COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

7 August update: $111M confirmed, 1,719 BTC, 25+ patterns

glxyresearch-2085748513015488758

https://x.com/glxyresearch/status/2085748513015488758

Captured screenshot of the post by @glxyresearch, posted 7 Aug 2026, 23:59 UTC
@glxyresearch posted captured full-size capture → original post →

Latest reviewed change

source content difference between and

A new reply from jordanschochet links the Galaxy report's Aug 6 date to a Kalshi self-certification change and alleges a separate Kalshi hack; an unrelated ad reply also re-entered the capture.

seen +39 -0 full history below
 media: 0
 body:
 multiple actors is a bigger finding than the total. does the footprint clustering separate distinct actors, or just distinct sweep sessions?
+
+post: 2087106875112522093
+role: reply
+author: ryoran_ads
+name: 百花繚乱 剣姫クロニクル_デベロッパー

First lines only. The complete diff is in the timeline below.

Author
@glxyresearch
Organisation
Galaxy Research
Evidence role
on-chain-analysis
Posted
Capture status
capture held

Galaxy Research 7 August 2026 update: $111 million confirmed stolen so far, 1,719 BTC with high confidence, 25+ separate attack patterns, 250+ victim reports to @intangiblecoins, no stolen coin created before the 17 March 2021 affected-firmware release. This supersedes the 1,596 BTC / ~7,300 address figure in glxy-losses-exceed-100m and is the basis for the state-changed flags on the 8 August 2026 claim sweep.

This post is registered as evidence and has a locally held capture. The original remains the canonical publication. Last checked .

The conversation

Captured . 5 continuation posts, 9 replies held, 3 muted as low signal. Posts are in the archive's own order, oldest first, not the order X ranks them in.

  1. @glxyresearch the registered post 7 Aug 2026, 15:22 UTC
    Captured screenshot of the post by @glxyresearch

    capture taken

  2. @glxyresearch same author, continuing 7 Aug 2026, 15:22 UTC
    Captured screenshot of the post by @glxyresearch

    capture taken

  3. @glxyresearch same author, continuing 7 Aug 2026, 15:22 UTC
    Captured screenshot of the post by @glxyresearch

    capture taken

  4. @glxyresearch same author, continuing 7 Aug 2026, 15:22 UTC
    Captured screenshot of the post by @glxyresearch

    capture taken

  5. @glxyresearch same author, continuing 7 Aug 2026, 15:22 UTC also held as its own record
    Captured screenshot of the post by @glxyresearch

    capture taken

  6. @glxyresearch same author, continuing 7 Aug 2026, 15:22 UTC also held as its own record
    Captured screenshot of the post by @glxyresearch

    capture taken

Replies are unmoderated third-party material, reproduced here as part of the record. Inclusion is not endorsement, and nothing in them has been checked by this project.
Replies held in this capture (9)

Low-signal replies are collapsed to one line, never removed. A reply is collapsed only on mechanical grounds: fewer than 40 characters, no text, mentions only, no letters or digits, a bare link, or text identical to another reply in the same capture. What a reply argues is never a reason. Each one says which rule collapsed it, and its screenshot is one click away.

  1. @Hiraweb3 7 Aug 2026, 15:46 UTC under 40 characters
    another day another exploit
    show the capture Captured screenshot of the reply by @Hiraweb3

    capture taken

  2. @4QAST 7 Aug 2026, 16:08 UTC under 40 characters
    This is getting out of control
    show the capture Captured screenshot of the reply by @4QAST

    capture taken

  3. Captured screenshot of the reply by @FixTheMoneyBTC

    capture taken

  4. @shiftfdn 7 Aug 2026, 19:12 UTC under 40 characters
    devastating to say the least
    show the capture Captured screenshot of the reply by @shiftfdn

    capture taken

  5. @ostrag_w 7 Aug 2026, 22:05 UTC
    Captured screenshot of the reply by @ostrag_w

    capture taken

  6. Captured screenshot of the reply by @mikexchain

    capture taken

  7. Captured screenshot of the reply by @romanwagmi

    capture taken

  8. Captured screenshot of the reply by @FramiaPro

    capture taken

  9. Captured screenshot of the reply by @jordanschochet

    capture taken

This capture reached the end of the conversation as X served it: it stopped because nothing further loaded, not because a limit was hit. X decides what a reader is shown, so that is not the same as a guarantee of every reply.

  1. source content difference between and source content +39 -0

    A new reply from jordanschochet links the Galaxy report's Aug 6 date to a Kalshi self-certification change and alleges a separate Kalshi hack; an unrelated ad reply also re-entered the capture.

    seen · Captured here 5,053 chars
    What changed from the previous capture 39 lines
     media: 0
     body:
     multiple actors is a bigger finding than the total. does the footprint clustering separate distinct actors, or just distinct sweep sessions?
    +
    +post: 2087106875112522093
    +role: reply
    +author: ryoran_ads
    +name: 百花繚乱 剣姫クロニクル_デベロッパー
    +created: 
    +media: 0
    +body:
    +No download, free to play
    +
    +W-What are you looking at! Fool!
    +Claim $600 of Items Now
    +
    +post: 2088417554997903807
    +role: reply
    +author: jordanschochet
    +name: Jordan Schochet
    +created: 2026-08-15T00:08:40Z
    +media: 0
    +body:
    +@glxyresearch
    + this is highly speculative..but I have been posting about what appears to be a BAD hack hitting Kalshi (see my profile). 
    +
    +The Aug 6 date in your report caught my attention- happens to be the date Kalshi self certified a bizarre change re allowing advanced deposits to Kalshi before on-chain confirmation. And in prior posts I shared clear evidence of Kalshi reporting Perp data that is 100% wrong. Kalshi prime reports $50mm of net capital, which would aline with the wave 1 attack aum. 
    +https://
    +kalshi.com/prime
    +
    +"Re: Kalshi Klear LLC – Additional Method to Enable Self-Clearing Members to Receive Pre-funded Amounts of In-Transit USDC Deposits Before On-chain Confirmation of Funds"
    +
    +https://
    +kalshi.com/regulatory/not
    +ices
    +…
    +pdf below
    +
    +https://
    +kalshi-public-docs.s3.amazonaws.com/regulatory/not
    +ices/COVER%20LETTER-Additional%20Method%20to%20Deposit%20U.S.%20Dollars%208.6.26.pdf
    +…
    
    Extracted text as captured
    thread: 2085748513015488758
    url: https://x.com/glxyresearch/status/2085748513015488758
    author: glxyresearch
    
    post: 2085748513015488758
    role: focal
    author: glxyresearch
    name: Galaxy Research
    created: 2026-08-07T15:22:51Z
    media: 1
    body:
    $111 MILLION CONFIRMED STOLEN SO FAR IN COLDCARD EXPLOIT
    
    Thanks to victim reports, we can confirm with high confidence that 1719 BTC has been stolen from Coldcard victims so far
    
    We have many more coins we are vetting for confirmation - we think total losses likely exceed $130m
    
    post: 2085748519625707727
    role: self-thread
    author: glxyresearch
    name: Galaxy Research
    created: 2026-08-07T15:22:53Z
    media: 1
    body:
    We are tracking more than 25 separate attack patterns including Waves 1, 2, and 3. It’s obvious now that multiple different threat actors are actively exploiting the vulnerability.
    
    post: 2085748526034690520
    role: self-thread
    author: glxyresearch
    name: Galaxy Research
    created: 2026-08-07T15:22:54Z
    media: 1
    body:
    Not one stolen coin was created onchain prior to the March 17, 2021 release of the affected Coldcard firmware.
    
    There is NO evidence at this time that this bug affects other signing devices or wallets beyond: Coldcard Mk3, Mk4, Mk5, or Q operating on firmware released after March 17, 2021
    
    post: 2085748532208656819
    role: self-thread
    author: glxyresearch

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. Earliest copy held
    seen · Captured here 3,828 chars
    Extracted text as captured
    thread: 2085748513015488758
    url: https://x.com/glxyresearch/status/2085748513015488758
    author: glxyresearch
    
    post: 2085748513015488758
    role: focal
    author: glxyresearch
    name: Galaxy Research
    created: 2026-08-07T15:22:51Z
    media: 1
    body:
    $111 MILLION CONFIRMED STOLEN SO FAR IN COLDCARD EXPLOIT
    
    Thanks to victim reports, we can confirm with high confidence that 1719 BTC has been stolen from Coldcard victims so far
    
    We have many more coins we are vetting for confirmation - we think total losses likely exceed $130m
    
    post: 2085748519625707727
    role: self-thread
    author: glxyresearch
    name: Galaxy Research
    created: 2026-08-07T15:22:53Z
    media: 1
    body:
    We are tracking more than 25 separate attack patterns including Waves 1, 2, and 3. It’s obvious now that multiple different threat actors are actively exploiting the vulnerability.
    
    post: 2085748526034690520
    role: self-thread
    author: glxyresearch
    name: Galaxy Research
    created: 2026-08-07T15:22:54Z
    media: 1
    body:
    Not one stolen coin was created onchain prior to the March 17, 2021 release of the affected Coldcard firmware.
    
    There is NO evidence at this time that this bug affects other signing devices or wallets beyond: Coldcard Mk3, Mk4, Mk5, or Q operating on firmware released after March 17, 2021
    
    post: 2085748532208656819
    role: self-thread
    author: glxyresearch

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.