2026 Coldcard — RNG fallback flaw; ~594 BTC (~$38M) drained from ~500 wallets
Data compromised
Bitcoin private keys / wallet seeds generated with flawed entropy — ~594 BTC (~$38M) stolen from ~500 single-signature wallets in ~25 minutes (on-chain); paper-wallet keys and related derived secrets also in scope of the flawed generator per Block/Coinkite analyses
Technical writeup
Verified vendor advisory + on-chain/trade-press reporting — July 30–31, 2026. Coinkite published a Coldcard Mk3 security advisory after Block’s Bitcoin engineering team disclosed a predictable RNG fallback: firmware could skip the hardware RNG and fall back to software entropy seeded from non-secret chip data (serial/clock), introduced around firmware 4.0.0 (Mar 2021). CoinDesk reports ~594 BTC (~$38M) swept from ~500 single-sig wallets between 01:31–01:56 UTC July 31 in a ~25-minute window. Coinkite warned users who generated seeds on Mk3 4.0.1–4.1.9; later updates state fixed firmware for Mk3/Mk4/Mk5/Q tracks and that Mk4/Q/Mk5 seeds generated before fixed builds had reduced entropy (~72 bits vs expected 128). Firmware updates do not repair existing seeds — migration to a new seed on fixed firmware (or dice-entropy exceptions) is required. TAPSIGNER/OPENDIME/SATSCARD not affected. Catalog indexes recordsAffected 500 as the reported drained-wallet count (not a traditional PII breach).
Root cause
Firmware RNG fallback made device-generated seeds insufficiently random (Mk3 4.0.1–4.1.9; also reduced entropy on Mk4/Q/Mk5 before fixed builds); attackers swept predictable single-sig wallets