 2026, 16:10 UTC and 2 Aug 2026, 00:09 UTC Current capture noise +1 -1

    A relative-age label the enabled normalizer did not match in its literal form; the article body is unchanged.

    seen 2 Aug 2026, 00:09 UTC · Captured here text sha256 d70d7b9ae1bc5a9848a4f824 13,347 chars
    What changed from the previous capture 2 lines
     PublishedJul 31 2026
     UpdatedJul 31 2026
    -yesterday4 minutes read
    +<relative-time>4 minutes read
     Predictable seed generation put multiple hardware-wallet generations at risk
     TL;DR
     Coinkite warned on July 30, 2026, that affected Coldcard devices could generate predictable Bitcoin seeds, enabling remote theft without physical access.
    
    Extracted text as captured
    Dex
    News
    NewsNewsletter
    Learn
    How ToCrypto GlossaryTop ListsReviews
    About
    About Coin360AuthorsWidgetsMethodologyPartners
    Swap
    USD
    News/Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain
    Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain
    Van Thanh Le
    •
    PublishedJul 31 2026
    •
    UpdatedJul 31 2026
    2 days ago4 minutes read
    Predictable seed generation put multiple hardware-wallet generations at risk
    TL;DR
    Coinkite warned on July 30, 2026, that affected Coldcard devices could generate predictable Bitcoin seeds, enabling remote theft without physical access.
    Attackers drained 594.48 BTC, valued at about $38.3 million, from roughly 500 single-signature wallets during a 25-minute sweep.
    Block identified two entropy weaknesses affecting older and newer Coldcard generations, while Peter Todd urged greater use of multisignature custody and independently reviewed systems.
    Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
    Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
    Trade on Jupiter!
    Coldcard hardware-wallet flaws allowed attackers to reconstruct weak Bitcoin seeds and drain 594.48 BTC from roughly 500 single-signature wallets, according to findings disclosed by Coldcard maker Coinkite and Block after the July 30, 2026, theft. The confirmed loss was valued at about $38.3 million, while additional transactions identified by Block raised the preliminary potential exposure beyond the amount directly tied to the main sweep.
    Coinkite issued an urgent security advisory after learning that Bitcoin seeds generated by affected Coldcard firmware could be predictable. The weakness meant attackers could derive private keys remotely without obtaining the physical hardware wallet. The incident centered on failures in entropy generation, the process that supplies the unpredictable randomness used to create a wallet’s seed phrase.
    The main theft occurred between 01:31 and 01:56 UTC on July 30, when the attacker emptied the identified wallets across a period of about 25 minutes. The targeted wallets reportedly held more than 0.15 BTC each, and many had remained inactive for years. Coins connected to affected wallet activity dated from 2021 through 2026.
    Rob Hamilton, CEO of AnchorWatch, said he tracked 1,324 spent transaction outputs across 500 transactions completed within three Bitcoin blocks. Hamilton also said approximately 562 BTC from the theft was later consolidated into a single Bitcoin address.
    Measurement Amount Status
    Main wallet sweep 594.48 BTC Confirmed theft total
    Estimated dollar value About $38.3 million Value at the time
    Earlier matching transactions 488.11 BTC Under investigation
    Combined preliminary exposure 1,082.59 BTC Not fully confirmed by Coinkite
    Block security engineer Clay Garrett identified 695 earlier transactions carrying the same apparent on-chain fingerprint as the confirmed thefts. Those transactions moved another 488.11 BTC. If all were connected to the same exploitation campaign, Block’s preliminary estimate would raise the potentially stolen total to 1,082.59 BTC. Coinkite had not confirmed that every suspected transaction resulted from the disclosed firmware flaws, leaving the larger total unresolved.
    Firmware flaw weakened Coldcard seed generation
    Block’s Bitcoin engineering and security teams began investigating after receiving reports of remotely stolen Bitcoin from wallets unrelated to Block’s Bitkey product. The investigation linked the affected wallets to Coldcard devices and identified two separate weaknesses in the process used to generate wallet seeds.
    Older Coldcard firmware contained the more serious flaw. On affected Mk2 and Mk3 devices, a firmware configuration disabled the built-in hardware random number generator. A supporting software library checked whether the RNG configuration existed but did not verify that the RNG was actually enabled.
    Seed generation then fell back to a software method drawing from predictable device information, including the Coldcard serial number and internal clock registers or boot timing. Because those values were not cryptographically secure sources of randomness, an attacker could generate possible seeds until one produced a public address matching the intended target.
    Attackers did not need to touch the affected Coldcard. A visible Bitcoin address, wallet descriptor or exported public key could provide enough information to test candidate seeds. Once a candidate generated the same address as the victim’s wallet, the attacker could derive the corresponding private key and authorize transactions.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. capture noise difference between 1 Aug 2026, 03:51 UTC and 1 Aug 2026, 16:10 UTC capture noise +1 -1

    Only the article's relative-time label changed, this time to the word 'yesterday', which the existing relative-time normalizer does not match. The article body was unchanged.

    seen 1 Aug 2026, 16:10 UTC · Captured here text sha256 eca2849d0b35494977490ef7 13,346 chars
    What changed from the previous capture 2 lines
     PublishedJul 31 2026
     UpdatedJul 31 2026
    -<relative-time>4 minutes read
    +yesterday4 minutes read
     Predictable seed generation put multiple hardware-wallet generations at risk
     TL;DR
     Coinkite warned on July 30, 2026, that affected Coldcard devices could generate predictable Bitcoin seeds, enabling remote theft without physical access.
    
    Extracted text as captured
    Dex
    News
    NewsNewsletter
    Learn
    How ToCrypto GlossaryTop ListsReviews
    About
    About Coin360AuthorsWidgetsMethodologyPartners
    Swap
    USD
    News/Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain
    Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain
    Van Thanh Le
    •
    PublishedJul 31 2026
    •
    UpdatedJul 31 2026
    yesterday4 minutes read
    Predictable seed generation put multiple hardware-wallet generations at risk
    TL;DR
    Coinkite warned on July 30, 2026, that affected Coldcard devices could generate predictable Bitcoin seeds, enabling remote theft without physical access.
    Attackers drained 594.48 BTC, valued at about $38.3 million, from roughly 500 single-signature wallets during a 25-minute sweep.
    Block identified two entropy weaknesses affecting older and newer Coldcard generations, while Peter Todd urged greater use of multisignature custody and independently reviewed systems.
    Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
    Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
    Trade on Jupiter!
    Coldcard hardware-wallet flaws allowed attackers to reconstruct weak Bitcoin seeds and drain 594.48 BTC from roughly 500 single-signature wallets, according to findings disclosed by Coldcard maker Coinkite and Block after the July 30, 2026, theft. The confirmed loss was valued at about $38.3 million, while additional transactions identified by Block raised the preliminary potential exposure beyond the amount directly tied to the main sweep.
    Coinkite issued an urgent security advisory after learning that Bitcoin seeds generated by affected Coldcard firmware could be predictable. The weakness meant attackers could derive private keys remotely without obtaining the physical hardware wallet. The incident centered on failures in entropy generation, the process that supplies the unpredictable randomness used to create a wallet’s seed phrase.
    The main theft occurred between 01:31 and 01:56 UTC on July 30, when the attacker emptied the identified wallets across a period of about 25 minutes. The targeted wallets reportedly held more than 0.15 BTC each, and many had remained inactive for years. Coins connected to affected wallet activity dated from 2021 through 2026.
    Rob Hamilton, CEO of AnchorWatch, said he tracked 1,324 spent transaction outputs across 500 transactions completed within three Bitcoin blocks. Hamilton also said approximately 562 BTC from the theft was later consolidated into a single Bitcoin address.
    Measurement Amount Status
    Main wallet sweep 594.48 BTC Confirmed theft total
    Estimated dollar value About $38.3 million Value at the time
    Earlier matching transactions 488.11 BTC Under investigation
    Combined preliminary exposure 1,082.59 BTC Not fully confirmed by Coinkite
    Block security engineer Clay Garrett identified 695 earlier transactions carrying the same apparent on-chain fingerprint as the confirmed thefts. Those transactions moved another 488.11 BTC. If all were connected to the same exploitation campaign, Block’s preliminary estimate would raise the potentially stolen total to 1,082.59 BTC. Coinkite had not confirmed that every suspected transaction resulted from the disclosed firmware flaws, leaving the larger total unresolved.
    Firmware flaw weakened Coldcard seed generation
    Block’s Bitcoin engineering and security teams began investigating after receiving reports of remotely stolen Bitcoin from wallets unrelated to Block’s Bitkey product. The investigation linked the affected wallets to Coldcard devices and identified two separate weaknesses in the process used to generate wallet seeds.
    Older Coldcard firmware contained the more serious flaw. On affected Mk2 and Mk3 devices, a firmware configuration disabled the built-in hardware random number generator. A supporting software library checked whether the RNG configuration existed but did not verify that the RNG was actually enabled.
    Seed generation then fell back to a software method drawing from predictable device information, including the Coldcard serial number and internal clock registers or boot timing. Because those values were not cryptographically secure sources of randomness, an attacker could generate possible seeds until one produced a public address matching the intended target.
    Attackers did not need to touch the affected Coldcard. A visible Bitcoin address, wallet descriptor or exported public key could provide enough information to test candidate seeds. Once a candidate generated the same address as the victim’s wallet, the attacker could derive the corresponding private key and authorize transactions.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. capture noise difference between 1 Aug 2026, 02:53 UTC and 1 Aug 2026, 03:51 UTC capture noise +1 -1

    Only the article's relative-time label changed from 15 hours to 16 hours.

    seen 1 Aug 2026, 03:51 UTC · Captured here text sha256 ec30ad6b41059897a9402355 13,349 chars
    What changed from the previous capture 2 lines
     PublishedJul 31 2026
     UpdatedJul 31 2026
    -15 hours ago4 minutes read
    +16 hours ago4 minutes read
     Predictable seed generation put multiple hardware-wallet generations at risk
     TL;DR
     Coinkite warned on July 30, 2026, that affected Coldcard devices could generate predictable Bitcoin seeds, enabling remote theft without physical access.
    
    Extracted text as captured
    Dex
    News
    NewsNewsletter
    Learn
    How ToCrypto GlossaryTop ListsReviews
    About
    About Coin360AuthorsWidgetsMethodologyPartners
    Swap
    USD
    News/Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain
    Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain
    Van Thanh Le
    •
    PublishedJul 31 2026
    •
    UpdatedJul 31 2026
    16 hours ago4 minutes read
    Predictable seed generation put multiple hardware-wallet generations at risk
    TL;DR
    Coinkite warned on July 30, 2026, that affected Coldcard devices could generate predictable Bitcoin seeds, enabling remote theft without physical access.
    Attackers drained 594.48 BTC, valued at about $38.3 million, from roughly 500 single-signature wallets during a 25-minute sweep.
    Block identified two entropy weaknesses affecting older and newer Coldcard generations, while Peter Todd urged greater use of multisignature custody and independently reviewed systems.
    Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
    Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
    Trade on Jupiter!
    Coldcard hardware-wallet flaws allowed attackers to reconstruct weak Bitcoin seeds and drain 594.48 BTC from roughly 500 single-signature wallets, according to findings disclosed by Coldcard maker Coinkite and Block after the July 30, 2026, theft. The confirmed loss was valued at about $38.3 million, while additional transactions identified by Block raised the preliminary potential exposure beyond the amount directly tied to the main sweep.
    Coinkite issued an urgent security advisory after learning that Bitcoin seeds generated by affected Coldcard firmware could be predictable. The weakness meant attackers could derive private keys remotely without obtaining the physical hardware wallet. The incident centered on failures in entropy generation, the process that supplies the unpredictable randomness used to create a wallet’s seed phrase.
    The main theft occurred between 01:31 and 01:56 UTC on July 30, when the attacker emptied the identified wallets across a period of about 25 minutes. The targeted wallets reportedly held more than 0.15 BTC each, and many had remained inactive for years. Coins connected to affected wallet activity dated from 2021 through 2026.
    Rob Hamilton, CEO of AnchorWatch, said he tracked 1,324 spent transaction outputs across 500 transactions completed within three Bitcoin blocks. Hamilton also said approximately 562 BTC from the theft was later consolidated into a single Bitcoin address.
    Measurement Amount Status
    Main wallet sweep 594.48 BTC Confirmed theft total
    Estimated dollar value About $38.3 million Value at the time
    Earlier matching transactions 488.11 BTC Under investigation
    Combined preliminary exposure 1,082.59 BTC Not fully confirmed by Coinkite
    Block security engineer Clay Garrett identified 695 earlier transactions carrying the same apparent on-chain fingerprint as the confirmed thefts. Those transactions moved another 488.11 BTC. If all were connected to the same exploitation campaign, Block’s preliminary estimate would raise the potentially stolen total to 1,082.59 BTC. Coinkite had not confirmed that every suspected transaction resulted from the disclosed firmware flaws, leaving the larger total unresolved.
    Firmware flaw weakened Coldcard seed generation
    Block’s Bitcoin engineering and security teams began investigating after receiving reports of remotely stolen Bitcoin from wallets unrelated to Block’s Bitkey product. The investigation linked the affected wallets to Coldcard devices and identified two separate weaknesses in the process used to generate wallet seeds.
    Older Coldcard firmware contained the more serious flaw. On affected Mk2 and Mk3 devices, a firmware configuration disabled the built-in hardware random number generator. A supporting software library checked whether the RNG configuration existed but did not verify that the RNG was actually enabled.
    Seed generation then fell back to a software method drawing from predictable device information, including the Coldcard serial number and internal clock registers or boot timing. Because those values were not cryptographically secure sources of randomness, an attacker could generate possible seeds until one produced a public address matching the intended target.
    Attackers did not need to touch the affected Coldcard. A visible Bitcoin address, wallet descriptor or exported public key could provide enough information to test candidate seeds. Once a candidate generated the same address as the victim’s wallet, the attacker could derive the corresponding private key and authorize transactions.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. Earliest copy held
    seen 1 Aug 2026, 02:53 UTC · Captured here text sha256 91b086b2630d2c70d3a09027 13,349 chars
    Extracted text as captured
    Dex
    News
    NewsNewsletter
    Learn
    How ToCrypto GlossaryTop ListsReviews
    About
    About Coin360AuthorsWidgetsMethodologyPartners
    Swap
    USD
    News/Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain
    Coldcard Flaws Expose Bitcoin Wallets After $38 Million Drain
    Van Thanh Le
    •
    PublishedJul 31 2026
    •
    UpdatedJul 31 2026
    15 hours ago4 minutes read
    Predictable seed generation put multiple hardware-wallet generations at risk
    TL;DR
    Coinkite warned on July 30, 2026, that affected Coldcard devices could generate predictable Bitcoin seeds, enabling remote theft without physical access.
    Attackers drained 594.48 BTC, valued at about $38.3 million, from roughly 500 single-signature wallets during a 25-minute sweep.
    Block identified two entropy weaknesses affecting older and newer Coldcard generations, while Peter Todd urged greater use of multisignature custody and independently reviewed systems.
    Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
    Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
    Trade on Jupiter!
    Coldcard hardware-wallet flaws allowed attackers to reconstruct weak Bitcoin seeds and drain 594.48 BTC from roughly 500 single-signature wallets, according to findings disclosed by Coldcard maker Coinkite and Block after the July 30, 2026, theft. The confirmed loss was valued at about $38.3 million, while additional transactions identified by Block raised the preliminary potential exposure beyond the amount directly tied to the main sweep.
    Coinkite issued an urgent security advisory after learning that Bitcoin seeds generated by affected Coldcard firmware could be predictable. The weakness meant attackers could derive private keys remotely without obtaining the physical hardware wallet. The incident centered on failures in entropy generation, the process that supplies the unpredictable randomness used to create a wallet’s seed phrase.
    The main theft occurred between 01:31 and 01:56 UTC on July 30, when the attacker emptied the identified wallets across a period of about 25 minutes. The targeted wallets reportedly held more than 0.15 BTC each, and many had remained inactive for years. Coins connected to affected wallet activity dated from 2021 through 2026.
    Rob Hamilton, CEO of AnchorWatch, said he tracked 1,324 spent transaction outputs across 500 transactions completed within three Bitcoin blocks. Hamilton also said approximately 562 BTC from the theft was later consolidated into a single Bitcoin address.
    Measurement Amount Status
    Main wallet sweep 594.48 BTC Confirmed theft total
    Estimated dollar value About $38.3 million Value at the time
    Earlier matching transactions 488.11 BTC Under investigation
    Combined preliminary exposure 1,082.59 BTC Not fully confirmed by Coinkite
    Block security engineer Clay Garrett identified 695 earlier transactions carrying the same apparent on-chain fingerprint as the confirmed thefts. Those transactions moved another 488.11 BTC. If all were connected to the same exploitation campaign, Block’s preliminary estimate would raise the potentially stolen total to 1,082.59 BTC. Coinkite had not confirmed that every suspected transaction resulted from the disclosed firmware flaws, leaving the larger total unresolved.
    Firmware flaw weakened Coldcard seed generation
    Block’s Bitcoin engineering and security teams began investigating after receiving reports of remotely stolen Bitcoin from wallets unrelated to Block’s Bitkey product. The investigation linked the affected wallets to Coldcard devices and identified two separate weaknesses in the process used to generate wallet seeds.
    Older Coldcard firmware contained the more serious flaw. On affected Mk2 and Mk3 devices, a firmware configuration disabled the built-in hardware random number generator. A supporting software library checked whether the RNG configuration existed but did not verify that the RNG was actually enabled.
    Seed generation then fell back to a software method drawing from predictable device information, including the Coldcard serial number and internal clock registers or boot timing. Because those values were not cryptographically secure sources of randomness, an attacker could generate possible seeds until one produced a public address matching the intended target.
    Attackers did not need to touch the affected Coldcard. A visible Bitcoin address, wallet descriptor or exported public key could provide enough information to test candidate seeds. Once a candidate generated the same address as the victim’s wallet, the attacker could derive the corresponding private key and authorize transactions.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

Each copy above is identified by the SHA-256 of its extracted text, shown beside it, and the diffs are plain unified diffs. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.