Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
get updates
BACK TO NEWS
July 31, 2026
/
0
Min Read

Bitcoin Developers And Block Trace The Coldcard Drain In Real Time

The Coldcard entropy bug moved from a single advisory into a fast, public forensic effort within hours. Security teams, independent developers, and victims began comparing notes in real time, piecing together which devices were actually at risk and how the theft happened. Some of what surfaced contradicts Coinkite's own advisory and remains unconfirmed. This is how the story actually unfolded, in the community's own words.

THE FIRST REPORTS

The panic started with individual reports of drained wallets. A Reddit post describing a full panic after one user's wallet was drained captured the first wave of user-level alarm before the broader technical picture came into focus.

Independent developer Praveen Perera said he had independently confirmed generating the private keys tied to one of the stolen addresses, an early signal that the theft was not just plausible but reproducible.

Independently confirmed I was able to generate the private keys of one of the stolen addresses.

View original post

BLOCK OPENS AN INVESTIGATION

Block's Bitcoin engineering and security team, led publicly on X by Max Guise, said it began investigating reports of non-Bitkey wallets being drained as soon as the reports surfaced.

Earlier today, our Bitcoin engineering and security teams at Block began investigating reports of non-Bitkey wallets being drained. To proactively protect our customers, we began investigating immediately.

View full original post

Block researcher Clay Garrett followed with a more specific technical claim. The team said it had identified an unusual pattern across the sweeps and traced a hypothesis that the operator queried blockchain data through a paid account at what Garrett described only as a well-known blockchain-services provider. Garrett said Block was still vetting a second set of transactions that could be part of the same drain.

View fill original post (pattern hypothesis) · View full original post (second transaction set)

Neither claim has been independently verified outside Block's own account of its investigation, and Simply Bitcoin has not confirmed the identity of the provider Garrett referenced.

WHO IS ACTUALLY AT RISK: THE DEBATE OVER MK4, MK5, AND Q

In the hours after disclosure, researchers publicly disagreed about how far the bug reached. Bitcoin developer Nick Neuman said Mk4, Q, and Mk5 devices were vulnerable in a different way than Mk3, describing the risk as less severe but still serious enough to warrant moving funds off a single-sig Coldcard.

View original post

Bitcoin Core contributor instagibbs was more cautious, saying only Mk2 and Mk3 were confirmed and that Mk4 status could not yet be called either way.

Confirmed. Mk2/3 vuln, I don't think mk4 is but can't be certain.

View original post

Kevin Loaec took the opposite, more alarmed position, arguing hours later that the situation was worse than initially understood and that Mk4, Mk5, and Q devices would be drained, along with multisig setups where Coldcard signatures alone could reach the signing threshold, and miniscript wallets built on the same devices.

It's worse than you think. Mk4, MK5, Q will get drained. Multisig of Coldcard devices, or multisig where Coldcard signatures are sufficient to reach the threshold, are at risk. Miniscript wallets are also at risk.

View original post

Coinkite's own advisory, published the same day, landed between these positions. It confirmed Mk4, Mk5, and Q seeds generated before the fixed firmware carry roughly 72 bits of entropy instead of the intended 128, calling the impact on those models less severe than Mk3 but still serious. Loaec's prediction that those devices would be drained outright is his own assessment, not a claim Coinkite has made.

TRACING THE ATTACKER

Multiple independent voices converged on a similar read of the attacker's sophistication. Bitcoin developer Antoine Poinsot, replying in a thread with security researcher Praveen Perera, said the original attacker was, in his words, big time amateur, and warned a more serious drain was likely coming.

Original attacker was big time amateur. Won't be long till we see a really serious drain.

View original post

Miles Suter separately described the attacker as appearing to be a novice, adding that he was surprised more sophisticated attacks had not already followed now that the vulnerability was public.

View original post

Self-custody advocate ODELL raised a separate, unconfirmed theory: that the bug itself may have been found and exploited with the help of AI-assisted analysis. That claim echoes speculation in Coinkite's own disclosure, which raises the same possibility without confirming it. Treat it as an open question, not an established fact.

View original post

WHAT RESEARCHERS ARE TELLING PEOPLE TO DO

Across every account in the thread, the practical guidance converged even where the technical read did not. Bitcoin Core contributor James O'Beirne said he had verified that the dice roll path is safe, provided enough rolls were used, and warned that anyone relying on a passphrase alone is now only as safe as that passphrase.

Have verified that the dice roll path is safe, provided you incorporated enough dice rolls. If you are affected but have a passphrase, your coins are now only as safe as your passphrase.

View original post

ODELL urged Coldcard users to move funds out of an abundance of caution while the investigation continued, noting that dice-roll and passphrase-protected seeds should be fine. Jack Mallers went further, calling it one of the most serious wallet security incidents Bitcoin has seen and urging anyone who knows a Coldcard user to call or text them directly rather than assume they had already heard.

If you use a Coldcard hardware wallet, please pay attention. If you know someone who uses one, call them. Text them. This appears to be one of the most serious wallet security incidents Bitcoin has seen.

Bitcoin educator Guy Swann framed the scale of the incident directly, calling it the worst hit in Bitcoin history to bitcoiners who considered themselves properly secured, distinct from an exchange hack because it reached individual, self-custodied keys.

This isn't an exchange getting hacked because of hot keys. This is thousands of individuals having their personal private keys recreated out from underneath them.

View original post

WHERE THINGS STAND

Bitcoin Optech's Mike Schmidt said the newsletter's coverage of the vulnerability was still evolving as new details came in, and invited corrections in real time rather than waiting for a later edition.

View original post

Kevin Loaec said a fuller technical writeup was coming.

View original post

As of this writing, Coinkite has released fixed firmware for every affected model and release track and continues to describe its own advisory as an early analysis, with a formal technical review still to come.

One inconsistency worth flagging directly. A widely shared account from developer Zach Herbert dates the bug's origin to July 28, 2020, while Coinkite's own advisory places the flaw's introduction in March 2021.

View original post

Simply Bitcoin has not resolved which date is correct and is not treating either as confirmed until Coinkite's formal technical review lands.

The device and firmware guidance has not changed. Update to the fixed firmware for your model, do not generate a new seed until you have, and if your existing seed was generated on affected firmware without a strong passphrase or sufficient independent dice rolls, migrate to a new seed following the verified process rather than reacting immediately.

About Simply Bitcoin
Simply Bitcoin is an independent Bitcoin media network delivering daily news, analysis, and original shows. We believe in spreading the Bitcoin signal: truth, transparency, and freedom through education and self-sovereignty.

related materials

Related Stories
on Bitcoin & Freedom

all articles
Subscribe
NO CLARITY FOR BITCOIN, JUST JAIL TIME!
NO CLARITY FOR BITCOIN, JUST JAIL TIME!
Jul 29, 2026
The First Message Bitcoin Ever Sent Was A Warning About Banks
Jul 1, 2026
Every Company Holding Cash Is Making A Losing Bet
Jun 26, 2026

Stay in the Loop

Get the Best Bitcoin 
Stories, Daily
Subscribe to our free newsletter for the latest Bitcoin updates, top videos, and curated market insights, delivered straight to your inbox.