@hodlonaut It doesn't matter. They admit they had no idea what was in the code they used to secure your funds. Trust, don't verify, right?
https://t.co/XBCFBMmGyv
🚨🚨🚨Exchanges received a net of 11,163 BTC on Friday, the day of the ColdCard Attack.
Biggest Inflows:
River: +3,679 BTC
Binance: +3,224 BTC
Kraken: +2,848 BTC
OKX: +1,291 BTC
Centralized Entities received a total inflow of 15,205 BTC from unidentified addresses/plebs
As of Friday 07/31/2026, 23:51:35 UTC, centralized exchanges held a total of 3,651,438 BTC.
@hodlonaut It doesn't matter. They admit they had no idea what was in the code they used to secure your funds. Trust, don't verify, right?
https://t.co/XBCFBMmGyv
Reports are coming in that some Coldcard hardware wallet users are having their bitcoin drained. Multiple known Bitcoiners are confirmed affected.
@KLoaec’s working hypothesis is a low-entropy RNG issue, possibly in the secure element, with an attacker using AI to bruteforce and sweep only bip84 (segwit) paths, which would explain the partial thefts.
Root cause is still unconfirmed. Could be RNG, nonce reuse, or something else entirely.
If you use a Coldcard single-sig setup, check your balances now. If affected, email Coinkite with proof you control the keys.
@TFTC21@KLoaec This is interesting. I thought people were lying when they said multiple wallets/users. Please @TFTC21 tell us which "Multiple known Bitcoiners" are affected?
BITCOIN CORE DEVELOPER: “SORRY, THIS IS THE TIME TO PANIC” OVER COLDCARD MK2/MK3 VULNERABILITY
Bitcoin Core developer instagibbs says he successfully reproduced the reported COLDCARD vulnerability on a freshly initialized MK3 device using only the number of button presses made during setup, adding: “Sorry, this is the time to panic.”
He believes the issue affects MK2/MK3 devices but says he cannot yet confirm whether MK4 is vulnerable.
Developer Antoine Poinsot says the key difference is that the MK4 seeds entropy with hardware random number generators and actually uses the microcontroller’s true random number generator (TRNG), while the MK3 does not.
The proof-of-concept and mnemonic verification remain under review.
This is the part where I remind folks once again that every hardware vendor is fallible. If you want to hedge against vendor risks and supply chain risks, the solution is multi-vendor multisig.
We have plenty of coldcard users over at @CasaHODL and this event will just be a minor annoyance for them to rotate out the compromised key with a securely generated one.