Coldcard Wallet Hack: What Bitcoin Holders and Miners Need to Know

This is general information, not financial or legal advice. Verify everything against Coinkite’s official security notice before acting.

Key Takeaways

1
Cold Card Owners: This situation is ongoing. Follow official Coinkite updates here: Coinkite security warning.
2
A firmware flaw made some Coldcard private seeds guessable. The bug dates back to firmware released in March 2021. [1] [3]
3
Attackers swept roughly 594 BTC, about $38 million, in around 25 minutes. The theft reportedly hit about 500 single-signature wallets, many dormant for years. [1] [2]
4
What matters is the firmware used when your seed was created, not your firmware today. Updating now does not repair a seed that was already generated with weak randomness. [3] [4]

What Happened

In late July 2026, a long-standing flaw in Coldcard, one of the most popular Bitcoin hardware wallets, was exploited to drain millions in minutes.

The problem is a seed-generation flaw. When you set up a hardware wallet, it creates a random secret—the seed—that controls your funds. Security depends on that seed being truly unpredictable. On affected Coldcard devices, a firmware bug reportedly caused the device to bypass its hardware randomness source and fall back to a predictable, software-based value seeded from non-secret chip data. The result was seeds with roughly 72 bits of entropy instead of the intended 128, which was weak enough that an attacker could reproduce them. [1] [3]

On July 31, 2026 (UTC), an attacker reportedly used that weakness to sweep about 594 BTC, worth roughly $38 million, from around 500 wallets in a window of about 25 minutes. Every drained wallet was single-signature, and each held more than 0.15 BTC. The flaw had been present in firmware since March 2021, so exposed wallets were created across a multi-year span. [1] [2]

Who Should Be Worried

You have reason to check if all of the following are true: your seed was generated on the Coldcard device itself, not rolled with dice or imported, and it was created while the device ran affected firmware. As reported from Coinkite’s notice, that means Mk3 devices on firmware 4.0.1 or later, Mk4 and Mk5 devices before version 5.6.0, and Q devices before version 1.5.0Q. Single-signature wallets are the most exposed. [2] [4]

Lower risk: seeds you generated yourself with 50+ die rolls, seeds imported from elsewhere, and Coinkite’s other products such as TAPSIGNER, OPENDIME, and SATSCARD, which were not affected. [4]
Not automatically safe: multisig setups. A multisig is only protected if its keys were generated independently, ideally on different devices or vendors. If every key came from the same vulnerable process, an attacker could rebuild enough of them to sign. [4]
What to Do If You May Be Affected

If you use a Coldcard, this situation needs immediate attention. However, it's important not to panic. The safest short-term solution is to move your bitcoin to a brand new wallet created with a new seed or back to an exchange while you evaluate your next steps. Always send a small test transaction first and verify the receiving address before moving the rest of your funds.

If you want to learn more about this situation, the best place to start is by reading Block's research, which explains how the vulnerability worked and which devices are affected.

If your setup is particularly complex, such as multisig, multiple wallets, or a significant bitcoin balance, consider working with a professional before making changes. Companies such as Unchained provide collaborative custody and bitcoin security assistance. Never share your seed phrase, PIN, password, or authentication codes with anyone claiming to help.

Additionally, the BlockOps team found this Cyber Scrilla video walkthrough to be a helpful explanation of the vulnerability and recovery process.

Sources

Interested in Bitcoin Mining? Contact Us

Elevate your bitcoin mining operation with our comprehensive support & expertise