The Missing 153: what followed the Wave 1 reconstruction
praveenperera-missing-153
https://praveenperera.com/blog/coldcard-wave1-missing-153-search/
- Organisation
- unknown
- Evidence role
- Independent primary analysis
- Published
- 2026-08-14
- Source changes
- 0
- Detected differences
- 0
- Unreviewed
- 0
- Copies held
- 1
Praveen Perera's follow-up to his Wave 1 key-reconstruction work: what he tried against the final 153 unreconstructed addresses, checked against the published Galaxy victim lists. First-person account of independent reproduction work, carrying the post's own warning that it is an investigation record rather than a wallet-recovery guide.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
Blog Blog The Missing 153: What I Tried After Reconstructing Coldcard Wave 1 Praveen Perera August 14, 2026 20 min read bitcoin, security, coldcard, rng, entropy, forensics Edit on GitHub Affected users: Updating firmware does not repair a seed that affected firmware already generated. Read the official COLDCARD advisory and replace the affected seed before you use the wallet again. This post explains an investigation. It is not a wallet-recovery guide. Since I published Inside Wave 1, several researchers have asked what I have tried to recover the seeds behind the final 153 addresses. I should have included more of that work in the original post. I summarized the search with a few examples and aggregate numbers, but that summary left out many of the hypotheses, completed searches, and useful negative results. This post is a supplement to the original Wave 1 reconstruction. It records what I tested, what each search found, and why I stopped. I also want to clarify one line from the original post. My reference to a “private dataset” could have suggested a specific source, which I did not intend. I meant information that is not available in the public code or hardware schematics. Someone with an affected device, or experience with and access to the relevant STM32 chips, could collect it. I tested many PRNG paths and address derivations, but I may still have missed one. Most researchers working on this are focused on Bitcoin, so we may share a blind spot. I have also said that the attacker may have been more familiar with account-based systems such as Ethereum than with Bitcoin wallet software. That background may have led them to approach the problem differently. This is another reason for this post. By showing the paths I tested and where each search stopped, I hope someone will see a path, input, or assumption that I missed. The 153 missing addresses remain an important clue. I still do not know what they mean. None of these tests recovered a seed behind the 153. The repeated failures are hard to reconcile with the simple search that found the rest of Wave 1. I now consider these explanations possible but highly unlikely. The strongest new evidence concerns passphrases. A scan of all 2,048 lowercase BIP39 words across 1,014 recovered mnemonics found 74 historically funded passphrase addresses holding 32.77836472 BTC immediately before Wave 1. Wave 1 took the empty-passphrase wallets from those same seeds but left every passphrase address untouched. A broader scan then checked 83,035 common passphrases against the same 1,014 mnemonics. It found 97 funded addresses, but none belonged to Wave 1. These results make common passphrases an unlikely explanation for the missing 153. Something is probably still missing from the way I model the attacker’s seed search. What I tried Wider Bitcoin wallet paths: I searched higher indexes, change addresses, more accounts, and wrapped SegWit. The searches found affected wallets and reproduced known Wave 1 seeds, but found none of the 153. Other Coldcard setup sequences: I tested settings saves, migration, login-keypad changes, countdowns, erased state, and nine other sequences. They found real affected wallets and known Wave 1 seeds, but none of the 153. Added dice rolls: One-roll and two-roll searches found historically funded seeds outside Wave 1. A wider partial search also found funded seeds, but no tested dice result belonged to Wave 1. Larger pad ranges: I tested higher pad groups and samples from the full 32-bit range. The searches either found nothing or reproduced seeds I already knew. None found one of the 153. Other wallets from recovered seeds: I checked wider BIP44, BIP49, and BIP84 paths, BIP85 children, the Coldcard duress path, Samourai paths, Wasabi use, and known weak passphrases. None produced one of the 153. BIP39 and common passphrases: I tested every lowercase English BIP39 word and a reviewed list of 83,035 common passphrases on all 1,014 recovered mnemonics. Both searches found funded addresses, but none matched any of the 153 unresolved Wave 1 addresses. The remaining possibilities are listed with the reasons I have not searched every combination and why most are now unlikely. The starting point Wave 1 contains 1,195 traceable source addresses and 1,082.65318922 BTC. Reconstructed seeds explain 1,042 of those addresses and 949.70395260 BTC: The remaining 153 sources hold 132.94923662 BTC. Holding 3 has most of that value: 67.13366772 BTC in 53 sources. Of these sources, 149 use native SegWit and four use wrapped SegWit. Their theft transactions do not look different from the rest of Wave 1. All 153 use the same one-source, one-output format and fee rule. The difference must come before transaction creation: the attacker’s seed search, device state, wallet paths, or choice of targets. The public CSV contains the 153 addresses, their script types, Wave 1 branches, sweep heights, input counts, and swept values. Here, “unresolved” means that none of the recovered seeds produced the source address on the paths I tested. The transactions and addresses themselves are not in doubt. What a negative result means I used two types of search. One replayed the weak Coldcard RNG to look for unknown seeds. The other started from recovered seeds and checked related wallets, such as other accounts, BIP85 children, duress wallets, Samourai paths, and passphrase wallets. The first type can find a new seed, but only within the device states and wallet paths tested. The second cannot find a new root seed, but it shows what the attacker probably checked after finding one. This is why the passphrase result is useful. Wider Bitcoin derivation paths I tested whether the 153 were on common wallet paths but farther from the usual first address. These searches still found affected wallets outside Wave 1 and reproduced known Wave 1 seeds, so the search itself was working. None found one of the 153. A wrong account, branch, or index is now an unlikely general explanation. The main unknown-seed search models Coldcard 4.0.0+ with its membrane keypad, a zero RTC state, no added dice rolls, and the normal pad range. A keypad count is the number of keypad scan sessions before seed generation. It is usually, but not always, the same as the number of button presses. I completed these wallet paths: Address type Branch Accounts IndexesExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.