COLDCARD vulnerability what happened, and what to do
Informational only, and this site never asks for your recovery words. details

Informational only. This is independent analysis and an evidence-backed explainer, not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite, Block, or any other party named here. Published estimates are attributed, and differing scenarios are kept separate with their assumptions. Act on your own judgement. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it. Deliberate recovery on independently verified offline equipment is a separate operation. Seed-word safety.

Bitcoin Optech Newsletter #416

optech-416

https://bitcoinops.org/en/newsletters/2026/07/31/

Organisation
Bitcoin Optech
Evidence role
Secondary analysis
Published
2026-07-31
Source changes
0
Detected differences
0
Unreviewed
0
Copies held
1

Newsletter #416 led with the incident. It carries the unitemised estimate 'exceed 1,000 BTC' and dates the theft transactions to 29 July, possibly consistent with a US-local date; the newsletter does not state a timezone.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked 2 Aug 2026, 01:00 UTC.

  1. Earliest copy held Current
    seen 1 Aug 2026, 02:53 UTC · Captured here text sha256 a20c49857b87591d83bc0088 16,723 chars
    Extracted text as captured
    About
    Publications
    Topics
    Workshops
    Matrix
    en
    | ja
    | es
    | cs
    | hi
    | zh
    | de
    | fr
    | pt
    / home / newsletters /
    Bitcoin Optech Newsletter #416
    Jul 31, 2026
    This week’s newsletter warns about a severe vulnerability affecting wallets
    generated by COLDCARD signing devices, summarizes the disclosure of two
    denial-of-service vulnerabilities in Core Lightning, and describes a proof of
    concept for a zero-knowledge proof of reserves. Also included are our regular
    sections with selected questions and answers from the Bitcoin Stack Exchange,
    announcements of new releases and release candidates, and descriptions of
    notable changes to popular Bitcoin infrastructure software.
    Action items
    ● Move funds secured by COLDCARD-generated keys: if you used a
    COLDCARD Mk3 to generate a wallet, any funds received by that wallet
    are at risk of theft and should be carefully moved to an unaffected
    wallet as soon as possible. Wallets generated by other COLDCARD
    models may also be affected. See the News section below for details.
    News
    ● Wallets generated by COLDCARD at risk of theft:
    On 30 July 2026, some Bitcoin users discovered that funds from their COLDCARD
    wallets had been stolen in a series of unexpected transactions on 29 July.
    Over the course of the day, a bug was identified in the firmware of the
    COLDCARD Mk3 that causes wallets to be generated with insufficient
    entropy. As of this writing, estimated losses exceed 1,000 BTC, a figure
    that may continue to rise as the situation develops.
    A security advisory by Coinkite identified wallets
    generated by COLDCARD Mk3 using firmware version 4.0.1 (March 2021) or later,

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

Each copy above is identified by the SHA-256 of its extracted text, shown beside it, and the diffs are plain unified diffs. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.