Coldcard Wallet Hack: What Bitcoin Holders and Miners Need to Know

This is general information, not financial or legal advice. Verify everything against Coinkite’s official security notice before acting. 

 

Key Takeaways 

  1. Coldcard owners: Follow official Coinkite Blog and Updates here: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/ 
  2. A firmware flaw made some Coldcard private seeds guessable.  The bug dates back to firmware released in March 2021. [1] [3] 
  3. Attackers swept roughly 594 BTC (about $38 million) in around 25 minutes. The theft hit about 500 single-signature wallets, most holding more than 0.15 BTC, many dormant for years. Some outlets put total exposure even higher. [1] [2] 
  4. What matters is the firmware used when your seed was created, not your firmware today. Updating firmware now does not fix a seed that was already generated with weak randomness. If you are affected, the only real fix is a brand-new seed. [3] [4] 

What Happened 

In late July 2026, a long-standing flaw in Coldcard, one of the most popular Bitcoin hardware wallets, was exploited to drain millions in minutes.  

The problem is a seed-generation flaw. When you set up a hardware wallet, it creates a random secret (the seed) that controls your funds. Security depends on that seed being truly unpredictable. On affected Coldcard devices, a firmware bug caused the device to bypass its hardware randomness source and fall back to a predictable, software-based value seeded from non-secret chip data. The result was seeds with roughly 72 bits of entropy instead of the intended 128, which is weak enough that an attacker can reproduce them. [1] [3] 

On July 31, 2026 (UTC), an attacker used that weakness to sweep about 594 BTC, worth roughly $38 million, from around 500 wallets in a window of about 25 minutes. Every drained wallet was single-signature, and each held more than 0.15 BTC. The flaw had been present in firmware since March 2021, so the exposed wallets were created across a multi-year span. [1] [2] 

Who Should Be Worried 

You have reason to check if all of the following are true: your seed was generated on the Coldcard device itself (not rolled with dice or imported), and it was created while the device ran affected firmware. As reported from Coinkite’s notice, that means Mk3 devices on firmware 4.0.1 or later, Mk4 and Mk5 devices before version 5.6.0, and Q devices before version 1.5.0Q. Single-signature wallets are the most exposed. [2] [4] 

  • Lower risk: seeds you generated yourself with 50+ die rolls, seeds imported from elsewhere, and Coinkite’s other products such as TAPSIGNER, OPENDIME, and SATSCARD, which were not affected. [4] 
  • Not automatically safe: multisig setups. A multisig is only protected if its keys were generated independently, ideally on different devices or vendors. If every key came from the same vulnerable process, an attacker could rebuild enough of them to sign. [4] 

If You May Be Affected, Inform Yourself First 

We are deliberately not publishing recovery steps here, because getting a single detail wrong with your own funds is costly and every situation is a little different. This is general information, not financial or legal advice. The one fact worth internalizing: a firmware update does not repair a seed that was already created with weak randomness, so any real fix involves moving funds to a freshly and securely generated wallet. Before you touch anything, read the primary sources below, confirm whether your exact device and firmware are in scope, and follow Coinkite’s official security notice. 

If the amounts involved are significant, consider getting help from a qualified security or legal professional rather than acting alone. 

Sources 

[1] Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep · CoinDesk 

[2] Coldcard Security Risk: Immediate Action Required · Bitcoin Magazine 

[3] A flaw in Coldcard seed generation lets attackers recreate private keys · CryptoSlate 

[4] Coldcard RNG flaw: is your wallet affected? · BeInCrypto 

Contact Us

BlockOps Mining — Enterprise-grade hosting for serious miners. 

Coldcard Wallet Hack: What Bitcoin Holders and Miners Need to Know