← Radar

Incident case file

Sign in to watch

Coldcard Firmware RNG Vulnerability — Ongoing Multi-Wave Bitcoin Drain

Incident date 2026-08-06Last updated Aug 14, 2026

4 views

ActiveBitcoinFirmware vulnerability / weak entropyCluster: COLD-RNG-2026-08

Estimated loss

$111M

Victims identified

7300
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Ledger

Attacker

MISSING — at least 15 distinct attackers identified by Galaxy Research (confirmed via Alex Thorn/@intangiblecoins, Aug 4 tweet); no individual identity publicly disclosed by Galaxy or law enforcement. Known consolidation addresses (Waves 1-2, cross-confirmed by Galaxy Research, CoinDesk, and CryptoTimes): bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r (562.02 BTC), bc1qx76cae2706qd5q576feh7xq8rfcsjpf2htfhe3 (398.48 BTC), bc1q8jy96fe5lf8vfugydnte3cguk92gpev7kwtp3q (89.62 BTC), bc1qnk4zh9qcnap2mycp5

Funds moved to

Approximately 90% of stolen BTC remains unmoved across attacker-controlled addresses as of Aug 7, 2026. Partial laundering confirmed Aug 4: 64.9 BTC moved to the Wasabi coinjoin service; 200 ETH moved to Tornado Cash via a THORChain BTC→ETH bridge, with an intermediary address 0x41B7529a411EeA979a8d468bdEBd36b0ad703268 reported by CertiK (not independently re-verified on-chain in this investigation). Address bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r has become a public OP_RETURN message board

Linked

7 known consolidation addresses across Waves 1-2 holding 1,158.66 BTC collectively (cross-confirmed by Galaxy Research, CoinDesk, and CryptoTimes). Wave 3 funds spread across 293 monitored P2WSH vaults. Wave 4 (Aug 3) added 448.7 BTC from 709 addresses via an accelerated sweep pattern (13.8 sweeps/block vs. a 0.3 pre-incident baseline, blocks 960,778-960,792). Galaxy Research has shared confirmed attacker and victim addresses directly with U.S. federal law enforcement, cryptocurrency exchanges,

Chronology

1 beat
  1. T-X: Vulnerable Coldcard firmware (v4.0.1 and later) ships March 17, 2021 (block approximately 674,951), following a commit dated March 1, 2021 that changed the seed generation routine from ckcc.rng_bytes() (hardware true random number generator) to ngu.random.bytes() (a deterministic MicroPython software PRNG), per Block's Engineering team's root-cause analysis. This reduces effective entropy to roughly 40 bits on the Mk3 model and roughly 72 bits on Mk4/Mk5/Coldcard Q, versus the 128 bits intended for a standard BIP-39 seed. T0: Wave 1 begins July 30, 2026, between 01:10 and 01:51 UTC — 594 BTC (later refined to 1,082.65 BTC) drained from 1,196 addresses within a 41-minute window spanning blocks 960,183-960,191, preceding Coinkite's public advisory by approximately 30 hours. Every sweep transaction pays an identical hardcoded fee of 30.0 sat/vB — a 30-75x overpay relative to the 0.4-1.0 sat/vB market median that week — indicating fully automated tooling rather than manual withdrawal. Victim address types: 1,183 native segwit (BIP-84), 7 BIP-49, 6 BIP-44, consistent with multi-derivation-path scanning. Coinkite discloses the vulnerability publicly on July 30 and releases emergency firmware. T+1 day (July 31-Aug 1): A second wave is identified, bringing the cumulative total to 1,158.66-1,158.81 BTC across 2,673 addresses (~$75.1M). Aug 1: A third wave adds 207.7294 BTC, bringing the cumulative observed total to 1,367.05 BTC across 4,585 addresses (~$88.6M). Aug 2: Coinkite halts all shipments and destroys remaining inventory carrying the flawed firmware (Satscard, Opendime, and Tapsigner products are unaffected by this specific bug). Aug 3 (early Monday): A fourth wave adds 448.7 BTC from 709 newly suspected victim addresses, with sweep velocity accelerating to 13.8 transactions per block versus the 0.3 pre-incident baseline; the running total reaches approximately 1,816 BTC (~$114M per Fortune/Genfinity estimates at that point in time). Aug 4: Galaxy Research issues a formal revision, stating with 'high confidence' that 1,596 BTC has been confirmed stolen from approximately 7,300 addresses across three fully confirmed waves plus 14 smaller linked incidents; a suspected fourth wave remains unconfirmed by direct victim reports, and if included would bring the total to 2,055 BTC (approximately $130 million). The same day, Alex Thorn of Galaxy Research confirms via X that at least 15 distinct attackers are now independently exploiting the vulnerability, moving beyond the earlier hypothesis of a small number of coordinated operators. Laundering activity is also observed on Aug 4: 64.9 BTC moved to the Wasabi coinjoin service, and 200 ETH moved to Tornado Cash via a THORChain-facilitated BTC-to-ETH bridge. Aug 5: CoinDesk publishes a dedicated feature profiling address bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r (562.02 BTC, approximately $36 million at the time) as a de facto public bulletin board — victims and opportunists alike attach tiny Bitcoin payments to OP_RETURN messages containing pleas for the return of funds, poetry, and at least one solicitation offering money-laundering services. Aug 7 (most recent confirmed update, via Galaxy Research): the confirmed tally is revised upward to 1,719 BTC (approximately $111 million) stolen from Coldcard victims, with Galaxy stating total losses 'likely exceed $130m.' Approximately 90% of all stolen coins remain unmoved as of this date. Throughout the incident, Galaxy Research has explicitly and repeatedly declined to attribute the campaign to a single actor or coordinated group, citing meaningful differences in transaction construction patterns (fee rates, batching behavior, RBF signaling) across the different waves. Both Coinkite and Galaxy Research separately note that the automated sweep pattern appears 'probably orchestrated with a large language model'; notably, Coinkite discloses that its own AI-assisted code review, conducted weeks prior to the exploit, had failed to identify this vulnerability in its own codebase.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)