Own a Coldcard? Treat any wallet created without additional entropy as compromised and move your funds to a safe place now.

What is this?

Coldcard hardware wallets generated wallet seeds with a broken random-number generator: a predictable software pseudo-RNG instead of true hardware entropy. The private keys can be brute-forced and the coins swept. If affected, migrate your funds now.

We fund decoy “honeypot” wallets carrying that exact flaw on mainnet, some hardened with extra dice rolls or a passphrase, and track which ones an attacker sweeps and how fast. This maps the frontier of what coins are being confiscated. Read the methodology →

honeypots19
live14
swept5
value exposed~0.01 BTC
fastest sweep2m
frontier~5 bits ^

recent activity last 5 events

time (utc) event difficulty
2026-08-08 16:44 honeypot swept HP-2C6F low (dice)
2026-08-08 16:43 honeypot swept HP-10ED low (dice)
2026-08-08 00:09 honeypot funded HP-E736 trivial
2026-08-08 00:06 honeypot funded HP-696E low (dice)
2026-08-07 19:31 honeypot swept HP-5F1D trivial

honeypots

handle device difficulty sec(bits) est. crack (GPU) status age / time-to-sweep
HP-5D67 mk3 v4 2-of-3 multisig - - LIVE live 5d8h27m
HP-ADA6 mk3 v4 3-of-3 multisig - - LIVE live 4d13h8m
HP-718B mk3 v4 trivial 0 ~2 min SWEPT swept in 1h18m
HP-696E mk3 v4 low (dice) 5 ~66 min LIVE live 2d12h5m
HP-10ED mk3 v4 low (dice) 5 ~66 min SWEPT swept in 3d15h38m
HP-2C6F mk3 v4 low (dice) 5 ~66 min SWEPT swept in 2d14h49m
HP-9C4F mk3 v4 low (pass) 11 ~3 days LIVE live 5d15h21m
HP-E786 mk3 v4 low (pass) 11 ~3 days LIVE live 5d15h21m
HP-8EF5 mk3 v4 low (dice) 13 ~10 days LIVE live 5d12h59m
HP-C4AD mk3 v4 low (dice) 13 ~10 days LIVE live 5d12h59m
HP-0134 mk3 v4 mid (pass) 22 ~15 yr LIVE live 5d11h5m
HP-9252 mk3 v4 high (pass) 33 ~1e4 yr LIVE live 5d11h4m
HP-776C mk3 v4 extreme (dice) 90 ~1e21 yr LIVE live 5d8h15m
showing 13 - sort: sec(bits) ascending (easiest to sweep first)

external honeypots community-submitted, watch-only

handle device source status age / time-to-sweep
0 added bits mk3 x.com/ColeTU/status/2085065558333022663 SWEPT swept in 2m
1 word passphrase mk3 x.com/ColeTU/status/2085065558333022663 LIVE live 4d15h24m
2 word passphrase mk3 x.com/ColeTU/status/2085065558333022663 LIVE live 4d15h24m
3 word passphrase mk3 x.com/ColeTU/status/2085065558333022663 LIVE live 4d15h24m
0 added, random account mk3 x.com/ColeTU/status/2085065558333022663 SWEPT swept in 1d22h44m
2-of-4, 0-added mk4 zombo.com LIVE live 2d12h1m

frontier summary

difficulty deployed swept fastest still live
trivial 3 1 1h18m 2
low 7 2 2d14h49m 5
mid (pass) 1 0 - 1
high (pass) 1 0 - 1
extreme (dice) 1 0 - 1
difficulty bands added entropy over the attacker-known seed · dice ~2.585 bits/roll · passphrase 11 bits/word
trivial0 bitsthe control — no dice, no passphrase
low1–15 bits1–5 dice rolls, or a 1-word passphrase
mid16–30 bits6–11 dice rolls, or a 2-word passphrase
high31–45 bits12–17 dice rolls, or a 3–4 word passphrase
extreme>45 bits18+ dice rolls, or a 5+ word passphrase
A note on timing. Just because a particular honeypot here hasn't been taken yet doesn't mean its entropy class is safe. We don't know long this attack has been going on, but it started well before our honeypots existed. The thousands of coins already taken were ground down over more than a few days, likely much longer than ours have been live.

So read “still live” as not taken yet, nothing more: a honeypot surviving for weeks says little about the safety of its entropy class (in terms of older coins real people are still holding) because the attackers have had a chance to grind those coins for far longer than any of ours have existed.