21 BTC

Coldcard entropy exploit (2026)

Updated Random article
In plain words

A build/link error in Coldcard firmware from March 2021 (Mk2/Mk3 4.0.1–4.1.9, plus affected Mk4/Mk5/Q releases) made seed generation use MicroPython's software PRNG instead of the hardware RNG. Effective seed strength fell from 128 bits to ~40 bits on Mk2/Mk3 and ~72 bits on Mk4/Q/Mk5 (Coinkite's preliminary estimates). From 30 July 2026 attackers regenerated weak seeds offline and swept single-sig wallets in several waves; the devices themselves were not hacked.

What happened

A build/link error in Coldcard firmware from March 2021 (Mk2/Mk3 4.0.1–4.1.9, plus affected Mk4/Mk5/Q releases) made seed generation use MicroPython's software PRNG instead of the hardware RNG. Effective seed strength fell from 128 bits to ~40 bits on Mk2/Mk3 and ~72 bits on Mk4/Q/Mk5 (Coinkite's preliminary estimates). From 30 July 2026 attackers regenerated weak seeds offline and swept single-sig wallets in several waves; the devices themselves were not hacked.

What happened to the coins

Galaxy Research (14 Aug 2026): 1,778.84 BTC (~$112.7M) confirmed stolen from 8,600+ addresses; up to 2,417.35 BTC if unconfirmed footprints and 'Wave 4' are included. Earlier tallies: 1,596 BTC confirmed / 2,055 BTC with Wave 4 (Galaxy, 3 Aug) and ~1,816 BTC (TRM, 5 Aug). 1,531 BTC sat unmoved at attacker addresses; no multisig wallet was hit. Coinkite shipped fixes: 4.2.0 (Mk2/Mk3), 5.6.0 (Mk4/Mk5), 1.5.0Q (Q), Edge 6.6.0X/6.6.0QX. Updating does not repair an old seed.

On the Hacks & losses page

See also

References

  1. galaxy.com galaxy.com
  2. trmlabs.com trmlabs.com
  3. blog.coinkite.com blog.coinkite.com
  4. theblock.co theblock.co

Built from 21 BTC's checked data and the sources listed. Spotted an error? Trust the source over us.