NewsCryptoColdcard Ships Major Security Firmware After $130M Bitcoin Seed Exploit

Coldcard Ships Major Security Firmware After $130M Bitcoin Seed Exploit

Author: Crypto Adventure·

Key Takeaways

  • The seed-generation flaw, introduced in 2021 firmware, cut effective entropy to roughly 40 bits on Mk2/Mk3 devices and about 72 bits on Mk4, Mk5, and Q models instead of the intended 128, letting attackers reconstruct seeds offline without physical access to devices or recovery phrases.
  • Galaxy Research attributed 1,778.84 BTC worth $112.7 million across more than 8,600 addresses with high confidence after contacting 190 victims, while including medium-confidence activity such as a suspected fourth wave could raise the total to 2,417.35 BTC, about $153 million.
  • New seed creation now requires user-contributed randomness via at least 65 key presses, 50 dice rolls, or 128 coin flips, combined with the STM32 hardware RNG and both secure elements, and Coinkite replaced the Yasmarang backup generator with SHA-256 Hash_DRBG plus boot-time RNG checks.
  • Users whose seeds were generated on affected firmware between March 2021 and July 2026 must create a new seed and move their Bitcoin, because installing the latest firmware does not repair a recovery phrase created with insufficient entropy.
  • Law enforcement authorities are investigating with attacker addresses supplied by Galaxy, and roughly 1,531 BTC of confirmed stolen funds remain unmoved while about 246 BTC has moved, with around 65% of that entering CoinJoin transactions.
Coldcard Ships Major Security Firmware After $130M Bitcoin Seed Exploit

Coinkite, maker of the Coldcard hardware wallet, has released a major security firmware update after attackers exploited weak seed generation to steal more than 1,778 BTC from thousands of Bitcoin addresses, with earlier estimates placing the broader attack at close to $130 million.

The August 20 release introduces firmware 5.6.1 for the Mk4 and Mk5 devices and 1.5.1Q for the Q, following three weeks of security review after the July 31 hotfix. Under the new seed-generation process, every newly generated seed requires users to contribute their own randomness through at least 65 key presses with unpredictable timing, 50 physical dice rolls, or 128 physical coin flips.

Users whose seeds were generated on affected firmware between March 2021 and July 2026 still need to create a new seed and move their Bitcoin. Installing the latest firmware does not repair a recovery phrase created with insufficient entropy, which is why the update matters even for users who have not noticed any issue with their device.

Coldcard Adds User Randomness and New Signing Checks

The updated seed-generation process combines user input with fresh entropy from Coldcard's STM32 hardware random-number generator and both of the device's secure elements. Coinkite also replaced its Yasmarang backup pseudo-random generator with SHA-256 Hash_DRBG and added boot-time checks designed to stop the device if the intended hardware RNG path is not reached.

The original seed-generation flaw stemmed from firmware introduced in 2021. Affected Mk2 and Mk3 seeds could contain only about 40 bits of effective entropy, while later Mk4, Mk5 and Q devices could fall to roughly 72 bits instead of the intended 128. That weakness allowed attackers to reconstruct candidate seeds offline and compare derived addresses against the Bitcoin blockchain without stealing the physical device or recovery phrase.

Coldcard has also added a second check of staged partially signed Bitcoin transactions immediately before signing. A transaction modified by a compromised USB-connected computer after the user reviews it will now stop with a "Transaction modified" warning. The release further tightens USB access, firmware validation, Delta Mode isolation, wallet backups, and RNG fault handling.

Confirmed Coldcard Losses Reach 1,778 BTC

The theft initially expanded through several distinct attack waves. A subsequent third wave pushed the observed total above 1,367 BTC before more victims and attacker footprints were identified.

By August 14, Galaxy Research had directly contacted 190 victims and attributed, with high confidence, 1,778.84 BTC worth $112.7 million to more than 8,600 addresses. That figure excludes medium-confidence activity, including a suspected fourth wave; adding those candidate thefts would raise the potential total to 2,417.35 BTC, worth about $153 million at the time.

The earlier loss estimate near $132 million emerged as Galaxy identified at least 15 attackers exploiting the same weak-seed problem. No confirmed new attack footprint has been dated after August 6, although additional victims have continued reporting earlier losses.

About 1,531 BTC from the high-confidence theft set remained unmoved as of Galaxy's latest analysis. Roughly 246 BTC had moved afterward, with about 65% of that amount entering CoinJoin transactions.

Law Enforcement Investigates as Users Migrate Bitcoin

Coinkite said law enforcement authorities are investigating the thefts and working to identify those responsible. Galaxy has supplied attacker addresses to law enforcement agencies, exchanges, and investigation firms to support tracing and potential intervention if stolen Bitcoin reaches centralized services.

The exploit has also accelerated broader review of Bitcoin software. The Bitcoin Red Team recently produced thousands of security findings across hundreds of open-source projects using human researchers and AI-assisted analysis, while Coinkite drew on external researchers and AI models during its own three-week firmware review.

Affected Coldcard users should first install fixed firmware, generate and verify an entirely new seed, confirm a receiving address, and then move the Bitcoin onchain. Importing the old recovery phrase into another wallet leaves the vulnerable seed unchanged.

Coinkite currently recommends firmware 5.6.1 for Mk4 and Mk5 and 1.5.1Q for Q. Mk2 and Mk3 users require version 4.2.0 or later, and any affected seed must still be replaced separately from the firmware upgrade.