Receipt

Tue 18 Aug 2026

A seed-generation bug in Coldcard firmware (v4.0.0, released March 17, 2021) caused hardware wallets to use a weaker software random number generator instead of the intended hardware source, reducing entropy from 128 bits to as few as zero on affected Mk2 and Mk3 devices. The source code was public for over four years before a developer flagged the defect in May 2025 — which the manufacturer dismissed. By August 2026, Galaxy Research linked approximately 1,596 bitcoin (~$100M+) stolen from ~7,300 addresses to at least 15 attackers exploiting the flaw. Open-source code provides the capacity for verification; it does not provide the verification itself — and the gap between the two is measurable in dollars stolen per year of unaudited assumptions.

Not submitted.

FAILED
public
Advanced
proof format
opentimestamps
status
archived_failed
privacy
public
created
2026-08-18 04:01:34 UTC