21 BTC
Share this page
Discuss
Security · Checklist3 min read

The Coldcard seed bug: what happened, who is at risk, and a 7-step checklist

A 2021 firmware mistake made some Coldcard seeds guessable. Since 30 July 2026 attackers have taken around 1,400–2,050 BTC. What went wrong and what to do now.

Since 30 July 2026, attackers have been emptying Coldcard hardware wallets. Nobody broke into the devices. The problem was the seed phrase itself: on some firmware versions it was created with too little randomness, so attackers could guess it on their own computers and then sweep the coins.

Important

Updating the firmware does not fix a seed that was already created on affected firmware. If your seed is affected, you need a new one and must move your coins to it.

What went wrong

A wallet seed must be picked from a pool of possibilities so huge that no computer can try them all. Coldcard was supposed to get that randomness from a hardware random-number generator inside the device.

In a March 2021 firmware update, seed generation was routed to a simple software generator by mistake. That generator was seeded from device and timing data, which is far less random.

  • Mk2 and Mk3, firmware 4.0.1 to 4.1.9 (Block traces the code path to 4.0.0): seeds can be as weak as about 40 bits instead of the intended 128.
  • Mk4, Q and Mk5: extra randomness from the secure chips reduced the damage, but Coinkite estimates about 72 bits instead of 128.

According to CoinDesk, the code was open for anyone to read, yet the mistake went unnoticed for years.

How much was stolen

Estimates differ because thefts are still being discovered:

SourceEstimate
BlockSec, as of 7 Augat least ~1,405 BTC from ~4,925 addresses; up to 2,055 BTC with victims' private reports
Galaxy Research, via CoinDesk1,596 BTC from about 7,300 addresses (high confidence)
TRM Labs (preliminary)~1,816 BTC from more than 5,200 addresses, in four waves

Galaxy's Alex Thorn estimated on 4 August that at least 15 different attackers were exploiting the flaw. You can see this incident next to other large losses on our Hacks & losses page.

Who is at risk

Coinkite's advisory says funds are at risk if the seed was created on affected firmware unless:

  • you added at least 50 independent, private dice rolls when creating the seed, or
  • the wallet is protected by a strong, unique BIP-39 passphrase.

If you are not sure when or how your seed was made, treat it as affected.

The checklist

  1. Find out when, and on which firmware, your seed was created. If you don't know, assume it is affected.
  2. Update the device to fixed firmware: 4.2.0 (Mk2/Mk3), 5.6.0 (Mk4/Mk5), 1.5.0Q (Q), or Edge 6.6.0X / 6.6.0QX.
  3. Create a new seed on the fixed firmware. Adding your own dice rolls is extra protection.
  4. Send all your coins to addresses from the new seed. Do it soon: thefts came in waves.
  5. Back up the new seed (a metal backup survives fire and water) and check that the backup restores.
  6. Consider a strong, unique passphrase on top of the seed. Store it separately from the seed.
  7. Ignore anyone offering to "recover" stolen coins for a fee. (Our advice, not from the advisory.)

Steps 1–4 follow Coinkite's advisory. For a calmer setup, see our guides on Learn and the cold wallet comparison.

The lesson

Open-source code only helps if someone reviews it. A single silent build mistake survived five years. Using more than one vendor, for example in a multisig setup, means one vendor's bug cannot empty everything. (Our view.)

In Lugano

Educator BTC Sessions and Nathan Fitzsimmons run several security sessions:

  • 23 Oct, 10:15 Lugano / 11:15 MSK, UTXO Room: "Bitcoin Security Is a Spectrum: Lessons from the ColdCard Hack"
  • 23 Oct, 17:00 / 18:00, WAGMI Stage: "Self Custody Disaster – Lessons Learned and What Comes Next"
  • 24 Oct, 14:45 / 15:45, UTXO Room: "WTF Is Entropy and How Do You Get It?"
  • 24 Oct, 17:45 / 18:45, UTXO Room: "Could Your Family Access Your Bitcoin If You Died?"

Sources

  1. Coinkite: Technical deep dive into the entropy issue (advisory) blog.coinkite.com
  2. Block Engineering: Predictable RNG fallback and 32-bit reseed in COLDCARD firmware engineering.block.xyz
  3. TRM Labs: Inside the USD 116 million Coldcard hack trmlabs.com
  4. CoinDesk: How a bug in Coldcard's code went unnoticed for years (17 Aug 2026) coindesk.com
  5. BlockSec: When a wallet's random seed wasn't random blocksec.com
  6. Plan ₿ Forum agenda planb.lugano.ch

Times are Lugano (CEST, UTC+2) and Moscow (UTC+3). Not investment advice.

Found this useful? Share the article or any section (↗ next to each heading).↑ Share

Read next