Skip to content
CUNICULA

Incident Tracker

Dated security and solvency incidents affecting services in this directory, and how far the sourcing goes on each one.

2Incidents
1Confirmed
1Reported only
2Still open
Every incident was read against its own sources on 2026-08-07. This page lists incidents an editor reviewed and is not a census of everything that has happened to these services. An incident is recorded here only after review; automated detection files leads for an editor and never publishes.

How to read a record

CONFIRMED
Three or more sources were read directly, at least one of them primary — the operator's own advisory, a court or government record, or the vendor's own repository. This is the bar an article must clear.
REPORTED
Fewer than three sources, or no primary source. The row is recorded because it bears on user risk, but it rests on what one party published and Cunicula has not independently confirmed it.

Status words

The exposure is still live for at least some users as of the review date on the record.
The operator or an outside party closed the exposure and obligations were settled.
The parties disagree on the facts and no record read for this row settles it.
A fix exists in principle but has not shipped, or shipped without repairing users already affected.
Sort by

Coldcard firmware generated wallet seeds with reduced randomness

Coldcard · VULNERABILITY

CONFIRMED
Incident date
2026-07-30
Recorded
2026-07-30
Reviewed
2026-08-07

A 2021 firmware migration silently routed wallet-seed generation on Coldcard Mk2 and Mk3, and on pre-hotfix Mk4, Mk5 and Q devices, to a deterministic software fallback instead of the hardware random-number generator. Effective seed entropy fell to roughly 40-72 bits against a 128-bit target. Coinkite disclosed the defect on 2026-07-30 and shipped fixed firmware for every model and track the following day.

What this means for a userFixed firmware stops new weak seeds but does not repair a seed already generated on vulnerable firmware. A user who generated a seed on an affected version must move funds to a newly generated seed unless that seed came from at least 50 independent dice rolls or sits behind a strong BIP-39 passphrase. Independent on-chain trackers report drained totals in the hundreds of millions of dollars across several waves beginning 2026-07-30; those totals are a disputed range, not one confirmed figure.

Why it carries this statusRecorded as unpatched rather than resolved because the firmware defect is fixed while the seeds it produced are not. Unmigrated wallets remain exposed.

Read the full account

SolvoCard ended its card program with refunds reported unpaid

SolvoCard · SHUTDOWN

REPORTED
Incident date
2026-06-10
Recorded
2026-08-05
Reviewed
2026-08-07

KYCnot.me records that SolvoCard's Mastercard program ended in June 2026. Its record describes multiple users waiting on balance refunds and states that the reviewer's own residual test balance was still unpaid at the last review.

What this means for a userA user holding a balance when the program ended may not be able to retrieve it. SolvoCard's public site carried no incident notice at the 2026-08-05 review, so a prospective user reading only the operator's own pages would not learn that the program had ended.

Why it carries this statusRecorded as ongoing because no source read for this row shows the outstanding balances settled. Corroboration is reported, not confirmed: this rests on one reviewer's account, and searches for a second independent account returned nothing usable at the 2026-08-07 review.

Machine-readable at /api/v1/incidents and as RSS at /incidents/feed.xml. Both carry the corroboration field on every record.