keneci Network
News • Comedy • Science & Tech
Coldcard Hack: Over $100M Bitcoin Drained In Hardware Wallet Exploits
August 04, 2026
post photo preview

A critical firmware vulnerability in Coldcard hardware bitcoin wallets by Coinkite allowed attackers to steal about 1,367 BTC (valued at up to $89 million) from over 4,500 addresses in a series of coordinated attacks in the past week.

An initial coordinated sweep drained 594 BTC (~$38 million) from roughly 500 wallets in just 25 minutes, targeting the highest-value dormant accounts. The attack expanded to 1,082 BTC across 1,196 addresses within a 41-minute window, with attackers using elevated transaction fees to ensure rapid confirmation.

Cumulative losses reached 1,367 BTC across 4,585 addresses, with attackers continuing to exploit the vulnerability as other actors joined in.

The flaw, present since March 2021, caused affected devices to generate wallet seeds with significantly reduced entropy—40 bits for Mk3 devices and 72 bits for later models—instead of the intended 128 bits, by silently falling back to a predictable software-based random number generator instead of the hardware RNG.

A 2021 code commit introduced a library (`libngu`) that used a preprocessor check which only verified if a macro was defined, not if it was enabled. This caused the device to bypass its secure hardware random number generator.

The fallback software generator relied on non-secret data like chip IDs and internal clock values, creating a search space small enough for attackers to brute-force private keys offline.

Mk3 units running firmware 4.0.0 or later were most severely impacted. Mk4, Mk5, and Q devices were also vulnerable, though with slightly higher entropy (~72 bits).

The bug remained undetected through five years of updates and AI-assisted audits, as the generated seeds appeared valid but lacked true randomness.

The stolen Bitcoin remains largely unspent, held in a small number of attacker-controlled addresses, with analysts suggesting this is a deliberate strategy to avoid capture by authorities and triggering immediate market panic.

Galaxy Research identified about 600 suspected attacker addresses and reported them to federal investigators, compliance firms, and cybersecurity teams. Block, Jack Dorsey’s company, published an independent technical analysis confirming the RNG flaw.

Coinkite released patched firmware and urged users to transfer funds to new, secure wallets. Crucially, users were warned that updating the device does not fix old seeds; users must generate entirely new seeds using the updated firmware.

In an update on X Tuesday, Coinkite wrote in part: "We understand there is real anger at this moment. Users have suffered real losses, and for those impacted, no public statement is enough.

"We continue to support affected customers directly and urge others to reach out to any other users they are aware of who may be affected. Urgently: if your seed was generated with our affected firmware, without at least 50 independent, private dice rolls, and your funds aren't protected by a strong, unique BIP-39 passphrase, move those funds to a new wallet now.

"As independent researchers have publicly corroborated, this firmware bug appears to have lived at a boundary between two unrelated submodules, not in the parent code, and not in the cryptographic or Bitcoin-specific logic that are the subject of most internal and third-party reviews.

"Because the flag check looked correct, the bug silently went unnoticed, and its potential impact grew with every release.

"We believe it’s important for the broader ecosystem to understand how this bug arose, and why it evaded detection, so they can avoid similar consequences.

"We know there are questions about our own use of AI in code review. We'll cover this fully in our post-mortem, but given the active investigation right now, here's what we can say immediately.

"We've run AI-assisted review against our critical codebases, including in the weeks before the exploit. It did not catch this vulnerability. Since the incident, we've also tested our code against frontier models, including Kimi K3, Claude Fable, and Codex 5.6. None of them caught it.

"It's a reason for us, and anyone else relying on AI tools, to be specific about what it currently catches and what it might not."

The ColdCard incident highlighted that hardware wallet security is only as strong as its entropy generation, prompting competitors like Ledger and Trezor to reaffirm the security of their own TRNG implementations.

community logo
Join the keneci Network Community
To read more articles like this, sign up and join my community today
0
What else you may like…
Videos
Posts
Articles
SpaceX Starlink Internet Satellites

With Starlink internet, data is continuously being sent between a ground dish and a Starlink satellite orbiting 550km above. Furthermore, the Starlink satellite zooms across the sky at 27,000 km/hr! MORE VIDEOS ON KENECI NETWORK RUMBLE CHANNEL: https://rumble.com/c/Keneci

00:28:08
Elon Musk, DOGE Speak On Waste And Fraud

US Department of Government Efficiency Services (USDS) led by Elon Musk speak on the "mind-boggling" fraud and waste in UInited States federal government

00:00:45
January 17, 2025
SpaceX Launches Starship 7th Test Flight

SpaceX successfully executed its second-ever “chopsticks” catch of a Super Heavy booster (or Booster 14) using the “Mechazilla” launch tower on Thursday(Jan. 16), during the seventh uncrewed test flight of the company's 123-meter Starship rocket. However, the megarocket's upper stage(or Ship 33) was lost approximately 8.5 minutes into the flight in a “rapid unscheduled disassembly(RUD)” or explosion

00:10:30
Welcome to Keneci Network!

Join the conversations!

December 09, 2025
Bitcoin White Paper By Satoshi Nakamoto

Bitcoin white paper

Bitcoin_White_Paper.pdf
September 17, 2024
Charges Against Sean 'Diddy' Combs In Grand Jury Indictment

The rapper was charged with racketeering conspiracy, sex trafficking by force, fraud or coercion, and transportation to engage in prostitution in the indictment unsealed Tuesday(Sept. 17)

Combs-Indictment-24-Cr.-542.pdf
post photo preview
China, US Developing Military 'Hunter' Satellites: Leaked Report

The United States and China are rapidly developing military space capabilities, including "hunter" satellites and orbital weapons, signaling a shift toward potential space warfare.

Recently leaked documents and space-tracking data from early September 2026, reportedly show both nations are creating spacecraft capable of maneuvering near, inspecting, or potentially disabling other satellites.

Unlike traditional satellites that follow fixed, predictable orbital paths, hunter satellites—also called co-orbital threat systems or inspector satellites—possess high maneuverability. They are equipped with advanced propulsion, autonomous navigation, and physical or directional payloads designed to interact with other spacecraft.

China and the US are aggressively pursuing on-orbit refueling technologies. Because maneuvering in space consumes significant fuel, refueling capabilities allow hunter satellites to remain operational indefinitely rather than becoming dead weight after a few maneuvers.

China’s advancements include orbital "dogfighting" and refueling technologies. Chinese military-linked researchers are pursuing satellites designed to pursue and capture other spacecraft, with patents covering autonomous fuel-efficient maneuvers and net-based capture systems.

Officially referred to as "space debris removal," "in-orbit servicing," or "repair craft," the exact same robotic mechanisms (grappling arms, nets, lasers) used in systems can be weaponized to disable enemy satellites.

In June 2026, a Chinese spaceplane released a mini-satellite that circled another spacecraft, an act US officials described as a dress rehearsal for combat. Additionally, China likely conducted an on-orbit refueling attempt last year, a breakthrough that would allow satellites to extend their operational lives indefinitely.

Chinese military-linked patent filings reveal developments in autonomous, fuel-efficient pursuit calculations and multi-satellite netting systems designed to capture non-cooperative target spacecraft.

The US is countering with joint allied operations and electromagnetic weapons. The US Space Force has introduced ground-based electromagnetic weapons to disrupt satellite communications and operates a secret, crewless spaceplane similar to China’s.

Ground- and space-based lasers can blind satellite optics or permanently damage solar arrays. High-powered electromagnetic weapons are designed to sever satellite data links to ground stations.

In a significant strategic signal, US Space Command, alongside Five Eyes allies recently conducted their first joint military space operation in the path of a suspected Chinese spy satellite, demonstrating allied coordination. In one instance, a US military satellite executed a close-approach intercept vector near a Chinese Shiyan 12-01 satellite, signaling operational readiness to inspect and counter adversary craft.

Autonomous craft like the US X-37B and China's secretive Shenlong serve as mobile deployment platforms for covert payloads, anti-satellite surveillance, and maneuver warfare.

US Space Force leadership describes the Chinese threat as "substantial," noting rapid expansion in both the number and complexity of Beijing’s space missions.

Read full Article
September 02, 2026
post photo preview
Owl Around The World: Rocket Lab Electron Launches Japanese StriX Satellite

Rocket Lab successfully launched its 94th Electron mission, deploying the latest StriX synthetic aperture radar satellite for Japanese company Synspective. The "Owl Around The World," mission lifted off from Launch Complex 1 in New Zealand at 1201 UTC on Wed (Sept. 2).

The Electron's upper 'kick stage' deployed the Strix satellite 56 minutes after liftoff, into a 575 kilometer low Earth orbit to expand Synspective’s imaging constellation.

Synspective is building a constellation of approximately 30 StriX satellites to provide high-resolution Earth observation data for urban planning, infrastructure monitoring, and disaster response.

Named after the owl genus Strix, these satellites use radar to image Earth’s surface day and night, penetrating cloud cover and darkness.

The Strix constellation will "make it possible to quickly monitor and confirm on-the-ground changes during disasters such as earthquakes and floods at night, as well as in areas that are difficult to access," Synspective's website reads.

"In addition to disaster response, we will leverage our SAR satellite capabilities to promote efficient resource utilization," it adds. "For example, we can use our satellite data to monitor natural resources and urban development, ensuring sustainable and optimal use of land and water."

Rocket Lab has been the exclusive launch partner for Synspective since 2020, maintaining a 100% mission success record for all Synspective launches.

The company has 16 additional Electron missions booked to deploy the remainder of the constellation before 2030.

The StriX program began with StriX-α launched on December 15, 2020, followed by StriX-β in February 2022 and the first commercial satellite, StriX-1, in September 2022.

As of Wednesday's launch, 10 StriX satellites have reached orbit, including recent missions like "Viva La StriX" (May 2026) and "Ten Owl of Ten" (June 2026).

The Electron rocket is a two-stage, small-lift vehicle standing 18 meters tall, recognized as the world’s most frequently launched small-lift orbital rocket. Rocket Lab has also launched nine missions to date with HASTE, a suborbital version of Electron that allows customers to test sensors and instruments in a hypersonic flight environment. While Electron debuted in 2017, HASTE lifted off for the first time in June 2023.

Read full Article
September 02, 2026
post photo preview
US Strikes On Iranian Targets Kill At Least 4 Including Children At Wedding Celebration, Over 70 Injured

US Central Command (CENTCOM) on Tuesday at 1600 UTC began a wave of strikes against Iranian military targets, including sites in Bandar Abbas, Jask, Sirik, Minab, Qeshm, and Chabahar.

The operation, CENTCOM claimed, targeted Islamic Revolutionary Guard Corps (IRGC) infrastructure, specifically air defense sites, radar systems, maritime assets, mine-laying capabilities, and communications networks, in response to recent IRGC attempts to attack commercial shipping in the Strait of Hormuz and US service members in the region.

A US strike hit a residential home in Kuhestak, Sirik, where a wedding celebration was taking place. According to the Iranian Red Crescent and local officials, the attack resulted in at least four deaths, including a child, and over 68 injuries.

Iran’s Foreign Ministry condemned the event as a "savage crime," while CENTCOM stated its focus was strictly on military and strategic infrastructure to degrade Iran’s ability to threaten maritime traffic.

In retaliation, Iran launched ballistic missiles and drones at US-linked facilities across the region. The IRGC claimed successful strikes on 85 US military sites, including Camp Titin in Jordan and the Sheikh Isa Airbase in Bahrain. Jordan’s military reported intercepting 10 out of 13 incoming ballistic missiles, while Kuwait and Bahrain activated air defenses against hostile drone and missile attacks.

President Donald Trump warned in a Truth Social post, that Iran would face further, more severe escalation if it continued retaliatory actions.

Iran’s Khatam al-Anbiya Central Headquarters and the IRGC in a statement vowing a "crushing response," and continued retaliatory barrage operations involving ballistic missiles and strike drones aimed at U.S. assets and allied infrastructure across the Jordan, Iraq, Kuwait and Bahrain.

The six-month conflict has focused on control of the Strait of Hormuz, through which roughly 20% of global oil flows. Iran closed the waterway in response to U.S.-Israeli attack that started on February 28. U.S. naval forces claim to have conducted mine-clearing and escort operations which has come under Iranian attacks.

This tit-for-tat escalation marks the latest flare-up in a conflict that repeatedly disrupted global maritime trade. Prior to the September 1 strikes, a brief month-long lull broke down when U.S. forces struck missile sites on Larak Island. Iran answered with attacks on tankers and military outposts, directly leading to CENTCOM's massive September 1 military campaign.

Global energy markets responded immediately, with crude prices spiking over $4 a barrel to five-week highs. This comes as Iranian diplomatic efforts are underway at the Shanghai Cooperation Organization (SCO) to secure material and military assistance from partners like Russia and China.

Read full Article
See More
Available on mobile and TV devices
google store google store app store app store
google store google store app tv store app tv store amazon store amazon store roku store roku store
Powered by Locals