Bitcoin Forum
August 02, 2026, 11:09:57 AM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: ColdCard Mk3 exploit. 500 wallets drained.  (Read 163 times)
Meuserna (OP)
Sr. Member
****
Offline

Activity: 329
Merit: 528


View Profile WWW
July 31, 2026, 12:35:36 AM
Merited by dkbit98 (1), Stalker22 (1)
 #1

From reddit:

Quote
Security Advisory with exploit in Cold Card MK3

An exploit , likely a flaw in rng generation with lower entropy in firmware but waiting on more details from investigation, has allowed an attacker to drain what appears 594 BTC from many Cold Card MK3 wallets

From Coinkite:

Quote
Security Advisory

Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk.

Mk4, Q and Mk5 are not affected based on our early analysis of the issue.

The issue is present through firmware version 5.0.3, the final release that supported Mk3.

If You Used a Passphrase

If the affected Mk3 seed was used with a BIP-39 passphrase, our early analysis indicates that your funds are at minimal risk from this issue.

I'm not a ColdCard user, but still... this is a very sad day. My heart goes out to those affected.

Charles-Tim
Legendary
*
Offline

Activity: 2352
Merit: 6466


Leading Crypto Sports Betting & Casino Platform


View Profile
July 31, 2026, 12:39:04 AM
Merited by estenity (1)
 #2

https://bitcointalk.org/index.php?topic=5589927.msg66995578#msg66995578

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
dkbit98
Legendary
*
Offline

Activity: 3038
Merit: 8778



View Profile WWW
July 31, 2026, 05:45:20 AM
 #3

I never liked c0ldcard or their NVK ego-nutcase, and I am not sorry for people losing coins from using non-open source devices with weak ass entropy.
NVK even posted and delete stuff with his X account, and I think he needs help from a shrink asap.
Rest in Pieces.

PS
Funny thing that Foundation devices that forked from their old code and remained open source are SAFE.  Cool

Quote
Foundation has confirmed that all Passport models have always correctly generated seeds with 128 bits of entropy (or 256 bits for 24 word seeds). All Passports are safe and secure.
https://x.com/FoundationHQ/status/2083033226562420969

▄▄██████▄░░░▄██████▄▄
██▀▀░░░░░░░░░░░░░▀▀██
▄▄██████▄▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
██████████
▐████▌▐████▌
▀▀▀█░░░█▀▀▀
 
Pmalek
Legendary
*
Offline

Activity: 3570
Merit: 9409



View Profile
July 31, 2026, 06:58:11 AM
 #4

This is a pretty sad day all round. I know that we have Coldcard users in our forum community. I can only hope they weren't affected or if they were that it wasn't a complete loss of all their bitcoin. What's interesting about this incident is that people are reporting that not all of their coins from all addresses got stolen. Victims talk about partial losses. Some of their UTXOs got spent, others were left intact.

At this point in time while the investigation is still early, it's better to consider all Coldcards as unsecure than thinking it's not going to affect me. Mk2, Mk3, Mk4, the Q, and the new Mk5. Single-sig setups with no passphrases are worse off than passphrase-protected wallets and multi-sig.


From Coinkite:

Quote
Security Advisory

Mk4, Q and Mk5 are not affected based on our early analysis of the issue.
Coinkite has edited the initial blog post. Mk4, Q, and Mk5 are also affected, with seeds being generated with less than the standard bits of entropy.

Quote
Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.

TAPSIGNER, OPENDIME and SATSCARD are not affected by this bug as they are different codebases

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Meuserna (OP)
Sr. Member
****
Offline

Activity: 329
Merit: 528


View Profile WWW
July 31, 2026, 07:34:11 AM
 #5

Adding this, from the other thread. I bolded the part that makes me want to scream:

Here's a post in X about WHY it may have happened,

Quote

Regarding the Coldcard entropy bug – many folks are explaining what happened but I wanted to take a minute to explain why it may have happened.

It's a disastrous situation and our heart goes out to all the Bitcoiners affected.

Here's a timeline of events:

On July 28 2020: @FoundationHQ announced our first Passport hardware wallet and noted that we were building on Coldcard firmware which at the time was GPLv3 licensed (FOSS license).

On July 30 2020: NVK publicly said he regretted choosing GPL because Coldcard now had a “clone” and that they would change things in future updates. x.com/nvk/status/128…

On November 18 2020: Coldcard added its MIT + Commons Clause license, prohibiting commercial products substantially derived from the software. github.com/Coldcard/firmw…

On January 8, 2021: Coldcard firmware 3.2.1 formally announced, “License changed from GPL to MIT+CC on files for which the GPL doesn’t apply.” CC is the "Commons Clause" license addendum which is "source available" instead of FOSS.

On March 1, 2021: The “First pass w/ libNgU” commit removed the GPL @Trezor-derived crypto libraries and replaced them with libNgU. That same 120-file commit changed seed generation code. libNgU was licensed with a novel “Licensed for Bitcoin Only” license.

On March 17, 2021: Version 4.0.0 announced that all crypto and BIP39 code had been replaced and that the “last remaining GPL code” was removed. blog.coinkite.com/version-4.0.0-…
github.com/Coldcard/firmw…

Our best understanding right now is that the entropy bug was collateral damage from this major overhaul of the codebase.

To be clear, this overhaul was not solely about licensing. Coldcard also cited technical goals including adopting Bitcoin Core’s libsecp256k1, faster AES and SHA implementations, and reproducible builds.

But the timeline establishes two things:
(1) Foundation’s launch was the obvious impetus for Coldcard’s licensing change, and
(2) removing the remaining GPL code was an explicit goal of the subsequent v4 rewrite.

We don't know by how much the licensing pressure affected the scope or timeline of the rewrite. All we can determine is that the entropy bug was introduced inside the same 120-file commit that removed the old GPL code dependencies.

https://x.com/zherbert/status/2082993276324319713


Personally, for people who use ColdCard, remove all your assets, throw the wallet away, AND NEVER buy another hardware wallet from them again.

It's infuriating.

I don't even know how to put in words how devastating a decision they made based on greed was for customers who trusted them.

I said this in the other thread, but it's worth repeating here.

I'm a former Ledger user. When Ledger added internet-based key extraction to their firmware, it shook me to my core. It made me rethink everything I thought I knew about doing self custody right.

I decided the only way to be sure my seed phrase was safe was to generate it myself so I could prove the randomness by doing it randomly.

I did this by printing the BIP39 word list. I cut the paper into strips with a word on each strip. I put the strips in a giant popcorn bowl.

Pick a word. Write it down. Put the strip back in the bowl and stir them up to scramble ‘em. Pick another word.

I did this 23 times.

I entered those 23 random words in a SeedSigner and let it generate the 24th word. With a 24 word seed phrase, there are usually only 7 or 8 words that can form a valid checksum, so I felt safe letting code find the final word.

I trust code, but not for generating the entropy my wallet is generated from. That being said, I also use a very strong passphrase because I take this stuff seriously. As should we all.

Brand loyalty for securing Bitcoin is proof of stupidity.

I expect the fallout from this current exploit to get worse. ColdCrd has already acknowledged that it goes beyond the MK3. A decision based on greed is making hodlers poor and hackers rich. I'd spit in MVK's face if he was standing in front of me now, and I'm not even affected by this hack.

This is awful, but it's only going to get worse.

If you're a ColdCard user, assume your seed is compromised and move your coins to a wallet protected by a passphrase or multisig. Long term: Generate your own seed phrase and move to ShieldSigner.

If you're a Ledger user, you're a fool. Assume your wallet is compromised, because if it isn't yet it's only a matter of time before it is. Move your coins to a wallet generated by a seed that has never touched a Ledger device.

If you're using some cool mofo brand device, you're a fool. Learn real self custody security. Take the security of your coins seriously. If you don't have the technical skills, you should seriously consider selling your coins and using the money to buy into an ETF instead. It saddens me to say that, but self custody comes with self-responsibility. Anyone who isn't up to it shouldn't do it.

Sigh.

Stalker22
Legendary
*
Offline

Activity: 2310
Merit: 1610



View Profile
July 31, 2026, 08:01:45 AM
 #6

This is fucking inexcusable.  All this damage just to feed someones ego, all because they wanted to strip the GPL clean from their source code?  Well, I guess they got what they wanted - nobody is ever going to clone their code or build new hardware with it again.  Honestly, I hope they rot in hell.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
Polkat
Jr. Member
*
Offline

Activity: 53
Merit: 66


View Profile
July 31, 2026, 11:04:59 AM
Merited by Lucius (1)
 #7

It’s clear that Coldcard messed up with the built-in generator, but this isn’t exactly an ordinary wallet—it was designed for advanced users and the paranoid.
Such people typically generate their seed using dice, use passphrases, and purchase such wallets to set up multisig arrangements.
I’m sure the victims didn’t fully grasp the purpose of the wallet they were buying; they likely just thought it was cool, which is what ultimately led to their undoing. I’m not defending Coldcard, but I do believe you shouldn’t buy products like this unless you fully understand what they are designed for and why all their specific features are necessary.
NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10037


┻┻ ︵㇏(°□°㇏)


View Profile WWW
August 01, 2026, 06:20:13 AM
 #8

PS
Funny thing that Foundation devices that forked from their old code and remained open source are SAFE.  Cool

In the other thread, I wrote that this is because Coldcard changed the code during the GPL rewrite and the RNG used got changed as a result.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Meuserna (OP)
Sr. Member
****
Offline

Activity: 329
Merit: 528


View Profile WWW
August 01, 2026, 08:06:49 PM
 #9

PS
Funny thing that Foundation devices that forked from their old code and remained open source are SAFE.  Cool

In the other thread, I wrote that this is because Coldcard changed the code during the GPL rewrite and the RNG used got changed as a result.

And you are exactly right.

All of this is happening because Coinkite switched their code from being open source to "Source Verifiable" in 2021.

NVK didn't want anybody to be able to use ColdCard's code for their own projects, so he switched the license for the code. That decision was made out of hubris and greed. And that decision is having devastating consequences.

The current total for known robberies due to ColdCard is now 1,367 BTC and climbing:

Quote
JUST IN:

A third Coldcard hack has been reported with another 207.7294 BTC stolen.

A total of 1,367.05 BTC has been stolen from 4,585 addresses so far, according to Galaxy Research.

-- Bitcoin Magazine, on Xwitter

The irony is, ColdCard began by using Trezor's code. Trezor was and still is open source. But ColdCard didn't want others to use their code, so they changed from being open source to "source verifiable." NVK used Trezor's code, but NVK doesn't want anybody using his code.

This bug was introduced in the code at the time of that switch, in 2021.

The robberies we're seeing now were caused by too few people actually working with ColdCard's code. Because people could read the code but not use it for their own work, they didn't use it for their own work.

Bugs are more often found when people work with code, not when they just read it.

This was a catastrophic bug. If ColdCard's code had stayed open source, this bug would have been found and fixed in 2021.

This is NVK's fault. Full stop.

This is only going to get worse because, now that the exploit has been found, every other hacker is working on it too, and they're draining everything they find the moment they find it because the exploit is known.

It's now a race between hodlers moving their coins to safe wallets and hackers trying to find unsafe wallets.

NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10037


┻┻ ︵㇏(°□°㇏)


View Profile WWW
Today at 04:42:57 AM
 #10

The thing is, they could've hired a security firm to audit the code at any time and all this would've been avoided, as the bug would've been found.

Instead, they had this on the front page for a long time



I actually believed them and was about to purchase a Coldcard Q a few weeks ago. Unfortunately(? Manye not so much now), I did not find a single HW seller in my city.

Regardless, I was always going to generate my own seed anyway, but because of the risk of fake HWs, not anything like this.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!