← Radar

Incident case file

Sign in to watch

Coldcard Mk3 Firmware RNG Flaw — 594 BTC Mass Wallet Sweep

Incident date July 30, 2026Last updated Aug 1, 2026

15 views

ActiveBitcoinHardware wallet RNG flawCluster: COLDCARD-RNG-2026-07

Estimated loss

$38.3M

Victims identified

500
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Ledger

Attacker

MISSING — attacker identity not publicly known. Consolidation address: bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r

Funds moved to

562.02 BTC was consolidated into a single address, bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r, which had not moved as of the most recent reporting. Three additional consolidation addresses were separately identified by Galaxy Research/Block: bc1qx76cae2706qd5q576feh7xq8rfcsjpf2htfhe3 (398.48 BTC), bc1q8jy96fe5lf8vfugydnte3cguk92gpev7kwtp3q (89.62 BTC), and bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0 (32.45 BTC) — these three addresses relate to a broader, unconfirmed estimate of the same on-cha

Linked

Approximately 500 individually affected single-signature wallets, each holding more than 0.15 BTC, generated seeds on Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3. Coinkite (Canada) is the hardware wallet manufacturer. Fix released in firmware 4.2.0+ (Mk3), 5.6.0+ (Mk4/Mk5), and 1.5.0Q+ (Q). Mk4, Q, and Mk5 devices were not affected by the underlying flaw based on Coinkite's early analysis. The vulnerability also potentially exposed paper wallet backups, seed-splitting mask

Chronology

1 beat
  1. T-1925dMarch 1, 2021

    Root cause introduced

    during a migration to libsecp256k1 in Coldcard firmware 4.0.0, the production board configuration defined a macro (MICROPY_HW_ENABLE_RNG) as zero, and a verification check in the underlying library tested only whether this setting existed rather than whether it was enabled. This caused seed generation to silently fall back to a non-cryptographic software PRNG ('Yasmarang'), seeded from non-secret data — the device's 32-bit chip ID and SysTick timer register (fewer than 80,000 possible values) plus the real-time clock — producing seeds with roughly 40 bits of entropy instead of the intended 128 bits. T0 — July 31, 2026, 01:31-01:56 UTC: Over a 25-minute window spanning three Bitcoin blocks, an attacker sweeps 594.48 BTC (~$38.3M) from approximately 500 single-signature wallets in 500 transactions moving 1,324 separate portions of bitcoin. All affected wallets had generated their seeds on vulnerable Coldcard Mk3 firmware. Roughly 562 BTC is later consolidated into a single address (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r), which remains unmoved as of reporting. July 30, 2026 (preceding the sweep by roughly 30 hours per later analysis): Coinkite publishes an emergency advisory warning Coldcard Mk3 users who generated a seed on firmware 4.0.1 or later, urging immediate migration to a newly generated seed on updated hardware. CoinDesk and other outlets report the incident on July 31, framing it as an emergency disclosure made ahead of full internal testing due to active exploitation. Bitcoin engineering researchers at Block, including security engineer Clay Garrett, trace the vulnerable code change to the March 2021 commit and publish a full technical writeup. Independent analysis (Galaxy Research, based on the same on-chain fingerprint) suggests the true scope could extend to as many as 1,082.65 BTC (~$70.2M) across additional addresses and a longer ~41-minute window — this broader figure is NOT confirmed by Coinkite and should be treated as a preliminary estimate. Coinkite releases patched firmware (4.2.0+ for Mk3, 5.6.0+ for Mk4/Mk5, 1.5.0Q+ for Q) and continues to characterize Mk4, Q, and Mk5 devices as unaffected based on early analysis. As of reporting, 0% of stolen funds have been recovered, and the attacker's identity remains unknown.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)