The Coldcard attack: how wallets were drained and how to protect yours
A flaw in Coldcard's randomness, present since 2021, left recovery phrases weak. See the timeline, who is exposed and how to migrate.

The short answer
Between July 30 and early August 2026, an attacker emptied more than a thousand Bitcoin addresses tied to Coldcard wallets — a popular hardware wallet, the physical device that keeps keys off the internet. Loss estimates vary by source, from roughly US$70 million to US$116 million. The cause was neither physical tampering nor a weak password: a build error in Coldcard's firmware, present since March 2021, made the device generate the recovery phrase — the "seed" that unlocks the entire balance — with insufficient randomness. Part of the keys became weak enough to brute-force without any access to the device.
This article covers what is known so far, why the flaw happened, who is exposed and what to do — including lessons that apply to any wallet, not just Coldcard.
What is known so far
- March 2021: a firmware update — the device's internal software — from version 4.0.1 introduced a configuration error. It went unnoticed for more than five years.
- July 30, 2026: the attack begins. In one wave, about 1,196 addresses were emptied in 41 minutes. On-chain analytics firm TRM Labs describes the first sweep as roughly 594 BTC (about US$38 million) taken from around 500 addresses in 25 minutes.
- July 31, 2026: Coinkite, the Canadian maker of Coldcard, ships emergency firmware for every affected model along with a security advisory.
- Early August 2026: further withdrawal waves. Loss estimates diverge: Galaxy Research cites about 1,367 BTC (roughly US$89 million) and 4,585 addresses; TRM Labs cites about 1,816 BTC (roughly US$116 million) and more than 5,200 addresses.
- August 20, 2026: Coinkite releases versions 5.6.1 and 1.5.1Q, which go beyond seed generation to strengthen transaction re-verification before signing and data isolation on the device.
The figures are still being revised because the count depends on which withdrawal waves are attributed to the same attacker and on the price of Bitcoin at the moment of each transfer. Treat every number as approximate.
Why the flaw happened
Every wallet starts from a huge, unpredictable secret number. The 12- or 24-word recovery phrase is derived from it. Security depends on that number being truly random: if an attacker can shrink the set of possibilities, they can test them one by one until they find yours.
The measure of that unpredictability is called entropy, counted in bits. A 12-word seed should have 128 bits of entropy — a search space so large that sweeping it is infeasible. Coldcard was supposed to draw those bits from a hardware random number generator: a dedicated circuit inside the chip.
The 2021 error was in how the software was built. A setting that should have enabled the hardware generator ended up being checked only for existing, not for being enabled. In practice, the request for randomness fell back to a weak, predictable software generator seeded only by the chip's unique identifier and timer counters — data that carries no real unpredictability. Coinkite estimates the resulting effective entropy at about 40 bits on the Mk2 and Mk3 and 72 bits on the Mk4, Mk5 and Q, far below the expected 128 bits.
With entropy at that level, an attacker can reproduce offline the sequences the weak generator would produce, derive the matching addresses and compare them against the public blockchain to find which ones hold funds. That is what happened: no owner had to click a link, install anything or lose sight of the device.
Which Coldcards are exposed
The risk applies to seeds generated on the device itself within the vulnerable window. By model:
| Model | Vulnerable firmware | Fixed in |
|---|---|---|
| Mk2 and Mk3 | 4.0.1 to 4.1.9 (March 2021 onward) | 4.2.0 |
| Mk4 and Mk5 | any version before 5.6.0 | 5.6.0 (Edge line: 6.6.0X) |
| Q | any version before 1.5.0Q | 1.5.0Q (Edge line: 6.6.0QX) |
The TAPSIGNER, OPENDIME and SATSCARD products are not affected, as they use a different codebase. Seeds created with at least 50 fair, independent dice rolls that were not recorded or exposed carry no additional risk from this error, according to Coinkite, because in that case the randomness came from outside the faulty generator.
What to do now if you own a Coldcard
Updating the firmware does not fix a seed that was already generated. The fix only affects new seeds. If yours may have been created on the device between March 2021 and the update, treat it as compromised and migrate. The procedure Coinkite recommends:
- Install the fixed firmware, downloaded only from the official site, and verify the file signature.
- Generate a new seed on the already-updated device.
- Record and verify the backup of that new seed before depositing any value.
- Check the receive address on the device's own screen.
- Send a test transaction with a small amount.
- Only after confirming, move the rest of the funds to the new wallet.
- Keep the old backup until the migration is complete.
A strong, unique BIP-39 passphrase — an extra secret word added to the 12- or 24-word phrase — effectively creates a separate wallet and offers temporary protection. Even so, Coinkite recommends migrating as soon as practical. A multisig setup — where a transaction requires signatures from several devices — only helps if the keys do not all come from affected Coldcards.
What the case teaches for any wallet
The problem was specific to Coldcard, but the lessons apply to any self-custody setup.
Randomness is the foundation of everything. Where the wallet allows it, add your own source of entropy — such as the dice rolls Coldcard accepts — instead of blindly trusting the device generator.
Verify independently. A backup is only a backup once tested: restore the seed on another compatible device, confirm it reaches the same addresses and repeat that test periodically. The routine is detailed in the piece on custody, access and permissions.
Keep the secret off any connected device. Never photograph or type the recovery phrase into a site, form or app. The first precautions are in what a crypto wallet is and how to use it safely.
Distribute trust. For larger amounts, a multisig with devices from different manufacturers keeps a single failure — of hardware, firmware or vendor — from bringing everything down.
Keep a tested recovery plan. An emergency is not the time to find out whether you can restore the wallet. The self-custody in 2026 guide covers the three decisions: choosing the wallet, protecting the backup and testing recovery.
It is worth remembering that an on-device approval protects the key but does not validate the strategy or the recipient — a point covered in the piece on automation and hardware signing.
Checklist
- Identify your Coldcard model and the installed firmware version.
- Work out when and where your seed was generated; when in doubt, treat it as exposed.
- Update the firmware from the official site and verify the file signature.
- Generate a new seed on the fixed device and test the backup before depositing.
- Migrate funds with a test transaction first.
- Reassess multisig setups made up only of affected Coldcards.
- Do not treat the passphrase as a permanent fix; it is a bridge, not a repair.
- Be wary of "support" that shows up by message offering help with the migration.
Frequently asked questions
Do I need to act if I bought the Coldcard after the fix?
If the seed was generated on already-fixed firmware (5.6.0 or 1.5.0Q onward, or 4.2.0 on the older models) and was never on a vulnerable version, it is not affected by this error. Confirm the version before assuming so.
Does restoring my old seed on the new firmware solve it?
No. The weakness is in the seed itself, not in the firmware. Restoring it on an updated device keeps the problem. You must generate a new seed and move the funds.
I used dice to create my seed. Am I safe?
According to Coinkite, seeds created with at least 50 fair, independent dice rolls that were not recorded or exposed carry no additional risk from this error. If you used fewer rolls or are unsure, migrate.
Can the stolen money be recovered?
Bitcoin transactions are irreversible. On-chain analysts report that part of the funds sat in a few attacker addresses, with later use of mixers. There is no guarantee of recovery, and no central support able to reimburse.
Informational and educational content. It does not constitute investment advice, an offer or a solicitation to buy or sell assets.
Sources: Coinkite — seed-generation security advisory; Coinkite — 5.6.1 / 1.5.1Q update; Coinkite — technical backgrounder on the entropy flaw; The Hacker News — Coldcard hardware wallet flaw; TRM Labs — inside the Coldcard hack; CoinDesk — cold-wallet attack spreads. Reviewed on September 3, 2026.
Read more
A sound market reading combines data, context and clear risk limits.