§ Guide · Intermediate

Has Coldcard been hacked? The verified record

No remote break-in for years — then seeds born predictable. The 2026 Coldcard entropy flaw, ≈$88.6M swept, the verified timeline, what buyers do now.

By dont-trust-verify Published August 2, 2026 Updated August 3, 2026

“Has Coldcard been hacked?” has a lazy answer and a precise one. The lazy answer — from fans, “never,” and from headline-skimmers, “yes, for $88 million” — is wrong in both directions. The precise answer requires splitting one word, hacked, into four different claims, because Coldcard’s record contains all four: laboratory attacks that never hurt anyone, firmware bugs fixed before exploitation, a company-data story that is routinely misreported, and — since July 30, 2026 — the single worst verified loss event in hardware-wallet history. This page is the verified record, each item labeled with what an attacker actually needed and whether it is fixed today.

TL;DR. No Coldcard has ever been broken into remotely — but yes, in July 2026 Coldcard users suffered the worst verified loss event any hardware wallet has produced, and it earned the word “hack” in every practical sense. From March 2021 to July 2026, a one-line firmware bug silently replaced the hardware random number generator with a predictable software PRNG, so seeds generated on affected firmware could be brute-forced entirely offline, with zero access to the device. On July 30, 2026, attackers swept ≈1,082.65 BTC (≈$70.2M) from 1,196 addresses in 41 minutes; tracked losses grew to ≈1,367 BTC (≈$88.6M) across 4,585 addresses over three waves, per Galaxy Research — figures still evolving. The device wasn’t hacked; the seeds were born predictable. A firmware update alone does not fix an existing seed — affected users must generate a new seed on fixed firmware (Mk3 4.2.0+, Mk4/Mk5 5.6.0+, Q 1.5.0Q+) and migrate. Everything else in Coldcard’s history is lab attacks requiring physical possession, or remote-class bugs patched before known exploitation. No confirmed breach of Coinkite’s servers has ever occurred, and no counterfeit Coldcard hardware has ever been documented.

The event you actually heard about: July 30, 2026

When someone asks this question in August 2026, they almost always mean one thing: Coinkite’s July 30 advisory (updated August 1) and the on-chain sweeps that landed the same day.

The mechanics are almost embarrassingly small. In March 2021, a firmware migration switched Coldcard’s seed generation off the STM32 chip’s hardware true-random-number generator and onto MicroPython’s deterministic Yasmarang software PRNG — because a build flag was set to 0 and the code checked whether the flag was defined instead of what its value was. One preprocessor line. Block’s engineers, working with anonymous researchers after reports from affected users, found it five years later; nobody had noticed in the interim, despite open source and reproducible builds. The result, per Coinkite’s entropy backgrounder: seeds generated on Mk2/Mk3 firmware 4.x carried roughly 40 bits of effective entropy, and seeds on Mk4/Mk5 before 5.6.0 and Q before 1.5.0Q roughly 72 bits — against an intended 128. (Block’s own enumeration estimates run lower still — as little as ≈2^16 of work for Mk2/Mk3, and at most ≈2^32 for the later models.) (One caveat worth keeping: Coinkite’s advisory dates the affected range from 4.0.1, Block says the regression shipped in 4.0.0 — so the safe phrasing is any Mk2/Mk3 seed generated on firmware 4.x before 4.2.0.)

Forty bits is a weekend of computation. Attackers enumerated candidate PRNG output streams offline, derived addresses, and checked them against the public blockchain — no device access, no malware, no phishing, no user error. On July 30, between 01:10 and 01:51 UTC, Galaxy Research tracked 1,082.65 BTC (≈$70.2M) drained from 1,196 addresses in 41 minutes. Over three waves the tracked total grew to ≈1,367 BTC (≈$88.6M) across 4,585 addresses — and Galaxy said the attack was ongoing, so treat every total as a snapshot, not a final score. Wave-one figures even differ across outlets — CoinDesk reported ≈594 BTC over 25 minutes for wave one where Galaxy tracked 1,082.65 over 41 — and Coinkite’s own advisory cites no theft figures at all; the loss attribution is Galaxy and Block analysis.

Three things this event is not, because the conflations are everywhere: it is not a remote break-in of the device (nothing ever connected to any Coldcard); it is not a Coinkite server breach (none has ever been confirmed — more below); and it has no CVE number — if you see one cited, it was invented. And the sentence that matters most, straight from the advisory: updating firmware does not repair a seed that already exists. Affected users must update, generate a new seed on fixed firmware, verify the backup and a receive address, send a test transaction, and migrate. Seeds made with 50+ private dice rolls, and funds behind a strong unique BIP-39 passphrase, are not at risk from this flaw alone; TAPSIGNER, OPENDIME and SATSCARD are unaffected.

On July 31 — about 24 hours after disclosure — Coinkite shipped fixed firmware for every model, including a new 4.2.0 build for the discontinued Mk2/Mk3. CEO Rodolfo Novak apologized, said he takes “full accountability for the firmware bug,” admitted review had failed, and urged users to move funds. Two honesty notes on the aftermath: his remark that AI likely found the bug is speculation, not established fact — no concrete evidence has been published — and no compensation or reimbursement commitment exists in any official post as of early August 2026. A formal technical review has been promised but not yet published.

The rest of the record, item by item

The 2026 disaster deserves its own section; the rest of Coldcard’s history deserves honest sorting. The sorting key is always the same question: what did the attacker need?

Four kinds of “hacked” — ranked by what the attacker needsFour kinds of “hacked” — what did the attacker need?NOTHING AT ALL2026 entropy flaw — weak seeds brute-forced offline. No device, no malware, no contact.EXPLOITEDYOUR COMPROMISED COMPUTER2020–21 isolation-bypass and multisig bugs — patched before any known exploitation.FIXEDSUPPLY CHAIN — TAMPERED BEFORE DELIVERYNo documented counterfeit Coldcard device — only fake websites in phishing letters.NO CASEPHYSICAL LAB — DEVICE IN HAND + ≈$200K GEARDonjon laser PIN extraction (Mk2, 2020) — nation-state class, no real-world victims.LAB ONLY Coldcard security timeline, 2020–2026The record on one line, 2020 → 20262020Donjon laser PIN attack (Mk2) — lab-grade; Mk3+ immune2020–21Isolation-bypass + multisig xpub bugs — fixed pre-exploitation2021-03RNG bug ships silently in firmware 4.x — the five-year fuse is lit2023Donjon faults Mk4’s second secure element — seed never reached2026-06Phishing paper letters from third-party leaks — no Coinkite breach2026-07-30Entropy disaster disclosed — ≈1,367 BTC (≈$88.6M) tracked swept2026-07-31Fixed firmware for every model — but existing seeds need migration

Remote-class firmware bugs, 2019–2021 — fixed before known exploitation

These required a compromised computer, not a stolen device — the same threat class as the 2026 flaw’s exploitation, which is why they matter:

The pattern worth naming: every one of these was fixed before any known exploitation — and Coinkite’s 2020–2021 instinct was to downplay and quiet-patch, a documented contrast with its fast, contrite 2026 response.

Laboratory attacks, 2020 and 2023 — physical possession, no victims ever

A lab attack that needs your specific device in hand, a chip lab, and six figures of equipment is a different universe from a flaw exploitable against everyone at once from a laptop. Both are worth knowing about; only one has ever cost anyone money.

The two side stories people conflate with “hacked”

The honest scoreboard: every vendor has a record

Here is where this page has to be careful, because this site earns commission on Trezor links, and the cheap move would be to let the Coldcard section above do the selling. So let’s put Trezor’s record on the same table, with the same rigor.

Trezor’s published attack history is longer than Coldcard’s: the wallet.fail seed extraction at 35C3 (2018); Donjon’s ≈$100 board that pulled a seed from a stolen Trezor One or Model T in about five minutes (2018, architecturally unfixable on those models); a power-analysis PIN recovery (fixed in firmware, 2019); Kraken’s voltage-glitch attack (2020, ≈15 minutes of physical access, silicon-level); Unciphered’s Trezor T extraction (2023 — Trezor’s CTO confirmed it’s substantially the same silicon flaw Kraken found); a Donjon supply-chain-implant scenario on the Safe 3 (2025 — realistic victim: someone buying second-hand or from an unauthorized seller; Safe 5 not affected; resolved); and a Donjon laser fault against the Safe 7’s brand-new secure element (2026 — funds not at risk because PIN, backup and keys are split across three independent chips; firmware mitigation shipped, hardened silicon due late 2026).

Count the entries and Trezor “loses.” But the records differ in class, not just count, and class is what empties wallets:

Mandatory disclosure while reading any of this: most Trezor findings and both Coldcard physical findings came from Ledger’s Donjon — a direct commercial competitor of both (both vendors confirmed the research; Trezor pays Donjon bounties). The 2026 Coldcard root cause, by contrast, came from Block, and the loss data from Galaxy Research — neither a hardware-wallet competitor — making it the cleanest-sourced item on this page.

What this means if you’re choosing a wallet today

Threat-model the record instead of vibing it. If your risk is a burglar or a border crossing — someone physically taking the device — the lab-attack rows matter, and the answer on every brand is the same: current-generation secure-element hardware plus a passphrase. If your risk is remote and scaled — the class that actually produced victims — the 2026 lesson is that the seed’s birth is everything: generated on current firmware, on hardware whose supply chain you didn’t take on faith, with entropy you can optionally supply yourself via dice.

That last clause is why the boring purchase advice keeps winning: buy new, direct from the maker. A used device stacks unverifiable history on top of whatever the vendor’s record already holds — the full argument is in is a used hardware wallet safe, and if you’re buying from Thailand, the channel-by-channel version is in buying a Trezor in Thailand. Note that the one realistic Trezor Safe 3 attack scenario (the 2025 supply-chain implant) and the used-device scam catalog point at the same mitigation. And whatever you run today, put your addresses on a watch-only alert — Watchtower exists because the first sign of a compromised seed is an on-chain movement, and July 30 gave 4,585 addresses that lesson at once.

Where do I land personally? My daily recommendation was Trezor before July 2026 and still is — but the reasons haven’t changed, and none of them is “Coldcard got hacked.” Current-generation secure elements, fully open source, passphrase support that neutralizes the entire physical-attack class, and a price that doesn’t punish starting small. If your threat model differs, run it through the hardware wallet picker — six questions, no brand loyalty — and the Safe 3 vs Safe 5 comparison settles the entry-level question head-to-head. Standard disclosure applies: this site earns a commission on the link below; the record above doesn’t care who profits.

FAQ

Is my Coldcard safe right now?

Firmware version today is the wrong question; seed origin is the right one. Seeds generated on Mk2/Mk3 firmware 4.x before 4.2.0, Mk4/Mk5 before 5.6.0, or Q before 1.5.0Q are predictable and actively being swept — treat them as compromised. Update, generate a new seed on fixed firmware, test, migrate. Dice-roll seeds and passphrase-protected funds are outside this flaw; TAPSIGNER/OPENDIME/SATSCARD unaffected.

Was the device actually hacked remotely?

No device was ever touched. The seeds were generated with ≈40 or ≈72 bits of effective entropy instead of 128, and attackers brute-forced them offline against the public blockchain. That’s worse than a device hack in one way — it needed no access to anything — and it’s why a firmware update can’t repair a seed that already exists.

Should I switch brands?

You’re migrating to a new seed either way, so it’s a fair moment to choose hardware fresh. Weigh classes, not counts: Trezor’s longer list is all physical-access, passphrase-mitigated, zero mass theft; Coldcard’s shorter list contains the one flaw in history that drained wallets remotely — answered by a fast, accountable fix. Whatever you pick: new, direct, current generation, with a passphrase.

Is counterfeit Coldcard hardware a thing?

No documented case exists, 2019–2026. The only counterfeits on record are fake Coinkite websites linked from fraudulent paper letters in mid-2026 — a phishing campaign, explicitly not a Coinkite breach. No vendor sends paper letters about firmware, and nothing legitimate ever asks for your seed.

Lab attack vs. real-world hack — why do you keep splitting hairs?

Because prerequisites are the whole story. No physical lab attack — $200k laser rig included — has ever been traced to documented mass theft on any brand, though a stolen, passphrase-less device from the unfixable-extraction era can’t be assumed safe; that’s exactly why the passphrase advice exists. A predictable-seed flaw exploitable from a laptop produced ≈$88.6M of tracked theft in days. Headlines price both the same; your threat model shouldn’t.

What would make you change this assessment?

Checkable events: Coldcard’s promised technical review not appearing or contradicting the disclosure; another generation-class flaw anywhere; any current-generation Safe-series seed extraction without physical access; any verified real-world theft traced to a Trezor vulnerability. Theft totals cited here are Galaxy Research tracking as of early August 2026 and still evolving — we update dated claims as the record moves.