If you own a Coldcard, whether the bug affects you depends on when your seed was generated, not on what firmware you’re running today. Coinkite, the Canadian maker of Coldcard, says a coding error introduced in March 2021 caused some devices to generate wallet seeds using a predictable software routine instead of the device’s dedicated hardware chip for randomness, and the fix for that is to move your coins to a brand-new seed, not simply to update the firmware, per Coinkite’s disclosure as reported by The Hacker News on 1 August 2026.
A Bitcoin wallet’s security rests on its seed phrase, a string of words derived from a large random number. A standard 12-word BIP-39 seed is meant to carry 128 bits of randomness, according to The Hacker News’s 1 August 2026 report on Coinkite’s disclosure, enough that guessing the right one is not practical. Coldcard’s production configuration set a flag, MICROPY_HW_ENABLE_RNG, to zero because Coinkite supplies its own wrapper around the hardware chip. A library called libngu, per The Hacker News, checked only whether that flag existed rather than whether it was switched on, which silently bound affected builds to a fallback generator inside MicroPython called Yasmarang. That fallback drew its starting values from the chip’s unique ID and internal timer and gathered no further randomness afterward, according to the same report.
Coinkite’s own estimate, cited by The Hacker News on 1 August 2026 and corroborated independently by Block’s security team as reported by Blockhead on 3 August 2026, puts effective entropy at roughly 40 bits for seeds generated on affected Mk2 and Mk3 devices, and about 72 bits on affected Mk4, Mk5 and Q devices, against the 128-bit target. Block went further and found that only a fraction of the newer models’ extra randomness, equal to roughly 32 bits, actually reached the final seed, per Blockhead’s 3 August 2026 report. The Hacker News notes that Block did not publish a single practical brute-force cost; it described conditional ceilings that the published text renders as “below 240.7 and 273.3,” a notation the source does not explain and this page cannot reliably interpret. Block specifically warned that the higher of the two figures is not the same as 73-bit cryptographic security, since real-world attack cost depends on how much an attacker knows about a device’s unique ID, boot timing and prior use.
Exposure tracks the firmware that was running when a seed was first created, not the version installed now, per The Hacker News’s 1 August 2026 report. Coinkite lists Mk3 versions 4.0.1 through 4.1.9 as vulnerable, fixed in 4.2.0, and does not separately name Mk2; Block’s own analysis places both Mk2 and Mk3 versions 4.0.0 through 4.1.9 on the vulnerable path, a discrepancy The Hacker News reports without resolving. Mk4 and Mk5 devices are exposed on anything before version 5.6.0, and the Q on anything before 1.5.0Q; edge builds are exposed before 6.6.0X for Mk4/Mk5 and before 6.6.0QX for Q, according to the same report. Coinkite shipped emergency firmware for every affected model on 31 July 2026, per The Hacker News, but that patch stops new weak seeds from being created; it does not strengthen a seed generated before the patch.
Coinkite says a seed built from at least 50 fair, independent, private dice rolls is not at risk from this bug on its own, and tells owners to migrate to a new seed if the number or privacy of those rolls is in doubt, per The Hacker News, 1 August 2026. A strong BIP-39 passphrase creates a separate wallet that the bare seed words cannot reach, but Coinkite still recommends replacing the underlying seed, according to The Hacker News. Multisig setups help only where the signing quorum is not built entirely from affected devices. Coinkite’s TAPSIGNER, OPENDIME and SATSCARD products run different code and are not affected, per both The Hacker News and Blockhead’s 3 August 2026 report.
Both rival hardware wallet makers responded within days by saying their own devices were unaffected. Ledger CTO Charles Guillemet told Decrypt, in an article published 4 August 2026, that Ledger devices “draw their root secret (the 24-word Secret Recovery Phrase) from a true hardware random number generator built directly into a certified Secure Element, with no software fallback path,” adding that “that generator produces the full 256 bits of entropy for every seed.” Ledger executive Ian Rogers separately told Bloomberg, in reporting carried by BigGo Finance, that the resulting address space is an astronomically large figure — the number three followed by 67 zeros — which he said no attacker could realistically brute-force. BigGo’s summary table notes these figures as of 12 August 2026; that date marks when the figures were current, not a confirmed publish date for Bloomberg’s original reporting. Trezor, in a tweet quoted by Blockhead on 3 August 2026, told its users “your funds are safe,” saying the Coldcard problem is limited to Coldcard’s own firmware and that Trezor mixes randomness from multiple independent sources rather than relying on one path.
These are self-reported claims from Ledger and Trezor’s own social accounts and interviews, not conclusions from an independently published audit of either company’s random number generator named in the sources reviewed for this page. Guillemet also told Decrypt that “open source and reviewed are not the same thing,” pointing out the Coldcard flaw “sat in public code for more than five years” before, he said, an adversary reportedly used AI to find it.
Five outlets give five different totals, reflecting different cutoff dates and different counting methods rather than one settled figure. Galaxy Research, which mapped the first sweep itself, found 1,196 addresses drained in 41 minutes on 30 July 2026, taking 1,082.65 BTC worth about $70.2 million at the time, per The Hacker News. Galaxy’s own tracking rose further: The Hacker News’s update cites roughly 1,367.05 BTC, worth about $88.6 million, across 4,585 addresses. Blockhead’s 3 August 2026 report corroborates the same BTC and dollar figures, citing Galaxy Research’s tally of “more than 4,500 addresses” as of 2 August 2026, though Blockhead does not give the more precise 4,585 count. Decrypt’s 4 August 2026 article cited a running total of roughly $130 million. Bloomberg, via reporting carried by BigGo Finance, cited TRM Labs’ count of approximately 1,816 BTC, worth close to $116 million, drained from more than 5,200 addresses across four waves. Separately, Sesame Disk reported on 31 July 2026 that AnchorWatch chief executive Rob Hamilton had identified an earlier sweep of 594.48 BTC (about $38.3 million at a bitcoin price of $64,364.07, per CoinGecko as cited by Sesame Disk) across 1,324 unspent outputs in 500 transactions, of which 562 BTC was later consolidated into a single address.
Galaxy Research itself has cautioned that its estimates rest on on-chain pattern analysis rather than cryptographic proof: it said it has not computationally confirmed that every flagged address was generated with weak Coldcard entropy, and it warned that a third wave of sweeps should not be assumed to share an operator with the first two, per The Hacker News. Galaxy also said, in the same update, that it has passed roughly 600 addresses it suspects are attacker-controlled to law enforcement, compliance firms and cybersecurity contacts, per The Hacker News.
No public report reviewed for this page has reconstructed a specific victim’s seed and matched it to a drained address; the case rests on inference from transaction timing and signature patterns, per The Hacker News, 1 August 2026. Galaxy Research itself flagged that a sweep can look identical to a legitimate owner-initiated transfer, per The Hacker News, meaning its pattern analysis identifies a likely operator, not proof of theft. No attacker has been named. Wizardsardine chief executive Kevin Loaec offered an unconfirmed hypothesis, reported by Sesame Disk on 31 July 2026, that an attacker used an AI-generated script to brute-force a limited range of BIP-84 derivation paths; Loaec stressed this remained unconfirmed.
This page cannot give a single final loss total. Galaxy Research and TRM Labs were both still revising their counts upward with each newly identified wave as of the most recent reports reviewed here, and neither has published a closing figure. It cannot independently verify Ledger’s or Trezor’s claims about their own random number generators; those statements come from company tweets and interviews with Decrypt and Bloomberg, not from a third-party audit named in any source used for this page. It cannot resolve the conflict between Coinkite’s own advisory, which lists Mk3 firmware 4.0.1 through 4.1.9 as vulnerable, and Block’s independent analysis, which extends that range down to 4.0.0. It does not identify who carried out the thefts. And it cannot confirm that every address Galaxy Research and TRM Labs have flagged was, in fact, generated with the weak entropy described here — both firms have said their figures rest on pattern analysis of on-chain activity, not on cryptographically reconstructing the affected seeds.
Every fact above is attributed to one of these reports. Where they disagree, the article says so.
We measure how many people read this site. That is all it is used for — there is no ad network, no advertising cookie, and nothing sold to anyone. Decline and the site works exactly the same. What we collect