COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Coldcard Wallet Bitcoin Theft: Legal Options for Victims

stoltmann-claimant-page

https://stoltmannlaw.com/coldcard-wallet-bitcoin-theft-claims/

Organisation
Stoltmann Law
Evidence role
Reporting
Published
2026-07-31
Source changes
0
Detected differences
0
Unreviewed
0
Copies held
1

Law firm claimant-intake page soliciting COLDCARD incident victims as potential claimants; self-labels as legal advertising. Surfaced during the 4 Aug 2026 claim-sweep recheck (Internet Archive snapshot of 3 Aug 2026); it is the law firm's claimant page the scams page previously recorded as reported but uncaptured. Client solicitation after a mass loss event is ordinary legal marketing, not itself a scam; held for provenance of the report, not endorsed. Browser capture: the site answers plain scripted fetches with a challenge page.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. Earliest copy held Current
    seen · Captured here 14,223 chars
    Extracted text as captured
    Published On: July 31, 2026
    
    If Bitcoin disappeared from a wallet whose seed was generated on an affected Coldcard device, protect any remaining assets, preserve the device and transaction records, and obtain legal and forensic guidance promptly. Depending on the facts, a victim may have claims involving warranty, negligence, misrepresentation, consumer-protection law, or a defective product but no claim or recovery is automatic.
    
    Key Takeaways
    Public reporting connected a rapid sweep of approximately 594 Bitcoin from roughly 500 wallets to a reported Coldcard random-number-generation flaw. The investigation remains ongoing, and the dollar value changes with Bitcoin’s price.
    Exposure depends primarily on the device model and the firmware used when the seed was created—not simply the firmware installed today.
    Installing fixed firmware protects newly generated seeds but does not repair a seed created under affected firmware. Coinkite advises generating a new seed and migrating funds.
    A legal evaluation must connect the alleged defect to the unauthorized transactions, account for other possible attack methods, and examine the governing purchase terms and applicable law.
    
    What Was Reported About the Coldcard Wallet Vulnerability?
    
    Coldcard hardware wallets are designed to keep Bitcoin private keys offline. That security model depends on a wallet seed being generated with enough cryptographic randomness that no attacker can realistically guess it. In late July 2026, Coinkite disclosed that a series of software-integration errors prevented the intended hardware random-number generator from contributing properly in certain firmware versions.
    
    According to Coinkite’s updated technical backgrounder and migration guidance, the affected code path used a software fallback rather than the intended hardware source. Coinkite estimated that the effective search space was substantially below its intended 128-bit target, with different levels of risk across device generations.
    
    Block’s Bitcoin Engineering and Security team independently analyzed the firmware and reported that the fallback could make seed generation reproducible under certain conditions. Block cautioned that practical exploitation depends on variables such as device identifiers, timing state, prior random-number calls, and derivation cost.
    
    Public reporting associated the issue with a July 31, 2026 sweep of approximately 594 Bitcoin from roughly 500 single-signature wallets in about 25 minutes. These reports and the technical investigation are developing. No court has yet made findings about legal responsibility, causation, or damages.
    
    Which Coldcard Devices and Seeds May Be Affected?
    
    As of Coinkite’s July 31, 2026 update, users were advised to review the model and firmware that generated the seed. The manufacturer identified the following affected ranges unless sufficient independent dice entropy was added when the seed was created:
    
    Mk3: seeds generated on firmware versions 4.0.1 through 4.1.9.
    Mk4 and Mk5: seeds generated before standard firmware 5.6.0 or Edge firmware 6.6.0X.
    Coldcard Q: seeds generated before standard firmware 1.5.0Q or Edge firmware 6.6.0QX.
    
    Coinkite stated that TAPSIGNER, OPENDIME, and SATSCARD use different codebases and are not affected by this issue. It also stated that at least 50 fair, independent, private dice rolls added during seed creation may supply sufficient independent entropy. A strong BIP-39 passphrase can add a separate barrier, but a Coldcard PIN is not the same thing, and a weak or reused passphrase may be guessable.
    
    The key question is when and how the seed was generated. Moving the same seed to a different hardware wallet does not cure weak seed generation because the underlying private keys remain derived from that original seed.
    
    Why a Firmware Update Alone Does Not Fix an Existing Seed
    
    A firmware update can correct the process used to create future seeds. It cannot add randomness retroactively to a seed that already exists. Coinkite therefore advises affected users to install the fixed firmware for their model, create a completely new seed, verify the new backup and receive address, send a small test transaction, and only then transfer the remaining balance.
    
    Users should follow the current official instructions rather than improvising. A hurried migration can create a second loss through an incorrect address, an unverified backup, a lost passphrase, or disclosure of the seed to a fraudulent support service. Never enter seed words or a passphrase into a website or give them to anyone claiming they can check whether a wallet is vulnerable.
    
    What Should You Do If Bitcoin Was Stolen?
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.