NewsCryptoCOLDCARD Seed Generation Flaw Puts Hundreds of Hardware Wallets at Risk After $40 Million Bitcoin Theft

COLDCARD Seed Generation Flaw Puts Hundreds of Hardware Wallets at Risk After $40 Million Bitcoin Theft

Author: Crypto Ninjas·

Key Takeaways

  • Approximately 594 BTC, worth close to $40 million at current market prices, was stolen from wallets potentially linked to the seed generation vulnerability in COLDCARD Mk3 devices.
  • Software flaws in Mk3 firmware version 4.0.1 and later reduced the entropy of generated wallet seeds by bypassing the more secure hardware random number generator.
  • Coinkite has released emergency firmware updates for its current-generation devices, but emphasizes that users must create entirely new seeds and transfer all funds to fully remediate the issue.
  • The company suspects attackers may have leveraged AI algorithms to analyze COLDCARD's open-source firmware, exploiting a vulnerability that had gone undetected during prior AI-assisted code reviews.
  • Users who incorporated 50 or more private dice rolls during initial wallet setup were considered relatively safe because they supplied their own entropy rather than relying on the faulty generator.
COLDCARD Seed Generation Flaw Puts Hundreds of Hardware Wallets at Risk After $40 Million Bitcoin Theft

A critical vulnerability in COLDCARD's Bitcoin wallet seed generation algorithm has raised serious concerns across the self-custodial wallet community, following reports that approximately 594 BTC — valued at nearly $40 million at current market prices — were stolen from wallets potentially linked to the flaw. The discovery has put hundreds of hardware wallets at risk and prompted an urgent response from Coinkite, the company behind the COLDCARD product line. COLDCARD devices are widely used by Bitcoin holders for their air-gapped design and open-source architecture, making the vulnerability particularly significant for users who rely on the devices for long-term cold storage.

COLDCARD Issues Urgent Security Advisory

Coinkite released an urgent security advisory warning that wallet seeds generated on the Mk3 device running firmware version 4.0.1 or later may be vulnerable to exploitation.

COLDCARD Mk3 Security Advisory

If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk.

Mk4, Q and Mk5 are not affected based on our early analysis.

Read the advisory and migrate carefully:

— COLDCARD (@COLDCARDwallet) July 30, 2026

According to the company, a chain of software flaws prevented the hardware random number generator from contributing the anticipated amount of entropy during wallet seed creation. As a result, certain aspects of seed production relied on a less robust software-based randomization scheme instead of the more secure hardware entropy source that users expected. In cryptographic terms, a wallet seed — typically expressed as a 12- or 24-word recovery phrase under the BIP39 standard — derives every private key in the wallet. If the seed's entropy is insufficient, the space of possible seeds may be small enough for an attacker to reconstruct, granting full access to all associated funds.

Coinkite later confirmed that seeds generated prior to the newly released firmware updates could also be affected. However, the company estimated the security impact on its specific devices to be very low. Users who incorporated 50 or more private dice rolls during their initial wallet setup were considered relatively safe, as they provided their own entropy source rather than relying on the device's faulty generator.

Approximately 594 BTC Stolen

The disclosure drew immediate attention after reports surfaced that roughly 594 BTC had been stolen from wallets associated with the vulnerability. At current market prices, this amount represents close to $40 million in Bitcoin. The theft reportedly occurred over the prior weekend.

AI as a Potential Attack Vector

Coinkite indicated that if attackers successfully exploited the weakness, they may have employed sophisticated AI algorithms to analyze the publicly released source code. COLDCARD's firmware is open source, and the company acknowledged that threat actors could have leveraged state-of-the-art artificial intelligence tools to uncover vulnerabilities that traditional code review methods failed to detect.

Notably, Coinkite added that it had recently conducted a thorough audit of its own codebase using one of the most popular AI models in the industry — and the error was still identified during that review. The company noted that its investigation is ongoing and that its understanding of how the attacks were carried out remains preliminary.

Emergency Firmware Updates Released; Users Urged to Migrate

Coinkite has already released emergency firmware updates for its current-generation devices, including version 5.6.0 for the Mk4 and Mk5 models and version 1.5.0Q for the Q device.

However, the company emphasized that updated firmware alone will not remediate wallets that were already created under the vulnerable seed generation process. Users are responsible for creating a new seed after performing the firmware update and transferring all funds to the newly generated wallet.