Tools Crypto Exploit Tracker exploit-0014
Exploit record
Coldcard Mk3 Seed Entropy Sweep
- Loss
- $116M
- Attack vector
- Private Key Compromise
- Chain
- Bitcoin
- Sector
- Wallet
What happened
On 30 July 2026, bitcoin began draining out of Coldcard-generated addresses in waves, the first taking about 594 BTC from roughly 500 wallets in 25 minutes. TRM Labs' 5 August analysis puts the running total at about 1,816 BTC, roughly $116m, from more than 5,200 addresses across at least four waves, making it the largest hardware-wallet exploit of 2026 by TRM's accounting. Coinkite had disclosed the same day the draining began that a build flag set to zero in March 2021 replaced the hardware random number generator with a software fallback, cutting Mk3 seeds to roughly 40 bits of real randomness against a 128-bit target. No device was touched: the seeds were guessable.
A preprocessor guard tested whether MICROPY_HW_ENABLE_RNG was defined rather than whether it was set, so a value of zero satisfied it and the #error never fired. Coinkite puts the effective search space at about 40 bits on Mk3 and about 72 bits on Mk4, Mk5 and Q; 2^40 is roughly 1.1 trillion candidates, a search a computer can finish. Updating the firmware does not repair a seed that already exists. The attacker's signature is an identical hardcoded fee of about 30 sat/vB on every sweep, against a 0.4 to 1.0 median that week, though TRM notes transaction construction differs between waves, so there may be more than one attacker. Laundering has started at the margins: 64.9 BTC went into Wasabi and 200 ETH into Tornado Cash on 4 August, with the bulk still sitting in attacker addresses in public view. Coinkite destroyed its remaining vulnerable stock and halted shipments on 2 August, opened a permanent disclosure record on 4 August, and notes that AI-assisted review failed to catch the bug. It has not confirmed the theft was caused by its flaw. Figures are TRM's on-chain estimates and still moving.
On-chain references
- Consolidating address (501 inputs)mempool.space/address/bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8f…
- The 341-input onward transactionmempool.space/tx/0c6bf853a645b699a3b2cd6d8e3c44cf1a02a16f538…
- Address holding 562 BTC, unspentmempool.space/address/bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3f…
Sources
- YFarmX reportyfarmx.com/coldcard-mk3-entropy-40-bits/
- TRM Labs, inside the $116m Coldcard hackwww.trmlabs.com/resources/blog/the-largest-hardware-wallet-e…
- Coinkite, Mk3 Security Advisoryblog.coinkite.com/coldcard-mk3-seed-generation-warning/
- Coinkite, Technical Deep Dive into the Entropy Issueblog.coinkite.com/entropy-technical-backgrounder/
- Coinkite, update of 2 Augustblog.coinkite.com/update-sunday/
- Coinkite, adding to the public recordblog.coinkite.com/adding-to-public-record/
On YFarmX
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026
