Kraken's Chief Security Officer, Nick Percoco, has pointed out a significant flaw in the Coldcard hardware wallets, specifically regarding the lack of independent testing for these devices.
— Nick Percoco (@c7five) August 2, 2026
Percoco noted that while auditors could verify the presence of an approved random number generator in the device, they could not confirm whether the operational firmware actually utilized it.
“Users are asked to trust the manufacturer’s implementation of the most critical function of the system without independent verification that the claimed entropy path is indeed being executed,” Percoco stated.
Why the Audit Missed the Issue
On July 30, Coldcard's manufacturer, Coinkite, issued a warning regarding a problem with the generation of seed phrases. This alert came shortly after significant withdrawals of funds.
Coinkite reported that the issue originated in March 2021 due to changes in the seed creation process and the integration of a new cryptographic library. Instead of utilizing a hardware true random number generator (TRNG) as intended, a weaker pseudorandom number generator from MicroPython was employed during wallet creation.
The pseudorandom number generator (PRNG) can produce sequences that appear random but can be predictable under certain conditions. Coinkite acknowledged that a substantial portion of the randomness in Coldcard came from the PRNG, which the company was unaware was being used in that section of the code.
According to a technical analysis by Block engineers, the production configuration of Coldcard had MICROPY_HW_ENABLE_RNG set to zero, and the libngu library checked for the presence of a macro rather than its activation. Consequently, the build resorted to a fallback generator, Yasmarang, from MicroPython.
For Mk2 and Mk3 versions 4.x, this meant a lack of cryptographic entropy in ngu.random. In contrast, Mk4, Q, and Mk5 devices added entropy from a secure element during boot, but only retained four bytes, limiting the search space.
Percoco emphasized that merely checking for a TRNG in a device does not ensure security. He argued that the industry needs audits that cover the entire pathway from the source of randomness to the actual firmware that generates the seed phrase.
Devices Affected
In its updated warning, Coinkite identified that funds secured with seed phrases generated on affected firmware versions without additional entropy from dice rolls or strong unique BIP-39-compliant passphrases are at risk.
The issue impacts Mk2 and Mk3 devices with firmware versions 4.0.1 to 4.1.9. It also affects seed phrases created on Mk4 and Mk5 devices prior to standard version 5.6.0 or Edge 6.6.0X, as well as on Q devices before standard version 1.5.0Q or Edge 6.6.0QX.
For Mk2 and Mk3, the risk is higher; according to Coinkite, such seeds might have around 40 bits of entropy. For Mk4, Mk5, and Q devices, the estimated entropy is about 72 bits instead of the expected 128 bits.
Updating the firmware does not rectify already created seed phrases. Coinkite has advised users of these wallets to update their devices, create a new seed, verify their backup, conduct a test transaction, and only then transfer the remaining funds.
Devices like TAPSIGNER, OPENDIME, and SATSCARD are unaffected as they utilize different codebases.
Losses Exceed $90 Million
On August 3, Alex Thorn, head of Galaxy Research, reported a suspected fourth wave of attacks targeting addresses resembling vulnerable Coldcard wallets. The initial estimate covered 218 transactions, 462 potential victim addresses, and around 388.9 BTC.
🚨 LIKELY 4TH ORGANIZED WAVE COLDCARD ATTACK OCCURRING RIGHT NOW
THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS
pattern identified:
— Alex Thorn (@intangiblecoins) August 3, 2026
blocks…
Thorn later revised the estimate, noting that the wave impacted 709 potential victim addresses and resulted in the movement of approximately 448.7 BTC. He also highlighted similar unconfirmed transactions in the mempool.
Thorn indicated that the activity matched the structure of vulnerable Coldcard UTXOs and exhibited an increased frequency of similar transfers. He referred to these addresses as “likely” victims of Coldcard but did not claim definitive attribution.
Earlier, Galaxy Research identified 1,196 addresses from which 1,082.65 BTC was withdrawn in just 41 minutes on July 30. This wave occurred roughly 30 hours before Coinkite's first warning.
We mapped the flow of funds for the Coldcard vulnerability based on the pattern identified by engineers at Block and shared by @clay_garrett
1,196 addresses drained in full for 1,082.65 BTC (~$70.2M) between 01:10:20 and 01:51:26 UTC on Jul 30 — a 41-minute window, blocks… pic.twitter.com/q785paZvMQ
— Galaxy Research (@glxyresearch) July 31, 2026
Experts have also documented an earlier mass withdrawal of 594.48 BTC over approximately 25–30 minutes. At that time, there was no public evidence linking it to Coldcard, and researchers described the low entropy version as a hypothesis.
As of this writing, total estimated losses have surpassed $90 million.
Coinkite Halts Shipments
On August 2, Coldcard suspended shipments of devices upon confirming the vulnerability. The remaining units with affected firmware were destroyed.
🚨 UPDATE: We halted COLDCARD shipments as soon as we confirmed the vulnerability. All remaining units at our facilities with affected firmware installed were destroyed.
Some orders had already shipped. We contacted those customers directly by email with the advisory and…
— COLDCARD (@COLDCARDwallet) August 2, 2026
Coinkite urged users not to discard older devices, as they may be needed if funds can be recovered.
According to the company’s statement, lawyers will engage with law enforcement in various jurisdictions to assist in identifying those responsible for the attack. Coinkite specifically advised users to avoid rushing through the migration process, warning that hastily transferring funds could create a more immediate risk than the vulnerability itself.
The Incident Raises Standards Questions
Percoco stated that hardware crypto wallets lack a verification process that systematically confirms the use of a validated source of entropy in operational firmware.
He compared the situation to other security segments, noting that payment industry PIN entry devices cannot be used without independent lab testing, and cryptographic modules for U.S. government agencies must undergo entropy source verification.
Percoco referenced standards such as NIST SP 800-90B and BSI AIS-31, with the former detailing requirements for the design, testing, and verification of physical sources of randomness for cryptographic protection, and the latter employed by the Federal Office for Information Security in Germany.
He noted that while hardware wallets possess certifications for secure elements, Common Criteria, CSPN, and audits funded by manufacturers, these do not always verify the complete path from the source of randomness to the execution of code in the operational firmware.
In July, Ledger researcher Baptiste Boualo exposed a vulnerability in Tangem hardware wallets, where a laser injection attack allows resetting the card's password and gaining control over the assets stored on it.
