Go to app

The Technical Mechanism: Entropy Collapse

Published 8/4/2026, 7:28:43 AM

The Coldcard hardware wallet exploit, which began on July 30, 2026, resulted in the theft of approximately 1,367 to 1,750 BTC (valued between $89M and $116M) from roughly 4,585 to 7,700 addresses [Source: https://www.cryptotimes.io/2026/08/04/coldcard-exploit-drains-100m-from-7700-addresses/]. The incident was caused by a critical firmware flaw that drastically reduced the entropy (randomness) of generated private keys, allowing attackers to brute-force seeds offline and sweep funds.

The Technical Mechanism: Entropy Collapse

The vulnerability stemmed from a production configuration error in firmware versions dating back to March 2021 (starting with version 4.0.0). A specific flag, MICROPY_HW_ENABLE_RNG = 0, caused the devices to bypass their dedicated hardware random number generator (RNG) [Source: https://www.cryptotimes.io/2026/08/04/coldcard-exploit-drains-100m-from-7700-addresses/].

Attack Execution and Impact

The drain occurred in several highly efficient "waves," prioritizing the largest balances first.

WaveDate (2026)BTC DrainedEst. ValueAddresses Affected
Wave 1July 301,082.65 BTC~$70.2M1,196
Wave 2July 31~594 BTC~$38.6M~500
TotalBy Aug 2Up to 1,750 BTC~$116M~7,700

[Source: https://www.thestreet.com/crypto/news/coldcard-exploit-summary-2026, https://www.cryptotimes.io/2026/08/04/coldcard-exploit-drains-100m-from-7700-addresses/]

The attacker consolidated funds into a few primary addresses, such as bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r, where the majority of the stolen assets remained unspent as of August 4, 2026 [Source: https://www.thestreet.com/crypto/news/coldcard-exploit-summary-2026].

Affected Devices and Remediation

Coinkite released emergency firmware updates to re-enable the hardware RNG. However, updating the firmware does not secure an existing seed that was generated while the flaw was active.

ModelVulnerable FirmwareFixed Version
Mk2 / Mk34.0.0 – 4.1.94.2.0+
Mk4 / Mk5Before 5.6.05.6.0+
QBefore 1.5.0Q1.5.0Q+

[Source: https://www.thestreet.com/crypto/news/coldcard-exploit-summary-2026]

Critical Security Note: Users who generated their seeds using 50+ dice rolls or a strong BIP-39 passphrase (25th word) were generally protected, as these methods provided entropy independent of the flawed internal RNG [Source: https://www.cryptotimes.io/2026/08/04/coldcard-exploit-drains-100m-from-7700-addresses/]. All other affected users must generate a new seed on patched firmware and migrate funds immediately.

While the technical cause is resolved, the final count of affected addresses remains a range (4,585 to 7,700) as investigators continue to track smaller balance sweeps.