COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

COLDCARD hardware wallet flaw

web3isgoinggreat-incident-entry

https://www.web3isgoinggreat.com/single/coldcard-hardware-wallet-flaw

Latest reviewed change

source content difference between and

The entry raised its loss figure from more than 1,367 BTC (about $89 million) to more than 2,000 BTC (about $130 million), restated the body as at least 2,055 BTC (about $130 million), added Galaxy Research's estimate of 15 unique attacker groups, and added a link to the Galaxy Research tweet thread.

seen +4 -3 full history below
 Threads
 Go to full timeline
 July 31, 2026
-Coldcard hardware wallet flaw sees more than 1,367 BTC (~$89 million) drained across thousands of wallets
+Coldcard hardware wallet flaw sees more than 2,000 BTC (~$130 million) drained across thousands of wallets
 Coldcard logo (attribution)
-Thousands of users of a hardware wallet called Coldcard, a physical device developed by the Canadian Coinkite firm to allow bitcoin holders to store their bitcoin on a device that's not connected to the internet, have suffered more than 1,367 BTC (~$89 million) in combined losses after thieves began exploiting a flaw with the wallet firmware's seed phrase generation. A 2021 version of the device firmware, which affects a wide range of Coldcard devices, skipped the device's more secure hardware randomness generator and instead fell back to generating seed phrases with random numbers seeded from the device's serial number and clock registers. The resulting seed phrases are relatively trivially guessed, and hackers have been methodically draining vulnerable wallets as researchers warn that all vulnerable Coldcard devices will be drained soon if their owners do not move assets to secure wallets.
-An estimated 1,367 BTC (~$89 million) and counting has been drained in the two days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Subsequent attacks have seen funds moved to around 600 attacker wallets, according to Galaxy Research, although the number of unique attackers is not clear at this point, and attackers regularly use multiple wallets to make tracing stolen funds more challenging.

First lines only. The complete diff is in the timeline below.

Organisation
Web3 is Going Just Great
Evidence role
Reporting
Published
not established
Source changes
1
Detected differences
1
Unreviewed
0
Copies held
2

A stable incident-database entry with independent framing and outbound archive links. Held as a compact secondary chronology and discovery aid, not as a substitute for the primary publications it cites. Its summary and loss figure are the publisher's own.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +4 -3

    The entry raised its loss figure from more than 1,367 BTC (about $89 million) to more than 2,000 BTC (about $130 million), restated the body as at least 2,055 BTC (about $130 million), added Galaxy Research's estimate of 15 unique attacker groups, and added a link to the Galaxy Research tweet thread.

    seen · Captured here 2,853 chars
    What changed from the previous capture 7 lines
     Threads
     Go to full timeline
     July 31, 2026
    -Coldcard hardware wallet flaw sees more than 1,367 BTC (~$89 million) drained across thousands of wallets
    +Coldcard hardware wallet flaw sees more than 2,000 BTC (~$130 million) drained across thousands of wallets
     Coldcard logo (attribution)
    -Thousands of users of a hardware wallet called Coldcard, a physical device developed by the Canadian Coinkite firm to allow bitcoin holders to store their bitcoin on a device that's not connected to the internet, have suffered more than 1,367 BTC (~$89 million) in combined losses after thieves began exploiting a flaw with the wallet firmware's seed phrase generation. A 2021 version of the device firmware, which affects a wide range of Coldcard devices, skipped the device's more secure hardware randomness generator and instead fell back to generating seed phrases with random numbers seeded from the device's serial number and clock registers. The resulting seed phrases are relatively trivially guessed, and hackers have been methodically draining vulnerable wallets as researchers warn that all vulnerable Coldcard devices will be drained soon if their owners do not move assets to secure wallets.
    -An estimated 1,367 BTC (~$89 million) and counting has been drained in the two days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Subsequent attacks have seen funds moved to around 600 attacker wallets, according to Galaxy Research, although the number of unique attackers is not clear at this point, and attackers regularly use multiple wallets to make tracing stolen funds more challenging.
    +Thousands of users of a hardware wallet called Coldcard, a physical device developed by the Canadian Coinkite firm to allow bitcoin holders to store their bitcoin on a device that's not connected to the internet, have suffered at least 2,055 BTC (~$130 million) in combined losses after thieves began exploiting a flaw with the wallet firmware's seed phrase generation. A 2021 version of the device firmware, which affects a wide range of Coldcard devices, skipped the device's more secure hardware randomness generator and instead fell back to generating seed phrases with random numbers seeded from the device's serial number and clock registers. The resulting seed phrases are relatively trivially guessed, and hackers have been methodically draining vulnerable wallets as researchers warn that all vulnerable Coldcard devices will be drained soon if their owners do not move assets to secure wallets.
    +An estimated 2,055 BTC (~$130 million) and counting has been drained in the days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Attacks have come from an estimated 15 unique groups, according to Galaxy Research.
     Hardware wallets are often used by more security conscious users, or those with more significant sums of money at risk, because the lack of internet connection makes the devices less vulnerable to phishing or malware-based attacks. However, if a wallet seed phrase can be obtained by an attacker, the lack of internet connection is no barrier to theft. Coldcard describes itself as "ultra-secure", and its website is filled with reviews describing the product as "one of the most secure Bitcoin hardware wallets ever built".
     "Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets", Decrypt [archive]
     "Major bitcoin wallet flaw drains $38 million worth of BTC in 25-minute sweep", CoinDesk [archive]
    +Tweet thread by Galaxy Research
     Theme tags: Hack or scam
     Blockchain tags: Blockchain: Bitcoin
     Text is licensed under a Creative Commons Attribution 3.0 Unported License. All attribution can be found on the attribution page.
    
    Extracted text as captured
    HomeAboutWhat is web3?FAQLicenseTwitterMastodonBlueskyInstagramThreadsRSSLeaderboardGlossaryContributeNewsletterStore
    Web3 is Going Just Great
    ...and is definitely not an enormous grift that's pouring lighter fluid on our already smoldering planet.
    Created by Molly White. Subscribe to her newsletter for weekly recaps.
    Twitter
    Mastodon
    Bluesky
    Instagram
    Threads
    Go to full timeline
    July 31, 2026
    Coldcard hardware wallet flaw sees more than 2,000 BTC (~$130 million) drained across thousands of wallets
    Coldcard logo (attribution)
    Thousands of users of a hardware wallet called Coldcard, a physical device developed by the Canadian Coinkite firm to allow bitcoin holders to store their bitcoin on a device that's not connected to the internet, have suffered at least 2,055 BTC (~$130 million) in combined losses after thieves began exploiting a flaw with the wallet firmware's seed phrase generation. A 2021 version of the device firmware, which affects a wide range of Coldcard devices, skipped the device's more secure hardware randomness generator and instead fell back to generating seed phrases with random numbers seeded from the device's serial number and clock registers. The resulting seed phrases are relatively trivially guessed, and hackers have been methodically draining vulnerable wallets as researchers warn that all vulnerable Coldcard devices will be drained soon if their owners do not move assets to secure wallets.
    An estimated 2,055 BTC (~$130 million) and counting has been drained in the days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Attacks have come from an estimated 15 unique groups, according to Galaxy Research.
    Hardware wallets are often used by more security conscious users, or those with more significant sums of money at risk, because the lack of internet connection makes the devices less vulnerable to phishing or malware-based attacks. However, if a wallet seed phrase can be obtained by an attacker, the lack of internet connection is no barrier to theft. Coldcard describes itself as "ultra-secure", and its website is filled with reviews describing the product as "one of the most secure Bitcoin hardware wallets ever built".
    "Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets", Decrypt [archive]
    "Major bitcoin wallet flaw drains $38 million worth of BTC in 25-minute sweep", CoinDesk [archive]
    Tweet thread by Galaxy Research
    Theme tags: Hack or scam
    Blockchain tags: Blockchain: Bitcoin
    Text is licensed under a Creative Commons Attribution 3.0 Unported License. All attribution can be found on the attribution page.
    Source code | Contribute
  2. Earliest copy held
    seen · Internet Archive 3,002 chars replay

    Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.

    Extracted text as captured
    HomeAboutWhat is web3?FAQLicenseTwitterMastodonBlueskyInstagramThreadsRSSLeaderboardGlossaryContributeNewsletterStore
    Web3 is Going Just Great
    ...and is definitely not an enormous grift that's pouring lighter fluid on our already smoldering planet.
    Created by Molly White. Subscribe to her newsletter for weekly recaps.
    Twitter
    Mastodon
    Bluesky
    Instagram
    Threads
    Go to full timeline
    July 31, 2026
    Coldcard hardware wallet flaw sees more than 1,367 BTC (~$89 million) drained across thousands of wallets
    Coldcard logo (attribution)
    Thousands of users of a hardware wallet called Coldcard, a physical device developed by the Canadian Coinkite firm to allow bitcoin holders to store their bitcoin on a device that's not connected to the internet, have suffered more than 1,367 BTC (~$89 million) in combined losses after thieves began exploiting a flaw with the wallet firmware's seed phrase generation. A 2021 version of the device firmware, which affects a wide range of Coldcard devices, skipped the device's more secure hardware randomness generator and instead fell back to generating seed phrases with random numbers seeded from the device's serial number and clock registers. The resulting seed phrases are relatively trivially guessed, and hackers have been methodically draining vulnerable wallets as researchers warn that all vulnerable Coldcard devices will be drained soon if their owners do not move assets to secure wallets.
    An estimated 1,367 BTC (~$89 million) and counting has been drained in the two days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Subsequent attacks have seen funds moved to around 600 attacker wallets, according to Galaxy Research, although the number of unique attackers is not clear at this point, and attackers regularly use multiple wallets to make tracing stolen funds more challenging.
    Hardware wallets are often used by more security conscious users, or those with more significant sums of money at risk, because the lack of internet connection makes the devices less vulnerable to phishing or malware-based attacks. However, if a wallet seed phrase can be obtained by an attacker, the lack of internet connection is no barrier to theft. Coldcard describes itself as "ultra-secure", and its website is filled with reviews describing the product as "one of the most secure Bitcoin hardware wallets ever built".
    "Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets", Decrypt [archive]
    "Major bitcoin wallet flaw drains $38 million worth of BTC in 25-minute sweep", CoinDesk [archive]
    Theme tags: Hack or scam
    Blockchain tags: Blockchain: Bitcoin
    Text is licensed under a Creative Commons Attribution 3.0 Unported License. All attribution can be found on the attribution page.
    Source code | Contribute
How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.