Coldcard seed-generation flaw (software PRNG instead of hardware RNG on older firmware) let attackers brute-force seeds; ~$116M in BTC stolen (TRM Labs); fixed firmware since 2026-07-31 but affected seeds must be migrated; Coinkite has not offered reimbursement. Status: Not shown reimbursed.
Data as of · Last updated · By VaultRubric Research · How we score · Not investment advice.
Coldcard seed-generation flaw (software PRNG instead of hardware RNG on older firmware) let attackers brute-force seeds; ~$116M in BTC stolen (TRM Labs); fixed firmware since 2026-07-31 but affected seeds must be migrated; Coinkite has not offered reimbursement. Status: Not shown reimbursed.
| Date | 2026-07 |
|---|---|
| Type | customer funds loss |
| Products in our data affected | Coldcard Mk4, Coldcard Q, Coldcard Mk5 |
| Reimbursement | Not shown reimbursed |
| Effect on VaultRubric scores | capped at 60% and not eligible to be our pick (unreimbursed customer-funds loss within 48 months) |
| Sources | coldcard.com, www.trmlabs.com, www.forbes.com |
Facts above are taken from the cited sources as of 2026-10-11. Follow the vendor's official guidance (linked) for remediation; nothing here is security advice. How hacks affect scores.
Coldcard seed-generation flaw (software PRNG instead of hardware RNG on older firmware) let attackers brute-force seeds; ~$116M in BTC stolen (TRM Labs); fixed firmware since 2026-07-31 but affected seeds must be migrated; Coinkite has not offered reimbursement.
Not shown reimbursed.
Coldcard Mk4, Coldcard Q, Coldcard Mk5.
capped at 60% and not eligible to be our pick (unreimbursed customer-funds loss within 48 months).