Active incident · public on-chain research

COLDCARD entropy incident: check a public address and review the evidence.

A firmware integration bug in affected COLDCARDs could generate wallet seeds with far less unpredictable entropy than expected. Researchers say an attacker could search a much smaller candidate seed set, derive matching private keys, and drain wallets. On July 30, 2026, 500 source addresses were swept in 500 transactions totaling 594.47722484 BTC, followed by 562.01962301 BTC later consolidated. The entropy flaw is confirmed, but public evidence does not establish it caused every sweep transaction.

An address match can identify inclusion in this dataset; it does not prove ownership, cause, or that a wallet is otherwise safe.

Check a public Bitcoin address

Lookup happens locally in your browser. No query is sent or logged.

Never enter a seed phrase, private key, passphrase, PIN, xpub, wallet backup, or wallet file.

If you may be affected

Take safety steps before trying to explain the loss.

  1. 01

    Confirmed

    Check only a public address

    Use this local checker with a public Bitcoin address. Never enter a seed phrase, private key, passphrase, or wallet export.

  2. 02

    Confirmed

    Confirm addresses on-device

    Use COLDCARD Verify Address or Address Explorer, noting their automatic verification range and path limits.

    Read the supporting guidance
  3. 03

    Confirmed

    Move remaining funds to a genuinely new seed

    Create fresh entropy on a patched or otherwise trusted device; do not reuse or restore the old seed. Verify the destination and consider a small test payment.

    Read the supporting guidance
  4. 04

    Confirmed

    Preserve evidence, never secrets

    Keep public TXIDs, addresses, UTC times, amounts, screenshots, notifications, device details, and case numbers. Do not send secret material to this site or anyone else.

Confirmed on-chain snapshot

The primary metrics are deliberately narrow.

Snapshot: 2026-07-31 10:39:59 UTC. These values include the 500 coordinated sweep transactions, confirmed in just over 15 minutes (15m18s), and exclude a later dust event so they should not be confused with lifetime address activity.

Coordinated sweep transactions

500

Confirmed in blocks 960188–960191 during a 15m18s confirmation window.

View supporting on-chain record
Unique source UTXOs

1,324

From 500 unique source addresses; no address was reused across sweep transactions.

View supporting on-chain record
Unique source addresses

500

One source address per sweep transaction; no source address was reused across the coordinated sweep.

View supporting on-chain record
Total source input

594.51379184 BTC

Aggregate source inputs in the confirmed coordinated sweep.

View supporting on-chain record
Aggregate sweep fees

0.03656700 BTC

Fees across the 500 confirmed sweep transactions.

View supporting on-chain record
Initial sweep output

594.47722484 BTC

Sent to the initial sweep address before later consolidation activity.

View supporting on-chain record
Consolidated sweep outputs

341

Initial sweep outputs later spent in the confirmed consolidation transaction.

View supporting on-chain record
Consolidated sweep input

562.02666941 BTC

Total value of the 341 sweep outputs consumed by the consolidation transaction.

View supporting on-chain record
Consolidation output

562.01962301 BTC

One unspent consolidation output at the snapshot time.

View supporting on-chain record
Consolidation fee

0.00704640 BTC

Fee paid by the transaction consolidating 341 initial sweep outputs.

View supporting on-chain record
Initial outputs remaining

159

Attack outputs that remained at the initial sweep address at the snapshot time.

View supporting on-chain record
Initial value remaining

32.45055543 BTC

Total value of the 159 attack outputs that remained at the initial sweep address.

View supporting on-chain record

Why this matters

A long recovery phrase can begin with too little randomness.

BIP-39 encodes starting entropy as mnemonic words, then BIP-32 deterministically derives wallet keys. If seed generation begins in a small, predictable family, the resulting 12- or 24-word phrase can still look normal.

Checksums, PBKDF2, hashing, and later deterministic derivation cannot add missing entropy after the fact. A strong, unique BIP-39 passphrase can add a barrier, but the vendor still recommends migration for an affected seed.

Technical references: BIP-39 and BIP-32.

Version scope

Keep the 4.0.0 / 4.0.1 disagreement visible.

Coinkite's current advisory begins Mk3 risk at 4.0.1. Block's preliminary independent analysis traces the Mk2/Mk3 regression to 4.0.0. The table preserves both claims instead of combining them into a single scope statement.

Vendor-confirmed and independently attributed affected-version findings
SourceModelAffected versionsFinding
Confirmed

Coinkite advisory and technical backgrounder

Mk34.0.1–4.1.9Vendor states seeds generated in this range are at risk; no fixed Mk3 release was available at review.
Confirmed

Coinkite advisory and technical backgrounder

Mk4/Mk5Before 5.6.0Vendor lists 5.6.0 as the fixed current release; updating cannot repair a seed generated earlier.
Confirmed

Coinkite advisory and technical backgrounder

QBefore 1.5.0QVendor lists 1.5.0Q as the fixed current release; updating cannot repair a seed generated earlier.
Attributed analysis

Block independent analysis

Mk2/Mk34.0.0–4.1.9Block traces the regression to 4.0.0 and labels its exploitability analysis preliminary.
Attributed analysis

Block independent analysis

Mk4/Q/Mk5Affected build path analyzed by BlockBlock describes four-byte secure-element reseeding and at most 2^32 securely distinguished streams for fixed fallback state and call history.

Observed transaction flow

Source UTXOs → initial sweep → partial consolidation.

Suspected addresses observed in this flow

These labels describe the public transaction pattern only. Blockchain evidence alone does not establish a real-world attacker's ownership or identity.

1. Confirmed inputs

1,324 UTXOs from 500 addresses

One source address appears in each of the 500 coordinated-sweep transactions.

Sourced timeline

Reports, analysis, advisory, and fixes.

  1. 2026-07-30

    Victim report

    Victims publish drain reports and device timelines

    First-person reports describe the loss and setup sequence; they are not independent confirmation of cause. The linked source is the original drain report; the device timeline is retained in primary sources.

Methodology and limits

What this site can and cannot establish.

  • The dataset is a snapshot of the 500 coordinated transactions confirmed in blocks 960188–960191.
  • Block time is a miner confirmation timestamp, not exact broadcast time.
  • The later 546-sat-input dust event is excluded to keep the 500 / 1,324 / 500 primary counts scoped to the sweep.
  • Transaction patterns and address matches do not prove ownership, causation, liability, or entitlement.

Source library

Reviewed dataset

Need the full address directory?

Browse all public source-address records and their linked transaction details.

Browse /addresses