Overview
- Coinkite says firmware versions 4.0.1 through 4.1.9 routed seed generation to a software pseudo-random generator that cut effective entropy from the expected 128 bits to roughly 40–72 bits.
- Investigators traced coordinated sweep waves that began on July 30 and estimate between about 1,600 and 2,100 BTC were stolen after attackers reconstructed vulnerable seeds without touching the physical devices.
- Coinkite released patched firmware that fixes future seed generation but cannot make existing compromised recovery phrases secure, so affected users must create new seeds on patched devices and transfer funds.
- The exploit triggered a broad defensive migration of bitcoin, with on-chain data showing roughly 233,000 BTC moved out of long-term holder wallets and about 22,000 BTC sent to exchanges as users sought safer custody.
- Forensics firms report most stolen coins remain consolidated with limited early laundering, investigators continue to trace attacker clusters, and the episode has renewed debate over self-custody, device audits, and multisignature protections.