COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

COLDCARD funds flow monitor

coldcard-watch

https://coldcardwatch.com/

Latest reviewed change

source content difference between and

Verified drained total rose from 1,366.5774 to 1,405.0671 BTC and verified drained addresses from 4,580 to 4,925. The site also renamed itself from Coldcard Sweep Watch to Coldcard Watch and split its view filter into Verified, Attested and Suspected.

seen +11 -5 full history below
-Coldcard Sweep Watch
+Coldcard Watch
 DashboardAddress listMethodology
 live
 Bitcoin Drained from Coldcards
-1,366.5774BTC
+1,405.0671BTC
 $71,048,000at $62,949 per bitcoin

First lines only. The complete diff is in the timeline below.

Organisation
community tracker
Evidence role
Chain monitor
Published
continuously updated
Source changes
10
Detected differences
10
Unreviewed
0
Copies held
11

The tracker expanded on 1 Aug from the first 1,195-address episode to two episodes totalling 2,321 addresses and 1,128.4717 BTC. It includes a browser-local address checker and follows spends from the consolidation addresses hop by hop. It labels the first episode 29 July without stating a timezone; the corresponding on-chain window begins 30 July at 01:10 UTC. Operator anonymous; figures cross-check against Galaxy's published map for the first episode. The original host, coldcard-watch.vercel.app, stopped resolving at 21:43 UTC on 3 Aug 2026; the same tracker (identical page, headline and last-drain figures) was found serving at coldcardwatch.com on 4 Aug 2026 and the registry URL moved with it.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +11 -5

    Verified drained total rose from 1,366.5774 to 1,405.0671 BTC and verified drained addresses from 4,580 to 4,925. The site also renamed itself from Coldcard Sweep Watch to Coldcard Watch and split its view filter into Verified, Attested and Suspected.

    seen · Captured here 4,041 chars
    What changed from the previous capture 16 lines
    -Coldcard Sweep Watch
    +Coldcard Watch
     DashboardAddress listMethodology
     live
     Bitcoin Drained from Coldcards
    -1,366.5774BTC
    +1,405.0671BTC
     $71,048,000at $62,949 per bitcoin
     Left of this line is the drain window on 30 and 31 July. Right of it is real time since. The two halves are drawn at different scales, so the drains stay visible against days of holding.
    +BTC
    +block
    +mined
    +addresses drained
    +view block
     0d 00h 00m 00suntouched for
     275blocks mined since
     960,466chain tip
     View:
    -Confirmed
    -Potential
    +Verified
    +Attested
    +Suspected
     These are verified minimums, not totals. Every figure here comes from clusters that
     have been identified and checked transaction by transaction. Other attackers are working the same
     flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
     0.00993644BTC
     taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
     31 July 2026, 08:36:17 UTCblock 960,369view transaction
    -4,580
    +4,925
     addresses drained, verified
     view the full list
     The last address drained, on 31 July. 237 other addresses were drained in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    
    Extracted text as captured
    Coldcard Watch
    DashboardAddress listMethodology
    live
    Bitcoin Drained from Coldcards
    1,405.0671BTC
    $71,048,000at $62,949 per bitcoin
    Left of this line is the drain window on 30 and 31 July. Right of it is real time since. The two halves are drawn at different scales, so the drains stay visible against days of holding.
    BTC
    block
    mined
    addresses drained
    view block
    0d 00h 00m 00suntouched for
    275blocks mined since
    960,466chain tip
    View:
    Verified
    Attested
    Suspected
    These are verified minimums, not totals. Every figure here comes from clusters that
    have been identified and checked transaction by transaction. Other attackers are working the same
    flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
    How these addresses were identified
    Is an address in the set?
    Every address confirmed drained is published in full on the address list. Open it and filter that public list to see whether an address appears. These are on-chain addresses anyone can verify on a block explorer; this page has no form and collects nothing.
    Never type a seed phrase, private key, or passphrase into any website. No legitimate tool asks for one.
    Most recent drain
    0.00993644BTC
    taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
    31 July 2026, 08:36:17 UTCblock 960,369view transaction
    4,925
    addresses drained, verified
    view the full list
    The last address drained, on 31 July. 237 other addresses were drained in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    Where the money is
    The six addresses the drains paid into. Nothing has left them.
    Coins have moved. The rows below now include the addresses they went to.
    Balances refresh every 60 seconds and stream over a websocket in between. If any tracked address spends, this page reads where the coins went and starts tracking those addresses too, following the trail one hop at a time. The headline figure only ever counts coins traced back to the theft, so a destination wallet holding other funds cannot inflate it.
    Is your Coldcard affected?
    Seeds generated on the firmware below were built with far less randomness than intended. Find your model and compare against the version you generated your seed on.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +4 -6

    First capture at the new coldcardwatch.com domain after the vercel.app host stopped resolving. The tracker replaced its browser-local address-checker form with a published full address list ('Is an address in the set? ... this page has no form and collects nothing') and changed its footer to 'Independent security research'. The headline figure is unchanged at 1,366.5774 BTC across 4,580 addresses.

    seen · Captured here 3,994 chars
    What changed from the previous capture 10 lines
     have been identified and checked transaction by transaction. Other attackers are working the same
     flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
     How these addresses were identified
    -Was your address drained?
    -Paste a public bitcoin address to check it against the 4,580 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
    -Check
    -The set covers three clusters: 1,195 addresses on 30 July (blocks 960183 to 960191), 1,126 on 31 July (blocks 960345 to 960369), and 13 more later that day (block 960455). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
    -Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
    +Is an address in the set?
    +Every address confirmed drained is published in full on the address list. Open it and filter that public list to see whether an address appears. These are on-chain addresses anyone can verify on a block explorer; this page has no form and collects nothing.
    +Never type a seed phrase, private key, or passphrase into any website. No legitimate tool asks for one.
     Most recent drain
     0.00993644BTC
     taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
     Updating the firmware does not repair a seed that already exists. If your seed was generated on an affected version, the fix is to move your funds to a newly generated wallet.
     Two things reduce the risk. Coinkite say 50 to 98 of your own private dice rolls contributed at least 128 bits on their own, and 99 or more about 256 bits; below 50, or if you cannot remember, they say migrate. A strong BIP-39 passphrase reduces the immediate exposure but does not repair the seed, so passphrase users are told to migrate as well. On fixed firmware dice rolls are optional and the device seed is enough. Their advisory is the authority on what to do, not this page.
     Balances stream from mempool.space and Blockstream Esplora. Incident detail from the Coinkite advisory and Block's engineering analysis.
    -Not affiliated with Coinkite. If you hold a Coldcard, follow the vendor advisory and move to a new seed rather than relying on anything here.
    +Independent security research. Not affiliated with Coinkite or Coldcard. If you hold a Coldcard, follow the vendor advisory and move to a new seed rather than relying on anything here.
    
    Extracted text as captured
    Coldcard Sweep Watch
    DashboardAddress listMethodology
    live
    Bitcoin Drained from Coldcards
    1,366.5774BTC
    $71,048,000at $62,949 per bitcoin
    Left of this line is the drain window on 30 and 31 July. Right of it is real time since. The two halves are drawn at different scales, so the drains stay visible against days of holding.
    0d 00h 00m 00suntouched for
    275blocks mined since
    960,466chain tip
    View:
    Confirmed
    Potential
    These are verified minimums, not totals. Every figure here comes from clusters that
    have been identified and checked transaction by transaction. Other attackers are working the same
    flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
    How these addresses were identified
    Is an address in the set?
    Every address confirmed drained is published in full on the address list. Open it and filter that public list to see whether an address appears. These are on-chain addresses anyone can verify on a block explorer; this page has no form and collects nothing.
    Never type a seed phrase, private key, or passphrase into any website. No legitimate tool asks for one.
    Most recent drain
    0.00993644BTC
    taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
    31 July 2026, 08:36:17 UTCblock 960,369view transaction
    4,580
    addresses drained, verified
    view the full list
    The last address drained, on 31 July. 237 other addresses were drained in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    Where the money is
    The six addresses the drains paid into. Nothing has left them.
    Coins have moved. The rows below now include the addresses they went to.
    Balances refresh every 60 seconds and stream over a websocket in between. If any tracked address spends, this page reads where the coins went and starts tracking those addresses too, following the trail one hop at a time. The headline figure only ever counts coins traced back to the theft, so a destination wallet holding other funds cannot inflate it.
    Is your Coldcard affected?
    Seeds generated on the firmware below were built with far less randomness than intended. Find your model and compare against the version you generated your seed on.
    Two details here go further than Coinkite’s advisory, both checked against their own signed release manifest. Their advisory bounds the Mk3 at 4.1.9, but signed Mk3 builds 5.0.1 and 5.0.3 shipped in 2022, after the change that caused this, and Coinkite has not said whether those are affected; they are listed as at risk because that is the safer reading. Block traces the fault to a 4.0.0 tag, but no 4.0.0 firmware was ever distributed, so 4.0.1 is the first version anyone could have generated a seed on.
    Coinkite emailed affected customers directly, and said so publicly on 2 August so people could tell a real message from a fake one. Treat any email, DM or call about this that asks for a seed phrase as an attack. Nobody legitimate needs it, and an incident like this draws people who will ask.
    Updating the firmware does not repair a seed that already exists. If your seed was generated on an affected version, the fix is to move your funds to a newly generated wallet.
    Two things reduce the risk. Coinkite say 50 to 98 of your own private dice rolls contributed at least 128 bits on their own, and 99 or more about 256 bits; below 50, or if you cannot remember, they say migrate. A strong BIP-39 passphrase reduces the immediate exposure but does not repair the seed, so passphrase users are told to migrate as well. On fixed firmware dice rolls are optional and the device seed is enough. Their advisory is the authority on what to do, not this page.
    Balances stream from mempool.space and Blockstream Esplora. Incident detail from the Coinkite advisory and Block's engineering analysis.
    Independent security research. Not affiliated with Coinkite or Coldcard. If you hold a Coldcard, follow the vendor advisory and move to a new seed rather than relying on anything here.
  3. source content difference between and source content +3 -0

    Added a View switcher with Confirmed and Potential options above the verified-minimums disclaimer, so the tracker now separates confirmed clusters from potential ones. The headline figures and disclaimer text were unchanged.

    seen · Captured here 4,226 chars
    What changed from the previous capture 3 lines
     0d 00h 00m 00suntouched for
     275blocks mined since
     960,466chain tip
    +View:
    +Confirmed
    +Potential
     These are verified minimums, not totals. Every figure here comes from clusters that
     have been identified and checked transaction by transaction. Other attackers are working the same
     flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
    
    Extracted text as captured
    Coldcard Sweep Watch
    DashboardAddress listMethodology
    live
    Bitcoin Drained from Coldcards
    1,366.5774BTC
    $71,048,000at $62,949 per bitcoin
    Left of this line is the drain window on 30 and 31 July. Right of it is real time since. The two halves are drawn at different scales, so the drains stay visible against days of holding.
    0d 00h 00m 00suntouched for
    275blocks mined since
    960,466chain tip
    View:
    Confirmed
    Potential
    These are verified minimums, not totals. Every figure here comes from clusters that
    have been identified and checked transaction by transaction. Other attackers are working the same
    flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
    How these addresses were identified
    Was your address drained?
    Paste a public bitcoin address to check it against the 4,580 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
    Check
    The set covers three clusters: 1,195 addresses on 30 July (blocks 960183 to 960191), 1,126 on 31 July (blocks 960345 to 960369), and 13 more later that day (block 960455). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
    Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
    Most recent drain
    0.00993644BTC
    taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
    31 July 2026, 08:36:17 UTCblock 960,369view transaction
    4,580
    addresses drained, verified
    view the full list
    The last address drained, on 31 July. 237 other addresses were drained in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    Where the money is
    The six addresses the drains paid into. Nothing has left them.
    Coins have moved. The rows below now include the addresses they went to.
    Balances refresh every 60 seconds and stream over a websocket in between. If any tracked address spends, this page reads where the coins went and starts tracking those addresses too, following the trail one hop at a time. The headline figure only ever counts coins traced back to the theft, so a destination wallet holding other funds cannot inflate it.
    Is your Coldcard affected?
    Seeds generated on the firmware below were built with far less randomness than intended. Find your model and compare against the version you generated your seed on.
    Two details here go further than Coinkite’s advisory, both checked against their own signed release manifest. Their advisory bounds the Mk3 at 4.1.9, but signed Mk3 builds 5.0.1 and 5.0.3 shipped in 2022, after the change that caused this, and Coinkite has not said whether those are affected; they are listed as at risk because that is the safer reading. Block traces the fault to a 4.0.0 tag, but no 4.0.0 firmware was ever distributed, so 4.0.1 is the first version anyone could have generated a seed on.
    Coinkite emailed affected customers directly, and said so publicly on 2 August so people could tell a real message from a fake one. Treat any email, DM or call about this that asks for a seed phrase as an attack. Nobody legitimate needs it, and an incident like this draws people who will ask.
    Updating the firmware does not repair a seed that already exists. If your seed was generated on an affected version, the fix is to move your funds to a newly generated wallet.
    Two things reduce the risk. Coinkite say 50 to 98 of your own private dice rolls contributed at least 128 bits on their own, and 99 or more about 256 bits; below 50, or if you cannot remember, they say migrate. A strong BIP-39 passphrase reduces the immediate exposure but does not repair the seed, so passphrase users are told to migrate as well. On fixed firmware dice rolls are optional and the device seed is enough. Their advisory is the authority on what to do, not this page.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +3 -3

    The tracker's headline moved from 1,359.1829 BTC across 4,312 verified addresses to 1,366.5774 BTC across 4,580, and its address-check copy changed with it. The cluster description of three windows on 30 and 31 July was unchanged.

    seen · Captured here 4,200 chars
    What changed from the previous capture 6 lines
     DashboardAddress listMethodology
     live
     Bitcoin Drained from Coldcards
    -1,359.1829BTC
    +1,366.5774BTC
     $71,048,000at $62,949 per bitcoin
     Left of this line is the drain window on 30 and 31 July. Right of it is real time since. The two halves are drawn at different scales, so the drains stay visible against days of holding.
     0d 00h 00m 00suntouched for
     flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
     How these addresses were identified
     Was your address drained?
    -Paste a public bitcoin address to check it against the 4,312 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
    +Paste a public bitcoin address to check it against the 4,580 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
     Check
     The set covers three clusters: 1,195 addresses on 30 July (blocks 960183 to 960191), 1,126 on 31 July (blocks 960345 to 960369), and 13 more later that day (block 960455). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
     Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
     0.00993644BTC
     taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
     31 July 2026, 08:36:17 UTCblock 960,369view transaction
    -4,312
    +4,580
     addresses drained, verified
     view the full list
     The last address drained, on 31 July. 237 other addresses were drained in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    
    Extracted text as captured
    Coldcard Sweep Watch
    DashboardAddress listMethodology
    live
    Bitcoin Drained from Coldcards
    1,366.5774BTC
    $71,048,000at $62,949 per bitcoin
    Left of this line is the drain window on 30 and 31 July. Right of it is real time since. The two halves are drawn at different scales, so the drains stay visible against days of holding.
    0d 00h 00m 00suntouched for
    275blocks mined since
    960,466chain tip
    These are verified minimums, not totals. Every figure here comes from clusters that
    have been identified and checked transaction by transaction. Other attackers are working the same
    flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
    How these addresses were identified
    Was your address drained?
    Paste a public bitcoin address to check it against the 4,580 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
    Check
    The set covers three clusters: 1,195 addresses on 30 July (blocks 960183 to 960191), 1,126 on 31 July (blocks 960345 to 960369), and 13 more later that day (block 960455). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
    Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
    Most recent drain
    0.00993644BTC
    taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
    31 July 2026, 08:36:17 UTCblock 960,369view transaction
    4,580
    addresses drained, verified
    view the full list
    The last address drained, on 31 July. 237 other addresses were drained in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    Where the money is
    The six addresses the drains paid into. Nothing has left them.
    Coins have moved. The rows below now include the addresses they went to.
    Balances refresh every 60 seconds and stream over a websocket in between. If any tracked address spends, this page reads where the coins went and starts tracking those addresses too, following the trail one hop at a time. The headline figure only ever counts coins traced back to the theft, so a destination wallet holding other funds cannot inflate it.
    Is your Coldcard affected?
    Seeds generated on the firmware below were built with far less randomness than intended. Find your model and compare against the version you generated your seed on.
    Two details here go further than Coinkite’s advisory, both checked against their own signed release manifest. Their advisory bounds the Mk3 at 4.1.9, but signed Mk3 builds 5.0.1 and 5.0.3 shipped in 2022, after the change that caused this, and Coinkite has not said whether those are affected; they are listed as at risk because that is the safer reading. Block traces the fault to a 4.0.0 tag, but no 4.0.0 firmware was ever distributed, so 4.0.1 is the first version anyone could have generated a seed on.
    Coinkite emailed affected customers directly, and said so publicly on 2 August so people could tell a real message from a fake one. Treat any email, DM or call about this that asks for a seed phrase as an attack. Nobody legitimate needs it, and an incident like this draws people who will ask.
    Updating the firmware does not repair a seed that already exists. If your seed was generated on an affected version, the fix is to move your funds to a newly generated wallet.
    Two things reduce the risk. Coinkite say 50 to 98 of your own private dice rolls contributed at least 128 bits on their own, and 99 or more about 256 bits; below 50, or if you cannot remember, they say migrate. A strong BIP-39 passphrase reduces the immediate exposure but does not repair the seed, so passphrase users are told to migrate as well. On fixed firmware dice rolls are optional and the device seed is enough. Their advisory is the authority on what to do, not this page.
    Balances stream from mempool.space and Blockstream Esplora. Incident detail from the Coinkite advisory and Block's engineering analysis.
    Not affiliated with Coinkite. If you hold a Coldcard, follow the vendor advisory and move to a new seed rather than relying on anything here.
  5. source content difference between and source content +3 -3

    The tracker rewrote its affected-firmware notes, saying signed Mk3 builds 5.0.1 and 5.0.3 shipped after the change that caused the fault and are listed as at risk, and that 4.0.1 is the first distributed vulnerable version. It added that Coinkite emailed affected customers on 2 August with a phishing warning, and expanded the dice-roll and passphrase guidance with Coinkite's bit-strength figures.

    seen · Captured here 4,200 chars
    What changed from the previous capture 6 lines
     Balances refresh every 60 seconds and stream over a websocket in between. If any tracked address spends, this page reads where the coins went and starts tracking those addresses too, following the trail one hop at a time. The headline figure only ever counts coins traced back to the theft, so a destination wallet holding other funds cannot inflate it.
     Is your Coldcard affected?
     Seeds generated on the firmware below were built with far less randomness than intended. Find your model and compare against the version you generated your seed on.
    -Coinkite\u2019s advisory covers the Mk3 and newer. The Mk2 entry comes from Block\u2019s engineering analysis, which found the same vulnerable path and no secure reseed on that model, and no patched firmware for it has been published. Coinkite dates the Mk3 exposure from 4.0.1 while Block traces it to 4.0.0; the wider range is shown here.
    -\n
    +Two details here go further than Coinkite’s advisory, both checked against their own signed release manifest. Their advisory bounds the Mk3 at 4.1.9, but signed Mk3 builds 5.0.1 and 5.0.3 shipped in 2022, after the change that caused this, and Coinkite has not said whether those are affected; they are listed as at risk because that is the safer reading. Block traces the fault to a 4.0.0 tag, but no 4.0.0 firmware was ever distributed, so 4.0.1 is the first version anyone could have generated a seed on.
    +Coinkite emailed affected customers directly, and said so publicly on 2 August so people could tell a real message from a fake one. Treat any email, DM or call about this that asks for a seed phrase as an attack. Nobody legitimate needs it, and an incident like this draws people who will ask.
     Updating the firmware does not repair a seed that already exists. If your seed was generated on an affected version, the fix is to move your funds to a newly generated wallet.
    -Two things reduce the risk: adding 50 or more of your own dice rolls during seed generation, and a strong BIP-39 passphrase. Coinkite still recommends migrating. Their advisory is the authority on what to do, not this page.
    +Two things reduce the risk. Coinkite say 50 to 98 of your own private dice rolls contributed at least 128 bits on their own, and 99 or more about 256 bits; below 50, or if you cannot remember, they say migrate. A strong BIP-39 passphrase reduces the immediate exposure but does not repair the seed, so passphrase users are told to migrate as well. On fixed firmware dice rolls are optional and the device seed is enough. Their advisory is the authority on what to do, not this page.
     Balances stream from mempool.space and Blockstream Esplora. Incident detail from the Coinkite advisory and Block's engineering analysis.
     Not affiliated with Coinkite. If you hold a Coldcard, follow the vendor advisory and move to a new seed rather than relying on anything here.
    
    Extracted text as captured
    Coldcard Sweep Watch
    DashboardAddress listMethodology
    live
    Bitcoin Drained from Coldcards
    1,359.1829BTC
    $71,048,000at $62,949 per bitcoin
    Left of this line is the drain window on 30 and 31 July. Right of it is real time since. The two halves are drawn at different scales, so the drains stay visible against days of holding.
    0d 00h 00m 00suntouched for
    275blocks mined since
    960,466chain tip
    These are verified minimums, not totals. Every figure here comes from clusters that
    have been identified and checked transaction by transaction. Other attackers are working the same
    flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
    How these addresses were identified
    Was your address drained?
    Paste a public bitcoin address to check it against the 4,312 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
    Check
    The set covers three clusters: 1,195 addresses on 30 July (blocks 960183 to 960191), 1,126 on 31 July (blocks 960345 to 960369), and 13 more later that day (block 960455). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
    Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
    Most recent drain
    0.00993644BTC
    taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
    31 July 2026, 08:36:17 UTCblock 960,369view transaction
    4,312
    addresses drained, verified
    view the full list
    The last address drained, on 31 July. 237 other addresses were drained in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    Where the money is
    The six addresses the drains paid into. Nothing has left them.
    Coins have moved. The rows below now include the addresses they went to.
    Balances refresh every 60 seconds and stream over a websocket in between. If any tracked address spends, this page reads where the coins went and starts tracking those addresses too, following the trail one hop at a time. The headline figure only ever counts coins traced back to the theft, so a destination wallet holding other funds cannot inflate it.
    Is your Coldcard affected?
    Seeds generated on the firmware below were built with far less randomness than intended. Find your model and compare against the version you generated your seed on.
    Two details here go further than Coinkite’s advisory, both checked against their own signed release manifest. Their advisory bounds the Mk3 at 4.1.9, but signed Mk3 builds 5.0.1 and 5.0.3 shipped in 2022, after the change that caused this, and Coinkite has not said whether those are affected; they are listed as at risk because that is the safer reading. Block traces the fault to a 4.0.0 tag, but no 4.0.0 firmware was ever distributed, so 4.0.1 is the first version anyone could have generated a seed on.
    Coinkite emailed affected customers directly, and said so publicly on 2 August so people could tell a real message from a fake one. Treat any email, DM or call about this that asks for a seed phrase as an attack. Nobody legitimate needs it, and an incident like this draws people who will ask.
    Updating the firmware does not repair a seed that already exists. If your seed was generated on an affected version, the fix is to move your funds to a newly generated wallet.
    Two things reduce the risk. Coinkite say 50 to 98 of your own private dice rolls contributed at least 128 bits on their own, and 99 or more about 256 bits; below 50, or if you cannot remember, they say migrate. A strong BIP-39 passphrase reduces the immediate exposure but does not repair the seed, so passphrase users are told to migrate as well. On fixed firmware dice rolls are optional and the device seed is enough. Their advisory is the authority on what to do, not this page.
    Balances stream from mempool.space and Blockstream Esplora. Incident detail from the Coinkite advisory and Block's engineering analysis.
    Not affiliated with Coinkite. If you hold a Coldcard, follow the vendor advisory and move to a new seed rather than relying on anything here.
  6. source content difference between and source content +3 -3

    The tracker's headline moved from 1,158.8480 BTC across 2,686 verified addresses to 1,359.1829 BTC across 4,312, and its address-check copy changed with it. The cluster description of three windows on 30 and 31 July was unchanged.

    seen · Captured here 3,483 chars
    What changed from the previous capture 6 lines
     DashboardAddress listMethodology
     live
     Bitcoin Drained from Coldcards
    -1,158.8480BTC
    +1,359.1829BTC
     $71,048,000at $62,949 per bitcoin
     Left of this line is the drain window on 30 and 31 July. Right of it is real time since. The two halves are drawn at different scales, so the drains stay visible against days of holding.
     0d 00h 00m 00suntouched for
     flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
     How these addresses were identified
     Was your address drained?
    -Paste a public bitcoin address to check it against the 2,686 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
    +Paste a public bitcoin address to check it against the 4,312 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
     Check
     The set covers three clusters: 1,195 addresses on 30 July (blocks 960183 to 960191), 1,126 on 31 July (blocks 960345 to 960369), and 13 more later that day (block 960455). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
     Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
     0.00993644BTC
     taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
     31 July 2026, 08:36:17 UTCblock 960,369view transaction
    -2,686
    +4,312
     addresses drained, verified
     view the full list
     The last address drained, on 31 July. 237 other addresses were drained in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    
    Extracted text as captured
    Coldcard Sweep Watch
    DashboardAddress listMethodology
    live
    Bitcoin Drained from Coldcards
    1,359.1829BTC
    $71,048,000at $62,949 per bitcoin
    Left of this line is the drain window on 30 and 31 July. Right of it is real time since. The two halves are drawn at different scales, so the drains stay visible against days of holding.
    0d 00h 00m 00suntouched for
    275blocks mined since
    960,466chain tip
    These are verified minimums, not totals. Every figure here comes from clusters that
    have been identified and checked transaction by transaction. Other attackers are working the same
    flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
    How these addresses were identified
    Was your address drained?
    Paste a public bitcoin address to check it against the 4,312 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
    Check
    The set covers three clusters: 1,195 addresses on 30 July (blocks 960183 to 960191), 1,126 on 31 July (blocks 960345 to 960369), and 13 more later that day (block 960455). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
    Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
    Most recent drain
    0.00993644BTC
    taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
    31 July 2026, 08:36:17 UTCblock 960,369view transaction
    4,312
    addresses drained, verified
    view the full list
    The last address drained, on 31 July. 237 other addresses were drained in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    Where the money is
    The six addresses the drains paid into. Nothing has left them.
    Coins have moved. The rows below now include the addresses they went to.
    Balances refresh every 60 seconds and stream over a websocket in between. If any tracked address spends, this page reads where the coins went and starts tracking those addresses too, following the trail one hop at a time. The headline figure only ever counts coins traced back to the theft, so a destination wallet holding other funds cannot inflate it.
    Is your Coldcard affected?
    Seeds generated on the firmware below were built with far less randomness than intended. Find your model and compare against the version you generated your seed on.
    Coinkite\u2019s advisory covers the Mk3 and newer. The Mk2 entry comes from Block\u2019s engineering analysis, which found the same vulnerable path and no secure reseed on that model, and no patched firmware for it has been published. Coinkite dates the Mk3 exposure from 4.0.1 while Block traces it to 4.0.0; the wider range is shown here.
    \n
    Updating the firmware does not repair a seed that already exists. If your seed was generated on an affected version, the fix is to move your funds to a newly generated wallet.
    Two things reduce the risk: adding 50 or more of your own dice rolls during seed generation, and a strong BIP-39 passphrase. Coinkite still recommends migrating. Their advisory is the authority on what to do, not this page.
    Balances stream from mempool.space and Blockstream Esplora. Incident detail from the Coinkite advisory and Block's engineering analysis.
    Not affiliated with Coinkite. If you hold a Coldcard, follow the vendor advisory and move to a new seed rather than relying on anything here.
  7. source content difference between and source content +3 -3

    The tracker's headline moved from 1,128.6633 BTC across 2,334 verified addresses to 1,158.8480 BTC across 2,686, and its address-check copy changed with it. The cluster description of three windows on 30 and 31 July was unchanged.

    seen · Captured here 3,483 chars
    What changed from the previous capture 6 lines
     DashboardAddress listMethodology
     live
     Bitcoin Drained from Coldcards
    -1,128.6633BTC
    +1,158.8480BTC
     $71,048,000at $62,949 per bitcoin
     Left of this line is the drain window on 30 and 31 July. Right of it is real time since. The two halves are drawn at different scales, so the drains stay visible against days of holding.
     0d 00h 00m 00suntouched for
     flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
     How these addresses were identified
     Was your address drained?
    -Paste a public bitcoin address to check it against the 2,334 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
    +Paste a public bitcoin address to check it against the 2,686 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
     Check
     The set covers three clusters: 1,195 addresses on 30 July (blocks 960183 to 960191), 1,126 on 31 July (blocks 960345 to 960369), and 13 more later that day (block 960455). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
     Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
     0.00993644BTC
     taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
     31 July 2026, 08:36:17 UTCblock 960,369view transaction
    -2,334
    +2,686
     addresses drained, verified
     view the full list
     The last address drained, on 31 July. 237 other addresses were drained in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    
    Extracted text as captured
    Coldcard Sweep Watch
    DashboardAddress listMethodology
    live
    Bitcoin Drained from Coldcards
    1,158.8480BTC
    $71,048,000at $62,949 per bitcoin
    Left of this line is the drain window on 30 and 31 July. Right of it is real time since. The two halves are drawn at different scales, so the drains stay visible against days of holding.
    0d 00h 00m 00suntouched for
    275blocks mined since
    960,466chain tip
    These are verified minimums, not totals. Every figure here comes from clusters that
    have been identified and checked transaction by transaction. Other attackers are working the same
    flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
    How these addresses were identified
    Was your address drained?
    Paste a public bitcoin address to check it against the 2,686 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
    Check
    The set covers three clusters: 1,195 addresses on 30 July (blocks 960183 to 960191), 1,126 on 31 July (blocks 960345 to 960369), and 13 more later that day (block 960455). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
    Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
    Most recent drain
    0.00993644BTC
    taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
    31 July 2026, 08:36:17 UTCblock 960,369view transaction
    2,686
    addresses drained, verified
    view the full list
    The last address drained, on 31 July. 237 other addresses were drained in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    Where the money is
    The six addresses the drains paid into. Nothing has left them.
    Coins have moved. The rows below now include the addresses they went to.
    Balances refresh every 60 seconds and stream over a websocket in between. If any tracked address spends, this page reads where the coins went and starts tracking those addresses too, following the trail one hop at a time. The headline figure only ever counts coins traced back to the theft, so a destination wallet holding other funds cannot inflate it.
    Is your Coldcard affected?
    Seeds generated on the firmware below were built with far less randomness than intended. Find your model and compare against the version you generated your seed on.
    Coinkite\u2019s advisory covers the Mk3 and newer. The Mk2 entry comes from Block\u2019s engineering analysis, which found the same vulnerable path and no secure reseed on that model, and no patched firmware for it has been published. Coinkite dates the Mk3 exposure from 4.0.1 while Block traces it to 4.0.0; the wider range is shown here.
    \n
    Updating the firmware does not repair a seed that already exists. If your seed was generated on an affected version, the fix is to move your funds to a newly generated wallet.
    Two things reduce the risk: adding 50 or more of your own dice rolls during seed generation, and a strong BIP-39 passphrase. Coinkite still recommends migrating. Their advisory is the authority on what to do, not this page.
    Balances stream from mempool.space and Blockstream Esplora. Incident detail from the Coinkite advisory and Block's engineering analysis.
    Not affiliated with Coinkite. If you hold a Coldcard, follow the vendor advisory and move to a new seed rather than relying on anything here.
  8. source content difference between and source content +4 -3

    The tracker moved from two episodes to three clusters by adding 13 addresses in block 960455, changed the destination set from four addresses to six, revised the same-block count for the last drained address from 250 to 237, and added an explanatory note about the two-scale timeline.

    seen · Captured here 3,483 chars
    What changed from the previous capture 7 lines
     Bitcoin Drained from Coldcards
     1,128.6633BTC
     $71,048,000at $62,949 per bitcoin
    +Left of this line is the drain window on 30 and 31 July. Right of it is real time since. The two halves are drawn at different scales, so the drains stay visible against days of holding.
     0d 00h 00m 00suntouched for
     275blocks mined since
     960,466chain tip
     Was your address drained?
     Paste a public bitcoin address to check it against the 2,334 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
     Check
    -The set covers both episodes: 1,195 addresses on 30 July (blocks 960183 to 960191) and a further 1,126 on 31 July (blocks 960345 to 960369). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
    +The set covers three clusters: 1,195 addresses on 30 July (blocks 960183 to 960191), 1,126 on 31 July (blocks 960345 to 960369), and 13 more later that day (block 960455). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
     Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
     Most recent drain
     0.00993644BTC
     2,334
     addresses drained, verified
     view the full list
    -The last address drained, in a second episode on 31 July. 250 others fell in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    +The last address drained, on 31 July. 237 other addresses were drained in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
     Where the money is
    -The four addresses the sweep paid into. Nothing has left them.
    +The six addresses the drains paid into. Nothing has left them.
     Coins have moved. The rows below now include the addresses they went to.
     Balances refresh every 60 seconds and stream over a websocket in between. If any tracked address spends, this page reads where the coins went and starts tracking those addresses too, following the trail one hop at a time. The headline figure only ever counts coins traced back to the theft, so a destination wallet holding other funds cannot inflate it.
     Is your Coldcard affected?
    
    Extracted text as captured
    Coldcard Sweep Watch
    DashboardAddress listMethodology
    live
    Bitcoin Drained from Coldcards
    1,128.6633BTC
    $71,048,000at $62,949 per bitcoin
    Left of this line is the drain window on 30 and 31 July. Right of it is real time since. The two halves are drawn at different scales, so the drains stay visible against days of holding.
    0d 00h 00m 00suntouched for
    275blocks mined since
    960,466chain tip
    These are verified minimums, not totals. Every figure here comes from clusters that
    have been identified and checked transaction by transaction. Other attackers are working the same
    flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
    How these addresses were identified
    Was your address drained?
    Paste a public bitcoin address to check it against the 2,334 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
    Check
    The set covers three clusters: 1,195 addresses on 30 July (blocks 960183 to 960191), 1,126 on 31 July (blocks 960345 to 960369), and 13 more later that day (block 960455). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
    Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
    Most recent drain
    0.00993644BTC
    taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
    31 July 2026, 08:36:17 UTCblock 960,369view transaction
    2,334
    addresses drained, verified
    view the full list
    The last address drained, on 31 July. 237 other addresses were drained in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    Where the money is
    The six addresses the drains paid into. Nothing has left them.
    Coins have moved. The rows below now include the addresses they went to.
    Balances refresh every 60 seconds and stream over a websocket in between. If any tracked address spends, this page reads where the coins went and starts tracking those addresses too, following the trail one hop at a time. The headline figure only ever counts coins traced back to the theft, so a destination wallet holding other funds cannot inflate it.
    Is your Coldcard affected?
    Seeds generated on the firmware below were built with far less randomness than intended. Find your model and compare against the version you generated your seed on.
    Coinkite\u2019s advisory covers the Mk3 and newer. The Mk2 entry comes from Block\u2019s engineering analysis, which found the same vulnerable path and no secure reseed on that model, and no patched firmware for it has been published. Coinkite dates the Mk3 exposure from 4.0.1 while Block traces it to 4.0.0; the wider range is shown here.
    \n
    Updating the firmware does not repair a seed that already exists. If your seed was generated on an affected version, the fix is to move your funds to a newly generated wallet.
    Two things reduce the risk: adding 50 or more of your own dice rolls during seed generation, and a strong BIP-39 passphrase. Coinkite still recommends migrating. Their advisory is the authority on what to do, not this page.
    Balances stream from mempool.space and Blockstream Esplora. Incident detail from the Coinkite advisory and Block's engineering analysis.
    Not affiliated with Coinkite. If you hold a Coldcard, follow the vendor advisory and move to a new seed rather than relying on anything here.
  9. source content difference between and source content +11 -6

    The tracker added dashboard, address-list and methodology navigation, described its figures as verified minimums and a floor rather than totals, and changed its checkable address set from 2,321 to 2,334.

    seen · Captured here 3,268 chars
    What changed from the previous capture 17 lines
     Coldcard Sweep Watch
    -connecting
    +DashboardAddress listMethodology
    +live
     Bitcoin Drained from Coldcards
    -1,128.4717BTC
    -$71,036,000at $62,949 per bitcoin
    +1,128.6633BTC
    +$71,048,000at $62,949 per bitcoin
     0d 00h 00m 00suntouched for
     275blocks mined since
     960,466chain tip
    +These are verified minimums, not totals. Every figure here comes from clusters that
    +have been identified and checked transaction by transaction. Other attackers are working the same
    +flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
    +How these addresses were identified
     Was your address drained?
    -Paste a public bitcoin address to check it against the 2,321 addresses drained across both episodes. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
    +Paste a public bitcoin address to check it against the 2,334 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
     Check
     The set covers both episodes: 1,195 addresses on 30 July (blocks 960183 to 960191) and a further 1,126 on 31 July (blocks 960345 to 960369). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
     Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
     0.00993644BTC
     taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
     31 July 2026, 08:36:17 UTCblock 960,369view transaction
    -2,321
    -total addresses drained
    +2,334
    +addresses drained, verified
     view the full list
     The last address drained, in a second episode on 31 July. 250 others fell in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
     Where the money is
    
    Extracted text as captured
    Coldcard Sweep Watch
    DashboardAddress listMethodology
    live
    Bitcoin Drained from Coldcards
    1,128.6633BTC
    $71,048,000at $62,949 per bitcoin
    0d 00h 00m 00suntouched for
    275blocks mined since
    960,466chain tip
    These are verified minimums, not totals. Every figure here comes from clusters that
    have been identified and checked transaction by transaction. Other attackers are working the same
    flaw with their own patterns, and undiscovered clusters are near certain. Treat this as a floor.
    How these addresses were identified
    Was your address drained?
    Paste a public bitcoin address to check it against the 2,334 addresses confirmed drained so far. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
    Check
    The set covers both episodes: 1,195 addresses on 30 July (blocks 960183 to 960191) and a further 1,126 on 31 July (blocks 960345 to 960369). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
    Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
    Most recent drain
    0.00993644BTC
    taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
    31 July 2026, 08:36:17 UTCblock 960,369view transaction
    2,334
    addresses drained, verified
    view the full list
    The last address drained, in a second episode on 31 July. 250 others fell in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    Where the money is
    The four addresses the sweep paid into. Nothing has left them.
    Coins have moved. The rows below now include the addresses they went to.
    Balances refresh every 60 seconds and stream over a websocket in between. If any tracked address spends, this page reads where the coins went and starts tracking those addresses too, following the trail one hop at a time. The headline figure only ever counts coins traced back to the theft, so a destination wallet holding other funds cannot inflate it.
    Is your Coldcard affected?
    Seeds generated on the firmware below were built with far less randomness than intended. Find your model and compare against the version you generated your seed on.
    Coinkite\u2019s advisory covers the Mk3 and newer. The Mk2 entry comes from Block\u2019s engineering analysis, which found the same vulnerable path and no secure reseed on that model, and no patched firmware for it has been published. Coinkite dates the Mk3 exposure from 4.0.1 while Block traces it to 4.0.0; the wider range is shown here.
    \n
    Updating the firmware does not repair a seed that already exists. If your seed was generated on an affected version, the fix is to move your funds to a newly generated wallet.
    Two things reduce the risk: adding 50 or more of your own dice rolls during seed generation, and a strong BIP-39 passphrase. Coinkite still recommends migrating. Their advisory is the authority on what to do, not this page.
    Balances stream from mempool.space and Blockstream Esplora. Incident detail from the Coinkite advisory and Block's engineering analysis.
    Not affiliated with Coinkite. If you hold a Coldcard, follow the vendor advisory and move to a new seed rather than relying on anything here.
  10. source content difference between and source content +9 -9

    The tracker expanded from the first 1,195-address episode to two episodes totalling 2,321 addresses and changed its headline from 1,082.5696 BTC to 1,128.4717 BTC.

    seen · Captured here 2,926 chars
    What changed from the previous capture 18 lines
     Coldcard Sweep Watch
     connecting
     Bitcoin Drained from Coldcards
    -1,082.5696BTC
    -$68,146,000at $62,949 per bitcoin
    +1,128.4717BTC
    +$71,036,000at $62,949 per bitcoin
     0d 00h 00m 00suntouched for
     275blocks mined since
     960,466chain tip
     Was your address drained?
    -Paste a public bitcoin address to check it against the 1,195 addresses drained in this sweep. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
    +Paste a public bitcoin address to check it against the 2,321 addresses drained across both episodes. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
     Check
    -The set covers every address drained between 01:10:20 and 01:51:26 UTC on 30 July 2026, blocks 960183 to 960191. In US time zones that window fell on the evening of Wednesday 29 July, which is why some accounts date the theft to the 29th. No drains outside that window have been published, and the four addresses below have taken in nothing since.
    +The set covers both episodes: 1,195 addresses on 30 July (blocks 960183 to 960191) and a further 1,126 on 31 July (blocks 960345 to 960369). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
     Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
     Most recent drain
    -0.15694687BTC
    -taken from bc1qysdng7zm6sqwqjgjmyg8880mvlw56tkaw65gw4
    -30 July 2026, 01:51:26 UTCblock 960,191view transaction
    -1,195
    +0.00993644BTC
    +taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
    +31 July 2026, 08:36:17 UTCblock 960,369view transaction
    +2,321
     total addresses drained
     view the full list
    -The last address drained in the sweep. 158 others were drained in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    +The last address drained, in a second episode on 31 July. 250 others fell in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
     Where the money is
     The four addresses the sweep paid into. Nothing has left them.
     Coins have moved. The rows below now include the addresses they went to.
    
    Extracted text as captured
    Coldcard Sweep Watch
    connecting
    Bitcoin Drained from Coldcards
    1,128.4717BTC
    $71,036,000at $62,949 per bitcoin
    0d 00h 00m 00suntouched for
    275blocks mined since
    960,466chain tip
    Was your address drained?
    Paste a public bitcoin address to check it against the 2,321 addresses drained across both episodes. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
    Check
    The set covers both episodes: 1,195 addresses on 30 July (blocks 960183 to 960191) and a further 1,126 on 31 July (blocks 960345 to 960369). The first window fell on the evening of Wednesday 29 July in US time zones, which is why some accounts date the theft to the 29th.
    Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
    Most recent drain
    0.00993644BTC
    taken from bc1qelcnp9m9qh5r2su986d8kdkmdc9grlsujc8uuv
    31 July 2026, 08:36:17 UTCblock 960,369view transaction
    2,321
    total addresses drained
    view the full list
    The last address drained, in a second episode on 31 July. 250 others fell in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    Where the money is
    The four addresses the sweep paid into. Nothing has left them.
    Coins have moved. The rows below now include the addresses they went to.
    Balances refresh every 60 seconds and stream over a websocket in between. If any tracked address spends, this page reads where the coins went and starts tracking those addresses too, following the trail one hop at a time. The headline figure only ever counts coins traced back to the theft, so a destination wallet holding other funds cannot inflate it.
    Is your Coldcard affected?
    Seeds generated on the firmware below were built with far less randomness than intended. Find your model and compare against the version you generated your seed on.
    Coinkite\u2019s advisory covers the Mk3 and newer. The Mk2 entry comes from Block\u2019s engineering analysis, which found the same vulnerable path and no secure reseed on that model, and no patched firmware for it has been published. Coinkite dates the Mk3 exposure from 4.0.1 while Block traces it to 4.0.0; the wider range is shown here.
    \n
    Updating the firmware does not repair a seed that already exists. If your seed was generated on an affected version, the fix is to move your funds to a newly generated wallet.
    Two things reduce the risk: adding 50 or more of your own dice rolls during seed generation, and a strong BIP-39 passphrase. Coinkite still recommends migrating. Their advisory is the authority on what to do, not this page.
    Balances stream from mempool.space and Blockstream Esplora. Incident detail from the Coinkite advisory and Block's engineering analysis.
    Not affiliated with Coinkite. If you hold a Coldcard, follow the vendor advisory and move to a new seed rather than relying on anything here.
  11. Earliest copy held
    seen · Captured here 2,984 chars
    Extracted text as captured
    Coldcard Sweep Watch
    connecting
    Bitcoin Drained from Coldcards
    1,082.5696BTC
    $68,146,000at $62,949 per bitcoin
    0d 00h 00m 00suntouched for
    275blocks mined since
    960,466chain tip
    Was your address drained?
    Paste a public bitcoin address to check it against the 1,195 addresses drained in this sweep. The check runs entirely inside your browser against a hashed list. Nothing is sent anywhere and nothing is logged.
    Check
    The set covers every address drained between 01:10:20 and 01:51:26 UTC on 30 July 2026, blocks 960183 to 960191. In US time zones that window fell on the evening of Wednesday 29 July, which is why some accounts date the theft to the 29th. No drains outside that window have been published, and the four addresses below have taken in nothing since.
    Never type a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
    Most recent drain
    0.15694687BTC
    taken from bc1qysdng7zm6sqwqjgjmyg8880mvlw56tkaw65gw4
    30 July 2026, 01:51:26 UTCblock 960,191view transaction
    1,195
    total addresses drained
    view the full list
    The last address drained in the sweep. 158 others were drained in the same block. How many people that adds up to is not knowable from the chain, since one wallet can hold many addresses.
    Where the money is
    The four addresses the sweep paid into. Nothing has left them.
    Coins have moved. The rows below now include the addresses they went to.
    Balances refresh every 60 seconds and stream over a websocket in between. If any tracked address spends, this page reads where the coins went and starts tracking those addresses too, following the trail one hop at a time. The headline figure only ever counts coins traced back to the theft, so a destination wallet holding other funds cannot inflate it.
    Is your Coldcard affected?
    Seeds generated on the firmware below were built with far less randomness than intended. Find your model and compare against the version you generated your seed on.
    Coinkite\u2019s advisory covers the Mk3 and newer. The Mk2 entry comes from Block\u2019s engineering analysis, which found the same vulnerable path and no secure reseed on that model, and no patched firmware for it has been published. Coinkite dates the Mk3 exposure from 4.0.1 while Block traces it to 4.0.0; the wider range is shown here.
    \n
    Updating the firmware does not repair a seed that already exists. If your seed was generated on an affected version, the fix is to move your funds to a newly generated wallet.
    Two things reduce the risk: adding 50 or more of your own dice rolls during seed generation, and a strong BIP-39 passphrase. Coinkite still recommends migrating. Their advisory is the authority on what to do, not this page.
    Balances stream from mempool.space and Blockstream Esplora. Incident detail from the Coinkite advisory and Block's engineering analysis.
    Not affiliated with Coinkite. If you hold a Coldcard, follow the vendor advisory and move to a new seed rather than relying on anything here.
How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.