Coinkite disclosed an ongoing security incident in which vulnerable COLDCARD firmware generated wallet seeds with weak entropy, allowing attackers to reproduce seeds offline and steal funds. The company said a build and link integration error during its libNgU migration caused seed generation to use MicroPython’s non-cryptographic Yasmarang PRNG instead of the intended hardware true random number generator, despite MICROPY_HW_ENABLE_RNG=0 being meant to disable the software path. Coinkite halted shipments, destroyed remaining affected inventory, released patched firmware for newly generated seeds, and warned that seeds already created on vulnerable devices remain at risk; SATSCARD, OPENDIME, and TAPSIGNER were not affected.
External reporting said the exploitation began rapidly, with Galaxy Research estimating attackers drained 1,367 BTC—about $88.6 million—from 4,385 addresses across multiple attack waves after an initial 41-minute sweep of 1,082.65 BTC from 1,196 addresses. Coinkite urged users who created seeds on affected firmware without at least 50 independent private dice rolls and a strong unique BIP-39 passphrase to move funds to a new wallet immediately, while preserving affected devices for possible recovery and law-enforcement action. The company also temporarily suspended its normal 120-day customer data blanking process to preserve records for ongoing and anticipated legal proceedings, while allowing customers to request exemption from that retention protocol.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
On August 7, Coinkite announced a temporary change to customer data handling by suspending its normal automated blanking of records after 120 days. The company said legal obligations tied to ongoing and anticipated legal proceedings from the incident required preserving potentially relevant records until further notice.
Coinkite said it published a historical disclosures page documenting known public security research, coordinated disclosures, professional reviews, internal findings, and security advisories affecting COLDCARD devices. The page was announced as part of its August 4 investigation update.
On August 4, Coinkite said the vulnerability was caused by a build and link integration error during the libNgU migration, not an intentional weak fallback or hardware TRNG failure. It urged users who created seeds with affected firmware, without at least 50 private dice rolls and without a strong unique BIP-39 passphrase, to move funds to a new wallet immediately.
Galaxy Research warned on August 2 that the Coldcard exploit was ongoing and urged users to move single-signature Coldcard funds to safe locations immediately. It also said about 600 suspected stolen-fund addresses had been reported to federal investigators and industry partners.
On August 2, Coinkite said customers had lost funds, urged users not to discard affected devices because they may be needed for recovery, and said its legal team may coordinate with law enforcement across multiple jurisdictions. It also stated that SATSCARD, OPENDIME, and TAPSIGNER were not affected.
In its August 2 update, Coinkite said it had halted shipment of affected COLDCARD inventory when the vulnerability was confirmed, destroyed remaining affected inventory, and released patched firmware. The company warned the fix protects only newly generated seeds and told users with vulnerable seeds to create a new seed and move funds.
SlowMist reported that by early August 2026, confirmed losses from the Coldcard seed-generation exploit had reached at least 1,719 BTC, worth about $111 million, across more than 5,200 addresses. The article said the thefts occurred in three to four waves, extending the scale beyond previously reported totals.
Galaxy Research identified second and third attack waves on August 1, raising the total stolen to 1,367 BTC worth about $88.6 million. The total known victim count rose to 4,385 addresses.
Coinkite disclosed a security incident on July 30, 2026. The incident later prompted legal preservation of customer records and multiple public updates from the company.
Galaxy Research said the first wave of attacks began on July 30, draining 1,082.65 BTC from 1,196 addresses in 41 minutes. Block’s Bitcoin Engineering and Security team said the same day that the incident stemmed from exploitation of a firmware vulnerability dating back to 2021.
Coinkite said Yasmarang did not become part of COLDCARD’s seed-generation path until the libNgU migration in March 2021. A build and link integration error caused libNgU’s rng_get() symbol to resolve to Yasmarang instead of relying exclusively on the hardware TRNG.
Coinkite said MicroPython’s built-in general-purpose Yasmarang PRNG was introduced upstream in May 2018. This later became relevant to the COLDCARD seed-generation vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
slowmist.medium.com
Open sourceblog.coinkite.com
Open sourceblog.coinkite.com
Open sourceinfosecurity-magazine.com
Open sourceblog.coinkite.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.