The Coldcard Seed Flaw: What Happened, and What to Do
For five years, one of the most respected Bitcoin hardware wallets generated seeds with far less randomness than it was supposed to. In late July 2026, someone started using that fact to drain wallets. This page explains what happened in plain English, whether your seed is affected, and what to do about it.
By drix · Last updated 11 August 2026. The exploit was still active and Coinkite's post-mortem still pending on that date; this page will be updated as the facts settle.
If you own a Coldcard, the short version
- If your seed was generated on a Coldcard since March 2021, treat it as compromised — regardless of what firmware the device runs today, and regardless of whether anything has been stolen yet.
- Updating the firmware alone does not fix it. The update fixes future seeds. Your existing seed keeps whatever randomness it was born with.
- Coinkite's advisory: update, generate a brand-new seed, send a test transaction, then move everything. The old seed is burned.
- Seeds made with 50+ dice rolls and the TAPSIGNER / OPENDIME / SATSCARD are not affected, per Coinkite. Seeds generated elsewhere and merely imported are unaffected by construction — the flaw is in on-device seed generation.
What Happened
On 30 July 2026, Coinkite published a security advisory: a flaw in how Coldcard devices generated seed phrases meant that seeds created on affected firmware had far less randomness than the 128 bits users were promised. The same day, wallets started being drained. The weakness let attackers reconstruct affected seeds by brute force and sweep the coins, in bulk, without ever touching a device — and the speed and scale of the first sweep suggest the work of reconstructing seeds had begun well before the advisory was public, though nobody has published who found the flaw first.
The flaw ships in firmware 4.0.1 for the Mk2 and Mk3. A build change quietly routes seed generation away from the chip's hardware random number generator and into a predictable software fallback. It carries forward into the Mk4, Mk5 and Q, and sits unnoticed for five years.
Coinkite publishes its advisory, and the first large theft wave runs the same day — security reporting describes over a thousand addresses drained in under an hour. Emergency firmware for every affected model and release track ships the next day, 31 July. Coinkite urges users to migrate immediately.
Sweeps continue in waves. By 5 August, Galaxy Research's tally stood at roughly 1,816 BTC — about $116 million — across more than 5,200 addresses, and was still described as preliminary. Coinkite has declined to publish its own loss estimate.
The running totals differ from tracker to tracker and from day to day, which is itself worth knowing: at the time of writing nobody, including Coinkite, can state the full size of this. What is not in dispute is the mechanism, the affected firmware ranges, and what owners need to do.
Sources: Coinkite, Coldcard security advisory (30 July 2026) · The Hacker News, Coldcard flaw linked to $70M theft in 41 minutes (1 Aug 2026) · TRM Labs, inside the $116M Coldcard hack (5 Aug 2026) · CoinDesk, Coldcard urges users to move bitcoin as exploit continues (4 Aug 2026) · Bloomberg, Coinkite declines to estimate losses (6 Aug 2026)
The Flaw, in Plain English
A seed phrase is nothing more than a very large random number written as words. Its entire security rests on that number being drawn from a space so large that guessing is hopeless — 128 bits of randomness, a number with 39 digits. Hardware wallets carry a dedicated hardware random number generator for exactly this job.
According to the root-cause analysis published by Block and summarized in security reporting, a March 2021 build change meant the Coldcard firmware stopped using that hardware generator for seeds. The build configuration asked whether the hardware-randomness setting existed rather than whether it was switched on, and so the code silently fell back to a software generator seeded from predictable values — the chip's serial number and its internal timers. Coinkite's own estimates, as reported by The Hacker News, put the effective randomness at roughly 40 bits on Mk3-era devices and roughly 72 bits on the Mk4, Mk5 and Q, instead of the 128 promised. Block deliberately declined to reduce it to a single practical figure.
Forty bits is a search a well-resourced attacker finishes. Seventy-two bits is a vastly harder search, and it is not public how far the attackers got against the newer models — but it is still far below what was promised, and Coinkite's advisory treats every affected model the same way: migrate. Because the weakness lives in the seed itself, none of the Coldcard's celebrated defenses apply: the air gap, the secure elements, the PIN — all of them protect the device, and the attacker never needs the device. They reconstruct the seed on their own hardware, derive the addresses, and sweep whatever is there.
Two details make this stark. The flaw was introduced by accident and sat in published source code for five years — Coldcard's firmware is source-available, and nobody caught it. And the public learned of it the worst way possible: the advisory and the first mass theft landed on the same day.
Sources: The Hacker News, Coldcard flaw linked to $70M theft in 41 minutes (1 Aug 2026) · Coinkite, Coldcard security advisory (30 July 2026)
Which Seeds Are Affected
The single question that matters: what firmware was running when your seed was generated? Not what is installed now. Per Coinkite's advisory:
If you cannot remember which firmware the device was on when you set it up — and almost nobody can — the date is the practical test. A seed created on a Coldcard from March 2021 until the patched releases of July 2026 should be treated as affected.
Not affected
- Seeds created with at least 50 fair, independent, private dice rolls — Coinkite says it does not consider these at risk from this bug alone
- Seeds generated on Mk2/Mk3 firmware before 4.0.1 (before March 2021), per the advisory’s affected ranges
- TAPSIGNER, OPENDIME and SATSCARD, which Coinkite says run different codebases
- Seeds generated on another device or in other software and merely imported into the Coldcard — the advisory does not address these directly, but they are unaffected by construction, because the flaw is in on-device seed generation
What to Do Now
This mirrors Coinkite's own advisory, with the habits this site already teaches applied to the migration.
Assume your seed is affected until you can prove otherwise
If your seed was generated on a Coldcard at any point since March 2021 and you did not use 50+ dice rolls, treat it as compromised now. Do not wait to see whether your address gets swept. The thefts ran in waves, and being missed in one wave means nothing about the next.
Update the firmware, then generate a completely new seed
Coinkite has published fixed firmware for every affected model and release track; its advisory lists the exact upgrade path for each. But the update only fixes how future seeds are made. It cannot add randomness to a seed that never had it, which is why Coinkite’s own advisory says to generate a new seed on the updated device. A new seed on a different vendor’s device is also a perfectly good answer.
Send a test amount to the new wallet first
Same discipline as any migration: send a small amount to the new wallet, verify the address on the device screen, wait for it to confirm, then move the rest. Coinkite’s advisory says the same.
Move everything, then never use the old seed again
Empty the old wallet completely, including any wallets protected by a passphrase on the same seed. Coinkite calls a strong passphrase an independent barrier, but still says to migrate — once the seed words themselves can be reconstructed, everything rests on the passphrase alone, and ordinary passphrases fall to brute force. The old seed is burned. Once you have confirmed a zero balance everywhere that seed was ever used — every account, every passphrase wallet — destroy the old backups so nobody mistakes them for live ones later.
Expect the phishing wave that follows every incident
Incidents like this are immediately followed by fake "migration tools", fake support agents, and fake advisory emails aimed at exactly the people scrambling to respond. The rule does not change: no legitimate wallet, support agent, or migration process will ever need your recovery phrase. Type it into a hardware wallet you are deliberately restoring, or into nothing.
What This Changes, and What It Does Not
Until 11 August 2026, our self-custody guide recommended the Coldcard. The link was never an affiliate link, so no revenue rode on the recommendation — but the recommendation was ours, and we are not going to pretend it never existed. We removed it while the exploit is active and the post-mortem is pending, and we will reassess when Coinkite publishes its full account. Nobody outside Coinkite caught the flaw, and that includes us: it sat for five years in code anyone could read, and the signals everyone relied on — published source code, a long track record, a security-obsessed reputation — all pointed the right way the whole time.
That is precisely the lesson. Choosing a hardware wallet moves trust from your computer to a vendor, and no amount of reputation reduces that trust to zero. The defenses that actually contained this flaw existed before it was found, and they are the unglamorous ones:
Supply your own randomness
Coldcard users who built their seeds from 50+ fair, independent, private dice rolls are the ones Coinkite says it does not consider at risk from this bug alone. Dice-roll randomness exists for exactly this failure: it removes the vendor's random number generator from the list of things you have to trust.
Multisig across vendors
A 2-of-3 wallet with keys on devices from different manufacturers survives any single vendor's catastrophic bug, because one reconstructed seed is still one signature short. This incident is the strongest real-world argument for that setup to date.
And what it does not change: the boring hierarchy of how bitcoin is actually lost. Vendor firmware bugs of this severity have now happened once at scale. Lost backups, phishing, and seeds typed into websites happen every single day, and they do not pause while the news cycle runs. The habits that defend against those — tested backups, on-device verification, buying direct — are unchanged, and they still matter more than which box you buy.
Common Questions
I updated my Coldcard firmware. Am I safe now?
Not if your seed was generated on the old firmware. The update fixes how new seeds are generated; it does nothing for a seed that already exists. If your seed was created on affected firmware, you need to generate a new seed on the patched device and move your funds to it. That is Coinkite’s own guidance, not ours.
My Coldcard is air-gapped and has never touched a computer. Does that protect me?
No, and this is the uncomfortable part. The flaw is in the seed itself: it was generated with far less randomness than it should have been, so attackers can reconstruct affected seeds by brute force on their own hardware, without ever contacting your device. The air gap protects a good seed from a bad computer. It cannot protect a weak seed from arithmetic.
I used dice rolls when I set up my Coldcard. Am I affected?
Coinkite says a seed built with at least 50 fair, independent, private dice rolls is not at risk from this bug alone. Fewer rolls than that, or rolls you are not sure about, and the honest answer is to migrate anyway. The cost of an unnecessary migration is an afternoon and a transaction fee. The cost of the other mistake is everything in the wallet.
Does this mean hardware wallets are pointless?
No. The lesson is narrower and more useful: a hardware wallet moves trust from your computer to the device vendor, and vendors can fail too. The mitigations that already existed are the ones that worked here — supplying your own entropy with dice rolls, and multisig across devices from different vendors, so no single vendor’s bug can reach the threshold. What empties most wallets is still lost backups and phishing, not firmware bugs. But firmware bugs are no longer hypothetical, and pretending otherwise would be marketing.
Sources
Firmware ranges and required actions are cited to Coinkite's own advisory. Technical root-cause details come from the security reporting on Block's analysis; the effective-randomness estimates are Coinkite's, as reported there. Loss figures are attributed to the named tracker with the date of the count, because they were still moving when this page was written. Where a claim is our inference rather than a source's statement, it is marked as such in place.
- •Coinkite, Coldcard security advisory (30 July 2026)
- •The Hacker News, Coldcard flaw linked to $70M theft in 41 minutes (1 Aug 2026)
- •TRM Labs, inside the $116M Coldcard hack (5 Aug 2026)
- •CoinDesk, Coldcard urges users to move bitcoin as exploit continues (4 Aug 2026)
- •Bloomberg, Coinkite declines to estimate losses (6 Aug 2026)
Last updated: 11 August 2026. If you own an affected device, Coinkite's advisory — not this page — is the authoritative source for your model's exact upgrade path.
Disclaimer: This page is educational and is not financial or security advice. It summarizes an incident that was still developing on the date above; verify current guidance against Coinkite's own advisory before acting. This site's Coldcard links were never affiliate links. Our hardware wallet comparison, including its affiliate disclosures, is on the self-custody guide.