COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Plain language Updated 15 Aug 2026

Timeline

How a software flaw reached COLDCARD wallets, when funds were stolen, and what happened afterward.

Show

May 2008

Debian Security Advisory DSA-1571-1 published

Debian

Primary Debian advisory for CVE-2008-0166, including the affected release period and instruction to regenerate cryptographic key material.

August 2013

Some SecureRandom thoughts published

Android Developers

Primary Android statement on improper PRNG initialization affecting some cryptographic applications, including Bitcoin wallets.

November 2020

Captured screenshot: Jwweatherman_ 1328075905604829185 captured
Jwweatherman_ 1328075905604829185 post

@JWWeatherman_

A November 2020 post, five and a half years before the incident, quoting Greg Maxwell that the mitigations for hardware-wallet tampering risk are to avoid specialised hardware or to use…

Captured screenshot: Jwweatherman_ 1329613163973668865 captured
Jwweatherman_ 1329613163973668865 post

@JWWeatherman_

JW Weatherman's November 2020 prediction that a hardware wallet would exit scam within five years by blaming a bug or rogue employee; registered as historical context.

December 2020

Captured screenshot: NVK 1341213389549412353 captured
NVK 1341213389549412353 post

@nvk

nvk's December 2020 reply that users were likelier to lose coins through their own mistakes than a vendor attack, recommending dice; a pre-incident record of the vendor's public stance.

January 2021

28 Jan 2021
The build-time guard exists in libngu
The #ifndef MICROPY_HW_ENABLE_RNG guard exists in libngu. Its defined-zero defect is already present, but COLDCARD seed generation does not yet use this path. R1

March 2021

1 Mar 2021
Seed generation migrates to ngu.random.bytes()
Commit b18723dddb6d751c39978e4364b56b2414f68b47 migrates wallet generation from ckcc.rng_bytes() to ngu.random.bytes(). Combined with the existing defined-zero guard defect, the migration activates the affected path. R2
17 Mar 2021
Firmware v4.0.0 opens the first exposure window
Firmware v4.0.0 ships for Mk2 and Mk3, opening the first exposure window. Its normal seed-generation path XORs output from the MicroPython and libngu Yasmarang generators before hashing. The vendor's later disclosure history states that v4.0.0 was built, signed and tested internally but never released publicly as a binary, making v4.0.1 the first public 4.x release; the published accounts behind the v4.0.0 boundary are set out on the firmware page. R3

October 2021

Captured screenshot: 2021: retirement attacks impossible captured
2021: retirement attacks impossible post

@COLDCARDwallet · Coinkite

The vendor's own 2021 marketing claim that COLDCARD makes retirement attacks impossible because users can generate their own entropy and reproduce it provably. Held as historical context: the July 2026…

Captured screenshot: 2021: retirement attack defined captured
2021: retirement attack defined post

@COLDCARDwallet · Coinkite

The vendor's 2021 definition, in reply to a reader: a retirement attack is when project makers could have a "bug" in the entropy generation for later retrieval. Companion to coldcard-retirement-attack-claim.

March 2022

11 and 14 Mar 2022
The reseed API, a paid pre-release review, and Mk4 v5.0.0
The reseed() API is added to libngu, and Mk4 v5.0.0 ships as the first production firmware calling rng_seeding() on the normal boot path. A secure-element-derived value overwrites one libngu state word, contributing at most 32 bits; other UID and timing terms remain in published models. The vendor's disclosure history records a paid private review in the same window (1 to 14 March 2022) that examined PIN derivation, rate limiting and random-number generation, and under which the runtime generator was seeded with authenticated entropy from both secure elements; it cites private correspondence this archive cannot inspect. R4 R5

April 2023

Captured screenshot: Browser-extension WASM vulnerability thread captured

@TrustWallet · Trust Wallet

Trust Wallet's primary incident thread states the affected browser-extension creation window, that the issue was fixed, and that affected users should follow its remediation guidance. The held capture covered the…

CVE-2023-31290 vulnerability record published

NIST National Vulnerability Database

Official vulnerability record for the Trust Wallet browser-extension generator, affected versions, 32-bit entropy bound and reported exploitation period.

June 2023

26 Jun 2023
v4.1.9, the last Mk3 release for three years
Firmware v4.1.9 ships. For the next three years it remains the latest published Mk3 release, and it contains the affected path. R6

August 2023

Milk Sad vulnerability disclosure published

Milk Sad research team

Primary disclosure for CVE-2023-39910, including the 32-bit MT19937 seed funnel, partial impact accounting and comparison with the Trust Wallet incident.

October 2023

extreme paranoia with hardware wallets published

Stacker News

lloyddunne in October 2023, praising the COLDCARD yet naming seed-generation trust as the thing that kept them up at night, and proposing normalised offline seed generation with dice and independent…

November 2023

Unciphered

Primary Randstorm disclosure describing vulnerable BitcoinJS-derived browser wallets and the browser- and date-dependent attack surface.

December 2023

Captured screenshot: Finnejay 1737662786941968736 captured
Finnejay 1737662786941968736 post

@FinneJay

A December 2023 thread promising an easy guide to generating a bitcoin private key offline; pre-incident context on manual key generation.

January 2024

10 Jan 2024
A cleanup touches the call site, not the source
Commit 024655be6bbfc0fd2e142f2e3b4ba39eb95e96a4 replaces the random.bytes() wrapper with a direct ngu.random.bytes() call and switches to sha256d(). The cleanup changed the call site but not the linked RNG source, so affected builds span every release from v4.0.0 until the 2026 hotfix. How it broke sets out the published accounts of both versions. R7

February 2024

8 Feb 2024
First public Q firmware
First public Q firmware, v0.0.3Q, with production v1.0.0Q on 10 March 2024. Every Q build in the published release history before v1.5.0Q contains the affected path. R8

March 2024

r/ledgerwallet

Primary behind the claimed years-old drain report that circulated as screenshots after the July 2026 disclosure (zenulabidin-drain-report-screenshot, btctherapist-prior-drain-report). Economy-Cash6726's two-year-old comment in an r/ledgerwallet seed-entropy thread claims a Coldcard Mk4…

April 2024

Captured screenshot: Foundationhq 1778581463618773441 captured
Foundationhq 1778581463618773441 post

@FoundationHQ

Foundation's April 2024 explanation for not adding dice rolls to Passport, citing reported COLDCARD losses from low dice counts and noting dice do not protect against malicious firmware.

March 2026

10 Mar 2026
COLDCARD Mk5 launches
COLDCARD Mk5 launches on firmware v5.5.0 and uses the Mk4-class generation path. Its pre-hotfix releases are affected under the same published candidate-space models. R9

Also in March 2026

Captured screenshot: NVK 2031836293240668367 captured
NVK 2031836293240668367 post

@nvk

nvk's March 2026 reference list of crypto company data breaches that led to phishing and scam campaigns, published months before the incident.

June 2026

July 2026

30 July 2026

Also on 30 July 2026

31 July 2026

Also on 31 July 2026

1 August 2026

Also on 1 August 2026

2 August 2026

Also on 2 August 2026

3 August 2026

Also on 3 August 2026

4 August 2026

Also on 4 August 2026

5 August 2026

Also on 5 August 2026

6 August 2026

Also on 6 August 2026

7 August 2026

Also on 7 August 2026

8 August 2026

9 August 2026

August 2026

Published updates, side by side

each subject's earlier and later published wording
Changes in published incident scope V81
SubjectEarlier publicationLater publication
Affected models Coinkite's 30 July advisory said Mk4, Q and Mk5 were not affected based on early analysis. The backgrounder's state held on 1 August included Mk4, Mk5 and Q in the affected scope. The page displays a 30 July publication date; the expanded scope's first appearance time is unresolved.
Mk2 coverage Through the state captured at 14:02 UTC on 1 August, which is the first held after the 13:35 UTC update, the advisory named only one model: "The issue is present on Mk3 firmware versions 4.0.1 through 4.1.9 inclusive", with the fixed release given as "Mk3: version 4.2.0 or later". The 14:35 EDT update of 1 August names both: "The issue is present on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 inclusive", with the fixed release given as "Mk2/Mk3: version 4.2.0 or later". The lower bound of 4.0.1 is unchanged.
Mk3 firmware The 31 July advisory said Coinkite was exploring whether it could safely publish one final Mk3 release, contingent on validating a sufficiently safe upgrade path, and warned users not to wait for it. Firmware 4.2.0 was published for Mk3 at 13:43 UTC on 31 July.
Who is at risk Through the state held at 00:17 UTC on 1 August, the advisory said Coinkite was "warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) thru 4.1.9 (inclusive) that their funds may be at risk". The 09:35 EDT update of 1 August states that funds are at risk "if the seed was created without at least 50 fair, independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase". The blanket warning becomes two published conditions.
Passphrase guidance The earlier text said a strong, unique BIP-39 passphrase "adds an independent barrier" and that "the risk depends on the strength of the passphrase", with short, common, patterned, quoted or reused passphrases not to be assumed low risk. The same section now says the reduced seed entropy alone is not enough to reach funds in that wallet because "an attacker must also discover the passphrase", and separately that a strong passphrase "does not repair the affected seed", that passphrase users "should also migrate as soon as practical", and that an uncertain passphrase means treating the funds as at risk and migrating immediately.
Site-wide banner The banner carried on the downloads and terms pages read "Seeds generated on firmware 4.0.1 or later may be at risk". The same banner reads "Seeds generated on firmware 4.0.1 (2021 or later) are at risk".
Attributed transaction accounting Early public figures described the 500-transaction, approximately 594.5 BTC set. Galaxy later published a wider 1,082.65 BTC attribution including 695 additional transactions.

Four dated advisory revisions are recorded here: the widening of scope to Mk4, Mk5 and Q, the announcement of fixed firmware, the replacement of a blanket warning with two published conditions, and the addition of the Mk2. None of them moves the published lower bound, which stays at 4.0.1 and so leaves the difference with Block's published v4.0.0 boundary as it was.

Unresolved as of 15 August 2026

nine questions the held record does not settle
  • The reported Mk4-class sweep. Kevin Loaec of Wizardsardine reported on 1 August that Mk4, Mk5 and Q wallets were being actively drained, quoting a third-party account of a deliberately funded honeypot wallet swept overnight. Nothing held here settles which device model generated its seed.
  • Backgrounder ordering. The page displays a 30 July publication date, but the first appearance of its expanded model scope relative to the 31 July 05:19 UTC hotfix commit remains unknown.
  • The wider transaction attribution. Block's captured preliminary thread and this site's own privacy-safe recheck support the 695-transaction counts and arithmetic, but no complete primary transaction list is published here and the arithmetic does not establish common control.
  • Later clusters. In their states checked on 1 August, two community trackers included a separately reported 45.9 BTC cluster in wider headlines. Its relationship to the principal incident set remains an attributed lead rather than a verified extension of the total.
  • Original discovery method. AI-assisted discovery remains an inference; AI-assisted post-disclosure reproduction is separately reported. The vendor's 4 August statement, that its own AI-assisted review and several frontier models tested since did not catch the bug, bears on review rather than on how the defect was first found. On 7 August the vendor stated a belief about the discovery for the first time, that the bug "lived in public for 5yrs, even third party researchers didn't find it" and that it "took the lastest LLM models to find it", but offers it as a belief and publishes nothing about the attacker to check it against, so the question stands.
  • The May 2025 audit account. James O'Beirne's 4 August account of auditing the firmware in May 2025 and reporting doubts about the RNG path to the COLDCARD team carries no contemporaneous report artefact. Nothing held here corroborates or contradicts it, and no captured vendor statement addresses it. He restated it on 7 August, adding that at least one other person warned the vendor about the same issue four years before him; that earlier warning is not identified and nothing held here corroborates it either.
  • Number of affected people and seeds. Addresses are not people, and no captured source supplies the total number of seeds generated on affected firmware.
  • The claimed fourth wave. The pattern-matched wave-4 set circulated on 2 and 3 August was corrected twice by its own compiler, who states there is no direct victim confirmation yet. Whether the surviving core belongs to the incident at all is not settled by anything held here.
  • The reported passphrase-wallet loss. BTC Sessions' 2 August report of a drained Mk3 with a two-word passphrase cites no transaction or address, so it can be neither corroborated nor refuted from the held record.

How to check this reconstruction

three clocks, and what is inherited

Three different clocks appear in this stream. A post carries its publication time, taken from the page's own timestamp. A dated publication carries the date its publisher displays. A source change carries a window: the page said one thing at the earlier capture and something else at the later one, so the edit landed somewhere between the two, and the entry says exactly that rather than presenting the later capture time as the moment of the edit.

First captures are deliberately not plotted. When a source entered this record is a fact about this project's collection schedule, not about the discourse, and mixing the two would let the polling rhythm masquerade as incident history. Each source page shows what we hold: the excerpted text and the diffs between one check and the next. Social posts link to the original. Anything recovered from the Internet Archive rather than captured here is labelled as such, so an inherited copy is never presented as one this project took at the time.

Predictable key generation has appeared before, in Debian OpenSSL, Android SecureRandom, Randstorm, Milk Sad and Trust Wallet. The reference register keeps those contextual sources apart from evidence about this incident, and the AI evidence page separates Coinkite's inference about how the defect was found from the separately reported post-disclosure reproductions. One limit belongs with both: a successful reproducible-build comparison can show that a distributed binary corresponds to specified source and build inputs, but not that the source logic is correct.

Evidence on this page 81 items
  1. R1
    Reported

    The presence and defined-zero defect of the MICROPY_HW_ENABLE_RNG guard in libngu at this date, as published

    Source Block's engineering disclosure, which documents the guard's defined-ness error and the deterministic fallback it selects, held capture of 31 Jul 2026

  2. R2
    Reported

    The 1 March 2021 migration commit and its activation of the affected seed-generation path, as published

    Source Block's engineering disclosure, which dates migration commit b18723dd to 1 March 2021 and traces its first appearance to released firmware v4.0.0, held capture of 31 Jul 2026

  3. R3
    Reported · contested

    The v4.0.0 source and release record and its seed-generation path; the vendor states the v4.0.0 binary was never publicly released

    Source Block's engineering disclosure, which dates the affected path to released firmware v4.0.0 on 17 March 2021; Galaxy Research's captured statement that the vulnerable firmware shipped 17 March 2021 around block 674,951; Coinkite security disclosure history, held capture of 5 Aug 2026

  4. R4
    Reported

    The addition of the reseed() API and the Mk4 v5.0.0 release record, as published

    Source Block's engineering disclosure, which documents the Mk4 secure-element reseed and tabulates Mk4 production firmware from v5.0.0 onward, held capture of 31 Jul 2026; Coinkite's disclosure history records the same first-shipped version

  5. R5
    Reported

    The March 2022 paid private review and its RNG work, as recorded by the vendor; the underlying correspondence is not inspectable here

    Source Coinkite security disclosure history, held capture of 5 Aug 2026

  6. R6
    Reported

    The v4.1.9 release record and its status as the latest published Mk3 release until 2026, as published

    Source Coinkite's security disclosure history, which cites the Mk3 release history and gives the affected Mk2 and Mk3 range as 4.0.1 to 4.1.9 with the fix in 4.2.0, held capture of 5 Aug 2026

  7. R7
    Reported

    The 10 January 2024 cleanup commit and the unchanged linked RNG source across both versions, as published

    Source Block's engineering disclosure, which reconstructs the generation path including the sha256d hashing step over the unchanged deterministic fallback, held capture of 31 Jul 2026

  8. R8
    Reported

    The Q release history from v0.0.3Q onward and the affected path in every published Q build before v1.5.0Q, as published

    Source Block's engineering disclosure, which tabulates all production Q firmware as carrying the same fallback and reseed construction, held capture of 31 Jul 2026; Coinkite's disclosure history cites the public Q release history

  9. R9
    Reported

    The Mk5 launch release and its place in the Mk4-class generation path, as published

    Source Block's engineering disclosure, which tabulates all production Mk5 firmware under the same construction, held capture of 31 Jul 2026; Coinkite's disclosure history scopes Mk4/Mk5 releases before 5.6.0 as affected

  10. R10
    Reported · contested

    Galaxy's 41-minute wider window, address count and BTC estimate

    Source Galaxy Research primary X post, preserved in the archive

  11. R11
    Reported

    The 500-transaction set's reported UTXO count, duration, collector receipt and consolidation figure

    Source Captured TFTC report and Rob Hamilton primary post

  12. V12
    Verified · contested

    The affected-model statement in Coinkite's first advisory

    Source Coinkite Mk3 Security Advisory; original state recovered through the Internet Archive

  13. R13
    Reported · contested

    Block's published affected-firmware range and exploitation account

    Source Block engineering report, published 30 Jul 2026; the firmware range is separately checked against source

  14. R14
    Reported

    Block's preliminary 695-transaction fingerprint match, counts and net first-collector amount, including its unconfirmed relationship to the drain

    Source Clay Garrett and Block engineering, captured primary X thread, 31 Jul 2026

  15. R15
    Reported

    Unchained's public client guidance

    Source Unchained, preserved X capture

  16. R16
    Reported

    The vendor-published Mk4/Mk5/Q hotfix release record and source-commit note, not binary contents

    Source The vendor's signed-release record and release commit as published; the held downloads-page capture of 1 Aug 2026 lists 5.6.0 and 1.5.0Q as current, and the vendor's disclosure history records the same fixed versions

  17. R17
    Reported · contested

    Coinkite's expanded affected scope and published candidate-space models; not the first-publication time

    Source Coinkite entropy technical backgrounder; source-level affected ranges are checked separately

  18. R18
    Reported · contested

    The vendor's expanded public scope and migration direction, including its v4.0.1 Mk3 boundary

    Source Official COLDCARD X update; the disagreement with Block's published v4.0.0 boundary is presented on the firmware page

  19. R19
    Reported

    Galaxy's wider-set attribution and estimate

    Source Galaxy Research primary X post, preserved X capture

  20. R20
    Reported

    The vendor's availability announcement for Mk3 4.2.0 and downloads-page listing for Mk2 and Mk3

    Source Captured official COLDCARD X update and vendor downloads page; source-level fix and binary limitations are documented separately

  21. R21
    Reported

    NVK's apology and stated commitments

    Source NVK, preserved X capture

  22. R22
    Reported

    The official availability announcement for Edge 6.6.0X and 6.6.0QX

    Source Captured official COLDCARD X update; binary limitations are documented separately

  23. R23
    Reported

    Block's account of the service-provider queries and its non-participation qualification

    Source Clay Garrett, complete three-post X thread preserved in the archive

  24. R24
    Reported

    The later operator attribution and public accounts of how the bug may have been discovered

    Source Captured statements from Block, Coinkite and named researchers

  25. R25
    Reported

    Loaec's dated multisig and miniscript guidance

    Source Kevin Loaec, preserved X capture

  26. R26
    Reported

    The coldcard-watch tracker's expanded two-episode headline and its stated totals

    Source coldcard-watch community tracker, held capture state of 1 Aug 2026

  27. R27
    Reported

    The vendor's urgent-migration appeal and the boundary conditions in the update it quotes

    Source Coinkite, captured official X post, 1 Aug 2026

  28. R28
    Reported · contested

    The 1 August account that Mk4, Mk5 and Q wallets were being actively drained, and the honeypot sweep quoted with it

    Source Kevin Loaec's captured post quoting Tomer Strolight; a community tracker's later held capture records the Mk4 attribution as withdrawn in favour of an Mk3-origin seed

  29. V29
    Verified

    The wording of the 1 August advisory and backgrounder update and of the changed site-wide banner

    Source Held captures of the Coinkite Mk3 advisory, entropy backgrounder, downloads page and terms page, with diffs against the preceding held states

  30. R30
    Reported

    The publication and argument of Wizardsardine's post-mortem, including the authors' stated conflict and speed caveats

    Source Wizardsardine post-mortem and captured announcement post, 1 Aug 2026

  31. R31
    Reported

    Loaec's statement that imported or dice-generated seeds are also exposed through certain COLDCARD features; the attached feature list did not render in the held capture

    Source Kevin Loaec, captured X post, 1 Aug 2026

  32. R32
    Reported

    Clay Garrett's initial findings on the separately disclosed Bitkey vulnerability and Block's stated risk limits

    Source Clay Garrett, captured X post, 1 Aug 2026

  33. R33
    Reported

    The existence, publication date and self-described purpose of the Stoltmann Law claimant-intake page

    Source Stoltmann Law claimant page, held browser capture of 4 Aug 2026; surfaced through an Internet Archive snapshot of 3 Aug 2026

  34. R34
    Reported

    Braziel's 1 August victim-intake solicitation and the information it requests

    Source Thomas Braziel (117 Partners), captured X post, 1 Aug 2026

  35. R35
    Reported

    The announcement and subject of Dettmer's commit-history walkthrough

    Source bitcoin++ Insider Edition, captured announcement, 1 Aug 2026

  36. V36
    Verified

    The fourth revision's substitution of Mk2 and Mk3 for Mk3 throughout the affected range, the fixed release and the migration sections of both the advisory and the backgrounder

    Source Held captures of the Coinkite Mk3 advisory and entropy technical backgrounder taken at 18:44 UTC on 1 August 2026, with diffs against the states held at 14:02 UTC the same day

  37. R37
    Reported

    Galaxy's 1 August third wave, revised total, attacker-holdings figure and stated method limit, and its statement about the firmware ship block

    Source Galaxy Research's captured 1 August thread; its scope is wider than the 30 July set and the underlying transaction and address lists are not published

  38. R38
    Reported

    Galaxy's account of how each wave was identified, its victim-outreach request and its statement about sharing findings with investigators

    Source Galaxy Research, captured X update, 2 Aug 2026

  39. R39
    Reported

    The vendor's shipments-halted and inventory-destruction statement, its customer-email account and its not-affected statement for SATSCARD, OPENDIME and TAPSIGNER

    Source Coinkite, captured official X post, 2 Aug 2026; TFTC's later secondary report is held separately

  40. R40
    Reported

    The vendor's stated purpose of the store disclaimer

    Source Coinkite, captured official X reply, 2 Aug 2026

  41. R41
    Reported

    The OpenSats board departure and its stated interim board size; the post states no reason

    Source OpenSats, captured X statement, 2 Aug 2026

  42. R42
    Reported

    BTC Sessions' account of a drained Mk3 two-word-passphrase wallet and its claimed timing; the post cites no transaction or address and the loss is not corroborated here

    Source BTC Sessions, captured X post, 2 Aug 2026

  43. R43
    Reported

    The vendor's Sunday statement: its damage acknowledgement, outreach description, community thanks and forward commitment

    Source Coinkite, captured official X post, 2 Aug 2026

  44. R44
    Reported

    The original wave-4 post's transaction, address, amount and block-range figures, and the pending Pastebin's stated replace-by-fee set

    Source intangiblecoins, captured original thread posts and linked Pastebin pages, 3 Aug 2026

  45. R45
    Reported

    The removal of six historical destination addresses from the circulated wave-4 list and the 206 freshly created remainder

    Source intangiblecoins, captured correction post, 3 Aug 2026

  46. R46
    Reported

    The multisig correction, the stated wave-4 figures as circulated and as corrected, and the author's statement that wave 4 has no direct victim confirmation

    Source intangiblecoins, captured correction post credited to Nunchuk, 3 Aug 2026

  47. R47
    Reported

    Kelbie's announcement of the tracker's move to coldcard.rip

    Source Kevin Kelbie, captured X post, 3 Aug 2026

  48. R48
    Reported

    The rebuilt tracker's ten-wave organisation and its stated swept totals, which the operator describes as AI-compiled and not independently fact-checked

    Source coldcard.rip incident tracker, held capture state of 3 Aug 2026

  49. R49
    Reported

    Braziel's 3 August strategy update: the private-suit direction, claimant count, legal theories, collectability framing and funding expectations

    Source Thomas Braziel (117 Partners), captured X post, 3 Aug 2026

  50. R50
    Reported · contested

    L0la L33tz's warnings about Braziel and the Delaware court findings quoted in them, against Braziel's own description of the matter as settled

    Source L0la L33tz, captured X posts, 3 Aug 2026; the underlying dispute is documented in the two bkclaims entries

  51. R51
    Reported

    Galaxy's 3 August confirmed and wave-4-inclusive totals, confirmation basis, victim count, unmoved-coins statements, law-enforcement handoff and ongoing-attack warning

    Source Galaxy Research's captured 3 August thread; the underlying transaction and address lists are not published

  52. R52
    Reported

    The NCFA commentary's publication, its attributed loss figures and its stated argument, which remains the author's position

    Source NCFA Canada, held browser capture of 5 Aug 2026; published 3 Aug 2026

  53. R53
    Reported

    Hamilton's and calle's 4 August Red Team status figures: spend, repositories scanned, disclosure counts and finding rates, all self-reported with no findings itemised publicly

    Source Rob Hamilton and calle, captured X posts, 4 Aug 2026

  54. R54
    Reported

    Hamilton's statement that four days of hardware-wallet scanning had shown no vulnerability, a time-bounded account of reviewed reports rather than a comprehensive finding

    Source Rob Hamilton, captured X post, 4 Aug 2026

  55. R55
    Reported

    James O'Beirne's first-person account of his May 2025 audit, the report he describes sending and the response he describes receiving; no contemporaneous artefact is attached

    Source James O'Beirne, captured X post, 4 Aug 2026

  56. R56
    Reported

    The vendor's 4 August investigation statement: its loss acknowledgement, submodule-boundary account, AI-review statements and announcement of the disclosure history

    Source COLDCARD, captured official X post, 4 Aug 2026

  57. V57
    Verified

    The disclosure-history page's stated counts, coverage window, self-described limits and wording as held; the underlying private correspondence is not inspectable

    Source Held capture of coinkite.com/historical-disclosures, 5 Aug 2026

  58. R58
    Reported

    Chainalysis's geographic attribution of losses and its stated national shares; the underlying dataset and method are not published

    Source Chainalysis, captured X post, 4 Aug 2026

  59. R59
    Reported

    Marius OffChain's 64 BTC mixing trace: the stated amounts, hops and named address; the transactions are checkable on chain but not reproduced here

    Source Marius OffChain, captured X post, 5 Aug 2026

  60. R60
    Reported · contested

    The coordinator-responsibility dispute: tanuki42_'s argument that Kruw's centralised coordinator could exclude the stolen coins, against Kruw's quoted reply that the theft cannot be proved because attacker and owner share the same entropy

    Source tanuki42_, captured X post, 5 Aug 2026; Kruw's reply as quoted by International Cyber Digest, 5 Aug 2026

  61. R61
    Reported

    calle's 5 August Red Team figures: 16 people, 27.5 hours, 4,962 findings across 390 projects, 85 critical and 635 high severity; self-reported, with the findings not public and held for disclosure

    Source calle, captured X post, 5 Aug 2026

  62. R62
    Reported

    The stated funding route: OpenSats paying the team's AI bill and donations converting into inference, in the participant's own characterisation

    Source calle, captured X post, 5 Aug 2026

  63. R63
    Reported

    Bitcoin Magazine's secondary report of the same figures plus the stated US$40,000 compute spend and 171,599-line harness

    Source Bitcoin Magazine, held capture of 6 Aug 2026; article dated 5 Aug 2026

  64. R64
    Reported

    The Code RED announcement and its stated terms: priority support for people red teaming Bitcoin software, including reimbursement of past LLM token costs

    Source OpenSats, captured official X post, 6 Aug 2026

  65. V65
    Verified

    The Code RED blog post's displayed 6 August 2026 publication date, its stated terms and its wording as held

    Source Held capture of opensats.org/blog/code-red-supporting-first-responders, 7 Aug 2026

  66. V66
    Verified

    The CKTRIPWIRE scoreboard's revised GPU crack-time estimates across every difficulty band, its 17-honeypot state and the addition of HP-8DA1, as held in the captures of 6 August 2026; the experiment's setup and entropy model have not been reproduced here

    Source Held captures of cktripwire.com, 6 Aug 2026

  67. R67
    Reported · contested

    Taylor Monahan's claim, as relayed by Laura Shin, that the dice rolling recommended to owners is what drained the earliest victims, against the dice carve-out published in Coinkite's own advisory

    Source Laura Shin, captured X post, 6 Aug 2026, relaying Taylor Monahan

  68. R68
    Reported

    The stated wallet-warning pull-request effort and the four pull requests named in the post; three of the four are not held here

    Source Yan at Swan (@skwp), captured X post, 6 Aug 2026

  69. V69
    Verified

    Sparrow pull request 2047 as held: its opening comment and approval both dated 6 August 2026, its stated detection rule and covered flows, its open status, the follow-up comments about warning surfaces and a load-time acknowledgment/MOTD proposal, and its author's build caveat

    Source Held capture of github.com/sparrowwallet/sparrow/pull/2047, 12 Aug 2026

  70. V70
    Verified

    The replacement of the ifndef guard on libngu master, the Linux getrandom() helper and the negative-count rejection, and the merge of pull request #58 as commit e9d5e80 on 6 August 2026

    Source Held captures of libngu ngu/random.c on master and of pull request #58, 6 Aug 2026

  71. V71
    Verified

    The wording of Casa's security advisory banner, its stated 1 August update date, the page date's move from 4 March to 6 August 2026, and the banner's absence from the state held on 3 August 2026

    Source Held captures of Casa's COLDCARD troubleshooting support page, 3 and 6 Aug 2026

  72. R72
    Reported · contested

    Coinkite's 7 August correction: its account of the Yasmarang generator's origin and arrival date, its stated design intent and its link-time-error characterisation, against James O'Beirne's reply that the libngu implementation was weaker and that the vendor had been warned four years earlier

    Source COLDCARD and James O'Beirne, captured X posts, 7 Aug 2026

  73. R73
    Reported

    The vendor's other overnight replies: further firmware versions under review, its statement that it will very likely not be around, its responsible-disclosure remark, and its stated belief that the latest LLM models were needed to find the bug

    Source COLDCARD, captured official X replies, 7 Aug 2026

  74. R74
    Reported

    Cointelegraph's report, attributed to Bloomberg, that Coinkite is working on a post-mortem rather than estimating customer losses; the Bloomberg report is not held here

    Source Cointelegraph, captured X post, 7 Aug 2026

  75. V75
    Verified

    The coldcard-watch tracker's rename, its Verified/Attested/Suspected filter split, and the movement of its stated verified figures between the states held on 4 and 7 August 2026

    Source Held captures of coldcardwatch.com, 4 and 7 Aug 2026

  76. V76
    Verified

    The Wave 2 collector's emptying as the tracker records it: the 30.18476329 BTC spend, its confirmation at block 961,368, the dust remainder, the movement of the tracker's MOVED and STILL HELD figures, and its later requalification of the Galaxy note, all between the states held on 7 August 2026

    Source Held captures of the COLDCARD hack tracker, 7 Aug 2026

  77. R77
    Reported

    orangesurf's stated Slipstream migration totals of at least 5,371 and at least 5,681 BTC and the stated 2-of-3 majority; the underlying address set is not published

    Source orangesurf, captured X posts, 6 and 7 Aug 2026

  78. R78
    Reported

    Checkonchain's stated fall of about 233,000 BTC, or 1.38 percent, in long-term-holder supply attributed to the incident; the linked newsletter analysis is not held here

    Source Checkonchain, captured X post, 7 Aug 2026

  79. R79
    Reported

    Coinkite's stated data-retention change: the 120-day blanking practice, its suspension for legal preservation, the opt-out route and the commitment to resume; the underlying legal obligations are not inspectable here

    Source COLDCARD, captured official X post, 7 Aug 2026

  80. V80
    Verified

    The post's appearance in this archive's captures of the Coinkite blog index and the change of its displayed date from Aug 6, 2026 to Aug 7, 2026 between the captures at 11:19 and 13:19 UTC on 7 August 2026, with the index otherwise unchanged since 4 August

    Source Held captures of blog.coinkite.com, 4 and 7 Aug 2026

  81. V81
    Verified

    The earlier and later published wordings compared in the table above

    Source Held captures of the Coinkite Mk3 advisory at 01:56 and 07:30 UTC on 31 July 2026, both recovered from the Internet Archive, plus the captured backgrounder, the 13:43 UTC official Mk3 update, and this project's own captures of the advisory, downloads page and terms page on 1 August 2026, including the advisory states held at 14:02 and 18:44 UTC that bound the Mk2-coverage row