Thursday, October 8, 2026
AI desk
/
/
Your “Safe” Coldcard Hardware Wallet May Have Already Been Drained: What the Firmware Flaw Means for Your Bitcoin

Your “Safe” Coldcard Hardware Wallet May Have Already Been Drained: What the Firmware Flaw Means for Your Bitcoin

A 2021 firmware bug in Coinkite’s Coldcard drained over $116M in bitcoin from 5,200+ addresses. Here’s what happened, who’s at risk, and what to do now.
Last updated
August 11, 2026
9 min read
Fact-checked

Photo: TechJournal

Share

Quick Answer

A build error in Coldcard firmware version 4.0.1 (March 2021) caused devices to generate wallet seeds with weakened randomness, reducing key strength to as little as 40 bits on Mk3 models. Attackers exploited this beginning July 30, 2026, draining more than 1,816 BTC (approximately $116 million) from over 5,200 addresses. Coldcard owners must install patched firmware, generate a new seed, and migrate all funds immediately.

Key Takeaways

  • The flaw traced to Coldcard firmware version 4.0.1 (March 2021), which silently replaced the device’s hardware random number generator with a weak software fallback for five years before exploitation.
  • Mk3 devices are the most severely affected, with effective seed entropy collapsing to roughly 40 bits, low enough for a GPU cluster to brute-force without ever physically accessing the wallet.
  • Mk4, Mk5, and Q models are also affected, but at approximately 72 bits of entropy, a weaker but still meaningful reduction from the designed 128 bits.
  • Patched firmware is available for all affected models (4.2.0 for Mk3, 5.6.0 for Mk4/Mk5, 1.5.0Q for Q), but installing it does not fix seeds already generated on vulnerable firmware, fund migration to a newly generated seed is required.
  • Seeds created with at least 50 independent, private dice rolls, or protected by a strong and unique BIP-39 passphrase, are not considered at risk under Coinkite’s advisory, though Coinkite still recommends migration as a precaution.

This article does not constitute financial or investment advice. Crypto self-custody carries unique technical risks. If significant funds are involved, consult a qualified security professional before taking action.

What exactly happened to Coldcard wallets starting July 30, 2026?

On July 30, 2026, an attacker began sweeping bitcoin out of wallets secured by Coldcard hardware devices, moving roughly 594 BTC worth close to $38 million out of approximately 500 wallets into a consolidation address within the first 25 minutes. That initial sweep was not the complete event. At least four waves of theft followed, and Galaxy Research’s running tally of losses stands near 1,816 BTC, worth close to $116 million, drained from more than 5,200 addresses, according to TRM Labs.

The attacks, which began on July 30 and continued in four distinct waves, represent the third-largest cryptocurrency hack of 2026, according to blockchain analytics firm TRM Labs. Galaxy Research cautioned that its findings are based on on-chain analysis and that it has not computationally confirmed that every identified address was generated with weak Coldcard entropy. Galaxy said the activity remains ongoing and that it has reported roughly 600 suspected attacker-controlled addresses to federal investigators, compliance firms, and cybersecurity investigators. The figures should therefore be treated as estimates that may change as tracing continues.

The incident has unsettled the crypto market because it targeted cold storage, long considered the safest way to hold bitcoin. The theft did not require a phishing link, a compromised exchange, or physical device access. The weakness existed silently inside the wallet’s own seed creation process.

What caused the firmware flaw, and why did it go undetected for five years?

A build configuration error in Coldcard firmware version 4.0.1, shipped in March 2021, routed seed generation to a deterministic software pseudorandom number generator instead of the device’s STM32 hardware random number generator, reducing effective entropy from 128 bits to approximately 40 bits on Mk3 devices and 72 bits on Mk4, Mk5, and Q models. This matters because 2 to the power of 40 is about 1.1 trillion candidates, enormous to a human but entirely searchable to a machine.

Block traced the fault to Coldcard’s production configuration, which defines MICROPY_HW_ENABLE_RNG as zero because Coinkite supplies its own hardware-RNG wrapper. The libngu library checked whether the macro existed rather than whether it was enabled, binding the build to MicroPython’s Yasmarang fallback. That fallback was initialized from the chip’s unique ID and timer registers and collected no fresh entropy after initialization. In practical terms, the device appeared to generate a fully random 24-word seed phrase, but it was drawing from a catastrophically small pool of possible outputs.

A seed built from 40 bits of predictable input still comes out as twelve perfectly ordinary BIP-39 words with a valid checksum. The wallet accepts it, derives addresses, and signs transactions; every screen shows exactly what a strong wallet would show. Statistical testing cannot help either: a deterministic generator seeded with predictable data still produces output that passes randomness tests. Coinkite believes the attacker used AI to discover the flaw in its open-source firmware, and says its own AI audit of the same code weeks earlier found nothing.

Which Coldcard models and firmware versions are affected?

Funds controlled by a seed generated on Mk2 or Mk3 firmware version 4.0.1 (March 2021) through 4.1.9 inclusive are at risk if the seed was created without at least 50 fair, independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase, according to Coinkite’s official security advisory. Coinkite expanded its advisory on August 1, 2026 after initially warning Mk3 owners. The company now says pre-fix Mk4, Mk5, and Q seeds had about 72 bits of entropy instead of the expected 128 bits.

ModelAffected Firmware RangeEffective EntropyFixed Firmware Version
Mk2 / Mk34.0.1 through 4.1.9~40 bits (designed: 128)4.2.0 or later
Mk4 / Mk5 (Standard)Before 5.6.0~72 bits (designed: 128)5.6.0 or later
Q (Standard)Before 1.5.0Q~72 bits (designed: 128)1.5.0Q or later
Mk4 / Mk5 / Q (Edge)Before Edge 6.6.0X / 6.6.0QX~72 bits (designed: 128)6.6.0X / 6.6.0QX
TAPSIGNER / OPENDIME / SATSCARDN/ANot affectedNo action required

One point from Coinkite’s advisory that many users miss: Standard and Edge are separate release tracks. An older Edge 6.x version number is not automatically fixed just because it looks higher than a standard 5.x release. Confirm which release track your device runs before assuming the installed firmware is patched.

Does updating the firmware fix the problem?

No. Installing patched firmware does not repair a seed that was already generated on vulnerable firmware. The update corrects how a new seed is created. It cannot change the private keys and addresses derived from the seed already controlling the wallet. That is why the response has two separate parts: install a fixed release before generating anything new, then transfer funds to addresses derived from a new seed.

The attack surface follows the recovery phrase itself, not the hardware that currently holds it. Restoring an affected seed onto patched firmware or onto any other wallet simply transfers the same weak secret. This applies equally to users who import their existing seed words into a different hardware wallet brand or a software wallet on a new device. The vulnerability travels with the seed phrase, not with the physical Coldcard. Users who hold bitcoin on exchanges and are evaluating self-custody wallet risks should understand that the security of a hardware wallet is entirely dependent on the integrity of its seed generation process.

What is the safe action plan for affected Coldcard owners?

Do not move funds until you have read the full official Coinkite advisory and understood each step. Coinkite’s guidance stresses one point repeatedly: move carefully. Rushing a wallet migration can create a bigger and more immediate risk than the flaw itself. Back up your current seed phrase and verify the backup before doing anything else. A migration error that sends funds to an unverified address is an irreversible loss.

Coinkite’s remediation process, as stated in its official security advisory, involves 5 ordered steps:

  1. Install the fixed firmware for your specific model and release track (see the table above). Do not generate any new seed until the update is confirmed.
  2. Generate a completely new seed on the patched device. Do not restore or import the old seed words at any point in this process.
  3. Write down and verify the new seed backup against the device display. Confirm the backup is accurate before proceeding.
  4. Verify a receiving address on the new wallet and send a small test transaction first.
  5. After confirming the test transaction arrived correctly, move remaining funds from the old wallet addresses to the new wallet addresses.

Official guidance stressed that installing the new firmware does not repair an existing seed; a completely new seed must be generated on the patched device, and funds must be migrated after verification of the new backup and receiving address. If a significant amount of bitcoin is involved, stop and contact a qualified Bitcoin security professional before proceeding. A migration error on a large holding cannot be reversed by any vendor, court, or authority.

Were seeds created with dice rolls or a BIP-39 passphrase protected?

Every Coldcard seed generated during the five-year vulnerable window without the manual dice-roll option is potentially compromised. Coinkite estimates that the dice-roll option, where users physically roll dice at least 50 times and type in the results, bypasses the broken code entirely. On the affected implementation, 50 to 98 private dice rolls contributed at least 128 bits of independent entropy, while 99 or more contributed approximately 256 bits. Fewer than 50 rolls, or an uncertain memory of the count, does not meet Coinkite’s exception.

The BIP-39 passphrase (sometimes called the “25th word”) provides a separate layer of protection, but its effectiveness depends entirely on its strength. If your seed was generated on an affected Coldcard Mk3, you should take this seriously even if you used a passphrase. A strong, unique passphrase may still protect your wallet, but a short or predictable one can be brute-forced if the seed is compromised. Coinkite’s guidance is not to treat a passphrase as the fix. If your seed was generated on an affected device, migrate to a new seed regardless of whether a passphrase is attached to it. Users who rely on passphrase-based account protection in other security contexts should note that the same principle applies here: a passphrase is a secondary layer, not a replacement for a secure primary credential.

What does this mean for Bitcoin self-custody and hardware wallet security more broadly?

Security researchers stress the Coldcard incident is not evidence that self-custody is inherently riskier than exchange custody, but rather that it carries a different category of risk: firmware and supply-chain integrity, rather than counterparty or exchange-solvency risk. That distinction matters for users deciding how to hold bitcoin. Exchange custody exposes funds to platform insolvency, hacks, and account freezes. Self-custody exposes funds to the integrity of the device’s firmware and the user’s own operational security.

Open-source firmware makes such flaws theoretically auditable, but the March 2021 commit that introduced the Yasmarang PRNG regression went undetected for over five years across thousands of deployments. Kraken CSO Nick Percoco called for independent testing of seed generation in production firmware. If Ledger, Trezor, and other manufacturers adopt third-party entropy audits as standard practice, it validates the systemic concern. If they do not, the industry is betting the same class of bug will not appear elsewhere. Trezor has stated that its devices use a different entropy generation approach and that the Coldcard vulnerability is specific to Coldcard’s firmware build process, according to reporting by crypto.news. Independent analysis of the affected libngu library was also published by Bitcoin Magazine, which traced the Yasmarang fallback path through the MicroPython build system in detail.

For US Bitcoin holders tracking the broader regulatory picture, the SEC and CFTC had not commented on the Coldcard exploit as of this writing. If regulators use the incident to argue that self-custody is unsuitable for retail investors, it could accelerate the push toward mandatory custodial frameworks for digital assets. No formal regulatory action has been announced as of August 11, 2026. Users concerned about regulatory risk around crypto self-custody may also want to follow IRS-related crypto security threats that have targeted holders in parallel.

FAQ

Does the Coldcard hack mean my bitcoin was already stolen?

Not necessarily. Funds controlled by seeds generated on affected firmware are at risk only if the seed was created without at least 50 independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase, according to Coinkite’s advisory. To confirm whether your specific addresses were swept, check them against the public Bitcoin blockchain using a block explorer. If funds are still present, treat the situation as urgent and follow the migration steps above before the wallet is targeted in a subsequent wave.

Can I just move my seed words to a different hardware wallet brand to stay safe?

Coinkite tells owners with exposed seeds to generate a new one on patched firmware and move their coins. Restoring the old seed to updated firmware or another wallet carries the weakness forward. The flaw is in the seed itself, not in the physical device. Importing the same 24 words into a Ledger or Trezor does not change the entropy of those words, and the resulting wallet remains vulnerable to the same brute-force reconstruction.

What firmware versions are confirmed safe for generating a new seed?

Fixed firmware versions were released for every affected track: 4.2.0 for Mk2 and Mk3, 5.6.0 for standard Mk4 and Mk5, 1.5.0Q for standard Q, and corresponding Edge builds 6.6.0X and 6.6.0QX. Confirm the installed version on the device’s settings screen before generating any new seed. Standard and Edge are separate release tracks, so verify the correct version for whichever track your device runs.

Is the Coldcard flaw a problem with Bitcoin itself?

The root cause was weak random-number generation dating to a March 2021 firmware build, not a flaw in the Bitcoin protocol itself. Bitcoin’s cryptography and blockchain are unaffected. The vulnerability existed entirely within Coinkite’s seed generation code, and the attacker exploited weak private keys rather than any weakness in how Bitcoin transactions are verified or recorded on-chain.

Should I still use a hardware wallet after this incident?

Hardware wallets remain a widely recommended approach to self-custody, but this incident demonstrates that firmware integrity is as important as physical security. Coinkite and independent researchers point to two broad principles: keeping device firmware up to date, since patches like the one Coinkite issued address known vulnerabilities, and using a strong BIP-39 passphrase, which independent researchers say would have made offline key reconstruction significantly harder. For holdings that represent a meaningful portion of your finances, consulting a qualified Bitcoin security professional before choosing a custody method is the most sensible approach.

Share this guide
Facebook
X
LinkedIn
Written by
Priya Sharma is a cybersecurity analyst and tech writer who covers digital privacy, online safety, and creative technology tools. She holds a CompTIA Security+ certification and writes about making security accessible for non-technical audiences. She’s passionate about the intersection of AI and creative work.

In this article

The AI Brief

Guides like this, every Friday.

One email. No hype cycle.

Keep reading