
A firmware vulnerability within the Coldcard hardware wallet ecosystem has enabled unauthorized actors to drain approximately 1,367 BTC Bitcoin, valued at nearly $89 million, from over 4,585 individual user addresses. The defect, which changed how seed phrases were generated on specific hardware units, traces to a March 2021 firmware build and went undetected for five years. Coinkite released an official statement acknowledging the financial losses incurred by users and the negative impact on consumer trust. Patched firmware is now available, but any seed generated on the affected versions remains vulnerable until the funds are moved to a newly generated wallet.
How the Coldcard Firmware Flaw Worked
The financial losses stem from a cryptographic coding error embedded within Coldcard’s core firmware architecture. Under standard operating conditions, hardware wallets utilize an internal, physical Hardware Random Number Generator to produce unpredictable entropy. This mathematical randomness is designed to ensure that the 12 or 24-word seed phrases generated by the device are unique and protected against predictive analysis. However, a software error caused the device to bypass this physical security mechanism. Instead, the system defaulted to a software-based pseudorandom number generator, sharply reducing the entropy of the resulting seeds. Coinkite’s advisory centres on Mk3 devices where the seed was generated on firmware 4.0.1 through 4.1.9, though the exposure extends further. Seeds created on Mk4 and Mk5 before version 5.6.0, and on Q devices before 1.5.0Q, carried roughly 72 bits of entropy rather than the intended 128. Coinkite says affected Mk2 and Mk3 seeds may have had as little as 40 bits.
— COLDCARD (@COLDCARDwallet) August 2, 2026
Because the underlying mathematical entropy was lowered, the resulting backup seeds lacked the variation required for standard security. This structural vulnerability allowed outside actors to launch computational brute-force operations entirely offline. By deploying software designed to systematically analyze these predictable numerical patterns, actors reconstructed the corresponding private keys. Once the private keys were determined, automated scripts executed transactions to transfer the funds to external addresses. Because the keys were analysed offline using public blockchain data, the operations required no physical access to the hardware. Technical mapping of the sweeps was published by Block, the fintech firm founded by Jack Dorsey, and by Galaxy Research. The first wave hit in the early hours of July 30, taking roughly 594 BTC, about $38 million at the time, from around 500 single-signature addresses in under half an hour. Later waves pushed the total past 1,300 BTC.
What Coldcard Users Need to Do Now
In an official public address to the user community, Coinkite confirmed it has permanently destroyed all remaining physical Coldcard inventory built with the affected firmware code to prevent further distribution. While the engineering team distributed an emergency patched firmware update, the company issued an explicit technical warning: installing this new patch does not secure or modify any seed phrase generated on the defective software versions. To secure their assets, affected users cannot rely on a simple software update. Instead, they must install the new firmware, generate a new seed phrase, and transfer all remaining funds to the new addresses. Coinkite released patched versions on July 31: 4.2.0 and later for Mk3, 5.6.0 and later for Mk4 and Mk5, and 1.5.0Q for Q devices. Not every owner is exposed. Coinkite says users who supplemented the wallet’s entropy with dice rolls, or who protected it with a strong BIP-39 passphrase, are substantially better placed, since the passphrase acts as an additional word the seed alone cannot reach. The company still recommends generating a new seed. Coinkite confirmed that its other product lines, including Satscard, Opendime, and Tapsigner, operate on entirely different software frameworks and remain unaffected by this issue.
Coldcard Firmware Flaw Drains $89M in Bitcoin From 4,585 Wallets
Operationally, Coinkite’s legal team is coordinating with international law enforcement agencies, utilizing blockchain analytics to track the movement of the transferred assets across public digital ledgers. In a formal advisory to affected users who may intend to discard their compromised hardware wallets, the company requested that they preserve their physical devices. The internal microchips contain specific cryptographic data that serves as essential forensic evidence, which may be required by authorities to verify ownership if asset recovery efforts progress. Rival manufacturers moved to distance themselves. Trezor told its users the problem is specific to Coldcard’s own firmware, which Trezor does not share, adding that it mixes randomness from multiple independent sources. Coinkite has said it is preparing a technical postmortem explaining how the coding failure occurred.



