Wednesday, August 12, 2026

Coldcard Hardware Wallet Vulnerability Linked to $111 Million in Stolen Bitcoin

Hyperreal neon illustration of a Coldcard wallet with cracked seed and glowing RNG lines on a blue digital background.

A vulnerability in Coldcard hardware wallets has been linked to the theft of at least 1,719 BTC, valued at roughly $111 million, as investigators continue tracing additional suspicious transactions. Galaxy Research said more coins remain under review and estimated total losses could eventually exceed $130 million, leaving the final scale of the incident unresolved.

The attacks began on July 30 and unfolded across multiple waves involving thousands of Bitcoin addresses. Investigators have identified different transaction patterns, raising the possibility that more than one attacker exploited the same weakness. The compromise originated in Coldcard’s seed-generation process rather than Bitcoin itself, allowing attackers to target vulnerable private keys without gaining physical access to the hardware wallets.

Weak randomness made recovery seeds vulnerable

The flaw traces back to firmware released in March 2021. Coldcard normally generates seeds using strong hardware-derived entropy, but the faulty implementation could fall back on substantially weaker randomness. That reduction made some recovery seeds predictable enough for attackers to generate possible keys offline and compare their addresses against the public Bitcoin blockchain. Galaxy Research said effective entropy could fall to about 40 bits on older devices and roughly 72 bits on newer affected models.

Security firm SlowMist reached a similar conclusion in its technical analysis of the Coldcard vulnerability, linking the thefts to weaknesses in private-key generation. Because the vulnerability exists in the seed itself, an attacker does not need to steal, connect to or physically manipulate the Coldcard device once a sufficiently weak seed has been identified.

Coinkite confirmed the problem in its official Coldcard security advisory, which has since been updated as its investigation progressed. The company says affected seeds include those generated on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9, as well as Mk4, Mk5 and Q devices running firmware released before their respective fixes. Coinkite has released corrected firmware across affected product lines, but installing an update cannot repair a seed that was already generated with insufficient entropy.

Existing wallets require new seeds, not just updates

Coinkite is advising affected users to install patched firmware, create an entirely new recovery seed and migrate their Bitcoin to addresses controlled by the replacement wallet. Simply updating an existing Coldcard while continuing to use the old recovery phrase does not eliminate the exposure, because the weakness remains embedded in the original seed.

The manufacturer also says seeds supplemented during creation with at least 50 fair, independent and private dice rolls are not considered exposed to this RNG flaw alone. Strong BIP-39 passphrases provide an additional barrier, although Coinkite still recommends migration. The incident demonstrates that hardware-wallet security ultimately depends not only on keeping keys offline, but also on the integrity of the process that generates those keys in the first place.

Scroll to Top
Chain Report
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.