A vulnerability in Coldcard hardware wallets has revealed a lack of independent testing for such devices. This was stated by Kraken's Chief Security Officer, Nick Percoco.
https://t.co/cIjpnVnMDM
— Nick Percoco (@c7five) August 2, 2026
According to him, auditors could verify the presence of an approved random number generator in the device but could not confirm that the operational firmware actually uses it.
"Users are asked to trust the manufacturer's implementation of the system's most critical function without independent verification that the approved entropy path is actually being executed," said Percoco.
Why the Audit Missed the Issue
On July 30, the manufacturer Coinkite published a warning about a problem in seed phrase generation. This came roughly 30 hours after the first major waves of fund withdrawals.
According to Coinkite, the error appeared in March 2021 after changes to the seed creation process and the integration of a new cryptographic library. Instead of the expected hardware true random number generator (TRNG), a weaker MicroPython pseudorandom number generator (PRNG) was used when creating the wallet.
A PRNG creates sequences that appear random but can be predicted under certain conditions. Coinkite acknowledged that a significant portion of randomness in Coldcard came from the PRNG, the actual use of which the company was unaware of in that part of the code.
According to a technical analysis by Block engineers, the production configuration for Coldcard defined MICROPY_HW_ENABLE_RNG as zero, and the libngu library checked for the presence of a macro, not its activity. Because of this, the build used the Yasmarang fallback generator from MicroPython.
For Mk2 and Mk3 version 4.x, this meant a lack of cryptographic entropy in ngu.random. For Mk4, Q, and Mk5, the situation was different: entropy from the secure element was added during boot, but only four bytes were retained as a result, limiting the search space.
Percoco noted that checking for the presence of a TRNG in the device does not guarantee security by itself. He said the industry needs an audit of the entire path: from the source of randomness to the actual firmware that creates the seed phrase.
Affected Devices
In an updated warning, Coinkite indicated that funds controlled by seed phrases created on affected firmware versions without additional entropy via dice rolls and without a strong unique BIP-39 passphrase are at risk.
The issue affected Mk2 and Mk3 with firmware versions 4.0.1–4.1.9 inclusive. It also concerns seed phrases created on Mk4 and Mk5 before standard version 5.6.0 or Edge 6.6.0X, and on Q before standard version 1.5.0Q or Edge 6.6.0QX.
The risk is higher for Mk2 and Mk3: according to Coinkite, such seeds could have had about 40 bits of entropy. For Mk4, Mk5, and Q, the company estimated the entropy at approximately 72 bits instead of the expected 128 bits.
Updating the firmware does not fix an already created seed phrase. Coinkite recommended users of such wallets to update the device, create a new seed, verify the backup, send a test transaction, and only then transfer the remaining funds.
TAPSIGNER, OPENDIME, and SATSCARD are not affected as they use different codebases.
Losses Exceed $90 Million
On August 3, Alex Thorn, Head of Galaxy Research, reported a suspected fourth wave of attacks on addresses resembling vulnerable Coldcard wallets. The initial estimate covered 218 transactions, 462 potential victim addresses, and about 388.9 $BTC.
🚨 LIKELY 4TH ORGANIZED WAVE COLDCARD ATTACK OCCURRING RIGHT NOW
— Alex Thorn (@intangiblecoins) August 3, 2026
THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS
pattern identified:
blocks...
Later, Thorn updated the estimate: according to his data, the wave affected 709 potential victim addresses and led to the movement of about 448.7 $BTC. He also pointed to similar unconfirmed transactions in the mempool.
Thorn noted that the activity matched the structure of vulnerable Coldcard UTXOs and was characterized by an increased frequency of similar transfers. He called these addresses "likely" Coldcard victims but did not claim the attribution was definitively proven.
Earlier, Galaxy Research identified 1,196 addresses from which 1,082.65 $BTC were withdrawn within 41 minutes on July 30. This wave occurred about 30 hours before Coinkite's first warning.
We mapped the flow of funds for the Coldcard vulnerability based on the pattern identified by engineers at Block and shared by @clay_garrett
— Galaxy Research (@glxyresearch) July 31, 2026
1,196 addresses drained in full for 1,082.65 $BTC (~$70.2M) between 01:10:20 and 01:51:26 UTC on Jul 30 — a 41-minute window, blocks... pic.twitter.com/q785paZvMQ
Separately, experts recorded an earlier mass withdrawal of 594.48 $BTC over approximately 25–30 minutes. At that time, there was no public evidence linking it to Coldcard, and researchers described the low entropy version as a hypothesis.
At the time of writing, the total estimated damage exceeded $90 million.
Coinkite Halts Shipments
On August 2, Coldcard halted device shipments after confirming the vulnerability. The company destroyed all remaining units with the affected firmware at its facilities.
🚨 UPDATE: We halted COLDCARD shipments as soon as we confirmed the vulnerability. All remaining units at our facilities with affected firmware installed were destroyed.
— COLDCARD (@COLDCARDwallet) August 2, 2026
Some orders had already shipped. We contacted those customers directly by email with the advisory and...
Coinkite asked users not to discard their old devices. According to company representatives, they might be needed if the funds can be recovered.
According to the statement, lawyers will engage with law enforcement agencies in various jurisdictions to assist in identifying those responsible for the attack. In the warning, Coinkite specifically asked users not to rush the migration. The company noted that a hasty transfer of funds could create a more immediate risk than the vulnerability itself.
Incident Raises Standards Question
According to Percoco, hardware cryptocurrency wallets lack a verification process that systematically confirms the use of a validated source of entropy in the operational firmware.
He compared the situation to other security segments. In the payment industry, PIN entry devices are not allowed for use without independent laboratory testing, and cryptographic modules for US government structures must undergo entropy source validation.
Percoco mentioned standards NIST SP 800-90B and BSI AIS-31. The first describes requirements for the design, testing, and validation of physical randomness sources for cryptographic protection; the second is used by the German Federal Office for Information Security (BSI).
According to him, hardware wallets have secure element certifications, Common Criteria, CSPN, and audits paid for by manufacturers. However, they do not always verify the full path from the source of randomness to code execution in the operational firmware.
Recall that in July, Ledger Donjon researcher Baptiste Boileau disclosed a vulnerability in Tangem hardware wallets. The attack, via laser fault injection, allows resetting the card's password and gaining control over the assets stored on it.
Cold Wallets: Sharing Access Below Zero





