1. Confirmed inputs
1,324 UTXOs from 500 addresses
One source address appears in each of the 500 coordinated-sweep transactions.
Active incident: Incident overview
Active incident · public on-chain research
A firmware integration bug in affected COLDCARDs could generate wallet seeds with far less unpredictable entropy than expected. Researchers say an attacker could search a much smaller candidate seed set, derive matching private keys, and drain wallets. On July 30, 2026, 500 source addresses were swept in 500 transactions totaling 594.47722484 BTC, followed by 562.01962301 BTC later consolidated. The entropy flaw is confirmed, but public evidence does not establish it caused every sweep transaction.
An address match can identify inclusion in this dataset; it does not prove ownership, cause, or that a wallet is otherwise safe.
Lookup happens locally in your browser. No query is sent or logged.
Never enter a seed phrase, private key, passphrase, PIN, xpub, wallet backup, or wallet file.
If you may be affected
01
ConfirmedUse this local checker with a public Bitcoin address. Never enter a seed phrase, private key, passphrase, or wallet export.
02
ConfirmedUse COLDCARD Verify Address or Address Explorer, noting their automatic verification range and path limits.
Read the supporting guidance03
ConfirmedCreate fresh entropy on a patched or otherwise trusted device; do not reuse or restore the old seed. Verify the destination and consider a small test payment.
Read the supporting guidance04
ConfirmedKeep public TXIDs, addresses, UTC times, amounts, screenshots, notifications, device details, and case numbers. Do not send secret material to this site or anyone else.
Confirmed on-chain snapshot
Snapshot: 2026-07-31 10:39:59 UTC. These values include the 500 coordinated sweep transactions, confirmed in just over 15 minutes (15m18s), and exclude a later dust event so they should not be confused with lifetime address activity.
500
Confirmed in blocks 960188–960191 during a 15m18s confirmation window.
View supporting on-chain record1,324
From 500 unique source addresses; no address was reused across sweep transactions.
View supporting on-chain record500
One source address per sweep transaction; no source address was reused across the coordinated sweep.
View supporting on-chain record594.51379184 BTC
Aggregate source inputs in the confirmed coordinated sweep.
View supporting on-chain record0.03656700 BTC
Fees across the 500 confirmed sweep transactions.
View supporting on-chain record594.47722484 BTC
Sent to the initial sweep address before later consolidation activity.
View supporting on-chain record341
Initial sweep outputs later spent in the confirmed consolidation transaction.
View supporting on-chain record562.02666941 BTC
Total value of the 341 sweep outputs consumed by the consolidation transaction.
View supporting on-chain record562.01962301 BTC
One unspent consolidation output at the snapshot time.
View supporting on-chain record0.00704640 BTC
Fee paid by the transaction consolidating 341 initial sweep outputs.
View supporting on-chain record159
Attack outputs that remained at the initial sweep address at the snapshot time.
View supporting on-chain record32.45055543 BTC
Total value of the 159 attack outputs that remained at the initial sweep address.
View supporting on-chain recordWhy this matters
BIP-39 encodes starting entropy as mnemonic words, then BIP-32 deterministically derives wallet keys. If seed generation begins in a small, predictable family, the resulting 12- or 24-word phrase can still look normal.
Checksums, PBKDF2, hashing, and later deterministic derivation cannot add missing entropy after the fact. A strong, unique BIP-39 passphrase can add a barrier, but the vendor still recommends migration for an affected seed.
Version scope
Coinkite's current advisory begins Mk3 risk at 4.0.1. Block's preliminary independent analysis traces the Mk2/Mk3 regression to 4.0.0. The table preserves both claims instead of combining them into a single scope statement.
| Source | Model | Affected versions | Finding |
|---|---|---|---|
| Confirmed | Mk3 | 4.0.1–4.1.9 | Vendor states seeds generated in this range are at risk; no fixed Mk3 release was available at review. |
| Confirmed | Mk4/Mk5 | Before 5.6.0 | Vendor lists 5.6.0 as the fixed current release; updating cannot repair a seed generated earlier. |
| Confirmed | Q | Before 1.5.0Q | Vendor lists 1.5.0Q as the fixed current release; updating cannot repair a seed generated earlier. |
| Attributed analysis | Mk2/Mk3 | 4.0.0–4.1.9 | Block traces the regression to 4.0.0 and labels its exploitability analysis preliminary. |
| Attributed analysis | Mk4/Q/Mk5 | Affected build path analyzed by Block | Block describes four-byte secure-element reseeding and at most 2^32 securely distinguished streams for fixed fallback state and call history. |
Observed transaction flow
Suspected addresses observed in this flow
These labels describe the public transaction pattern only. Blockchain evidence alone does not establish a real-world attacker's ownership or identity.
1. Confirmed inputs
One source address appears in each of the 500 coordinated-sweep transactions.
2. Suspected initial collection/sweep address
594.47722484 BTC arrived at the initial address after 0.03656700 BTC in aggregate fees.
Inspect the initial sweep address3. Suspected subsequent consolidation address
341 outputs totaling 562.02666941 BTC were spent to one 562.01962301 BTC output; 159 outputs remained at the initial address at the snapshot.
Sourced timeline
2026-07-30 01:36:08–01:51:26 UTC
Confirmed500 transactions swept 1,324 source UTXOs. Block time is a miner confirmation timestamp, not exact broadcast time.
2026-07-30
Victim reportFirst-person reports describe the loss and setup sequence; they are not independent confirmation of cause. The linked source is the original drain report; the device timeline is retained in primary sources.
2026-07-30 18:30 UTC
Attributed analysisIndependent public analysis links the coordinated activity on-chain.
2026-07-30 22:37 UTC
Attributed analysisA public reproduction claim adds context but is not treated as vendor confirmation here.
2026-07-30 22:50 UTC
ConfirmedCoinkite acknowledges the incident publicly and directs people to official guidance.
2026-07-31
Attributed analysisBlock attributes the issue to a predictable fallback path and a 32-bit reseed limitation, while noting full exploitability testing was not complete.
2026-07-31
ConfirmedThe vendor confirms a limited entropy RNG integration bug and publishes scope and mitigation guidance.
2026-07-31
ConfirmedCoinkite releases Mk4/Mk5 5.6.0 and Q 1.5.0Q; existing affected seeds still require migration.
Methodology and limits
Initial sweep address on Blockstream
Independent on-chain view
Consolidation address on Mempool
On-chain evidence
Later dust transaction on Mempool
On-chain scope validation
Victim report
Victim report
Rob Hamilton on-chain synthesis
Independent analysis
Independent reproduction claim
Independent analysis
Coinkite official advisory post
Vendor advisory
Independent reporting
Provisional earlier-cluster report
Unresolved analysis
Provisional earlier-cluster follow-up
Unresolved analysis
Initial sweep address on Mempool
On-chain evidence
Consolidation transaction on Mempool
On-chain evidence
Coinkite Mk3 seed-generation warning
Vendor advisory
Coinkite entropy technical backgrounder
Vendor technical backgrounder
Vendor source change
Vendor fixed release
Vendor fixed release
Block preliminary root-cause analysis
Independent analysis
Technical reference
BIP-32 hierarchical deterministic wallets
Technical reference
COLDCARD Verify Address guidance
Vendor safety guidance
COLDCARD Address Explorer guidance
Vendor safety guidance
FBI IC3 cryptocurrency guidance
Reporting guidance
FBI recovery-scam public service announcement
Safety guidance
Safety guidance
Reviewed dataset
Browse all public source-address records and their linked transaction details.