Coldcard Wallet Firmware Bug Exposes Bitcoin Seeds After $70 Million Stolen
Key Takeaways
- •Over 1,082 BTC valued at more than $70 million has been stolen from Coldcard hardware wallet users across 1,196 affected Bitcoin addresses.
- •The firmware bug caused seed generation to produce only approximately 40 bits of entropy instead of the intended 128 bits, making private keys predictable and vulnerable to brute-force attacks.
- •The vulnerability went undetected for over four years after being introduced in firmware version 4.0.1 released in March 2021, affecting multiple Coldcard device generations including the Mk3, Mk4, Mk5, and Q models.
- •Coinkite advises any user who generated a seed with fewer than 50 dice rolls to create an entirely new seed on an updated device.
- •Some security experts, including Wizardsardine CEO Kevin Loaec, have warned that every mnemonic generated via Coldcard since 2021 could be publicly exposed and recommended abandoning the hardware entirely.

A critical firmware vulnerability in Coldcard hardware wallets, manufactured by Coinkite, has enabled attackers to steal over $70 million in Bitcoin, exposing seed phrases generated across multiple device models since 2021.
Coinkite confirmed on Thursday that its Coldcard Mk3 model was affected by the vulnerability and urged users to relocate their funds immediately. The following day, the company expanded its advisory, warning that users of the Mk4, Mk5, and Q devices should also take precautionary measures.
The Attack
Hackers first exploited the vulnerability on Thursday, draining funds from 1,196 Bitcoin addresses whose private keys had been generated with insufficient entropy — the randomness essential to cryptographic security.
According to data compiled by Galaxy Research and engineers at payments company Block, a total of 1,082.65 Bitcoins have been stolen from affected wallets. The initial theft on Thursday moved 594.5 BTC — valued at over $35.7 million — from single-signature addresses to a new consolidating address.
NEW: Over 594 BTC worth $38 million was stolen from Bitcoin hardware wallet Coldcard users. The attacker then moved around the BTC and consolidated 562 BTC into this address below. Users are urged to review the company's official security guidance as soon as possible. pic.twitter.com/exD2Wax7CY — Bitcoin Magazine (@BitcoinMagazine) July 31, 2026
Blockchain analysts reported additional wallet drains in the days that followed, bringing total losses past $70 million. Multiple affected users recounted their experiences on social media, including one individual who stated that their Bitcoin had remained untouched since 2021 before being suddenly swept.
Coinkite and other engineers in the Bitcoin ecosystem continue to investigate ongoing wallet drains reported at the time of writing.
Technical Root Cause
A firmware bug present in Coldcard Mk3 devices beginning with version 4.0.1, released in March 2021, caused seed generation to fall back to a weak software pseudo-random number generator (PRNG) rather than the device's hardware true random number generator (TRNG). As a result, generated seeds contained only approximately 40 bits of entropy instead of the intended 128 bits.
To put this in perspective, 128 bits of entropy represents a keyspace so vast that brute-forcing it is computationally infeasible with current technology. At approximately 40 bits, the keyspace shrinks to roughly one trillion possible combinations — a range modern hardware can search exhaustively in practical timeframes. This is why affected seeds became vulnerable to systematic brute-force attacks.
This dramatic reduction in randomness rendered private keys for many single-signature wallets — particularly those created without dice roll entropy or a strong BIP-39 passphrase — predictable enough for attackers to brute-force.
While Coinkite has not explicitly confirmed that the thefts are directly linked to this vulnerability, the company acknowledged that the seed generation bug prevented the hardware TRNG from being utilized on certain firmware versions. The vulnerability went undetected for over four years, spanning firmware releases across multiple device generations.
Coldcard has been widely regarded in the Bitcoin community as one of the more security-focused hardware wallet options, marketed for its air-gapped design and open-source firmware. The scope of the vulnerability — affecting seed generation across years of device shipments — raises questions about the robustness of independent security audits and review processes for self-custody hardware, an area that has seen growing institutional and retail adoption since 2021.
Official Response and Guidance
Coldcard issued security guidance for affected users, available at blog.coinkite.com/entropy-technical-backgrounder.
The first post was the advisory and what users should do. This second post has the technical details: what actually went wrong, why our reviews missed it, the impact across Mk3/Mk4/Q/Mk5, and what we changed. ( current evaluating Mk3 firmware release ) — COLDCARD (@COLDCARDwallet) July 31, 2026
Coinkite initially identified only the Mk3 as affected but subsequently advised on Friday that any user who did not use sufficient entropy to generate a seed — specifically, fewer than 50 dice rolls — should create an entirely new seed on an updated device.
Some security experts have gone further, recommending that users abandon Coldcard hardware entirely to ensure the safety of their funds.
"Everything is fucked," wrote Kevin Loaec, CEO of Bitcoin security company Wizardsardine, in a public statement.
"Every single mnemonic generated [via a Coldcard] since 2021 will be public in the next few days," Loaec warned.
This article is based on reporting by Mathew Di Salvo for Bitcoin Magazine.