What Is a Seed Phrase? The Fundamentals

If you are newer to this, everything below rests on understanding what a seed phrase actually is and how it works. Rather than repeat it all here, I wrote a full beginner to advanced guide on exactly that: What Is a Seed Phrase and Why It Matters.

If any of the terms below feel unfamiliar, start there and come back. The one line version: your seed phrase is the master key to your Bitcoin, usually 12 or 24 words.

Anyone who has it controls your funds. And those words are simply a human‑readable version of a very large random number. That randomness is where this whole story lives.

What Is Entropy in a Bitcoin Seed Phrase?

Those 12 or 24 words are not chosen from thin air. They encode a huge random number called entropy, and it is the real foundation of your wallet's security. As I explained in the seed phrase guide, a 12 word phrase carries 128 bits of entropy, roughly 340 undecillion possible combinations. Even testing a trillion guesses per second, you would not exhaust them before the universe ended.

Think of the seed phrase as a combination lock, and the words as a friendly way of writing down the combination. If the combination is genuinely random, guessing it is impossible. But if the machine that picked it was not truly random, the number of real possibilities collapses, and "impossible to guess" quietly becomes "possible to guess."

That is exactly what happened here. The words looked normal. The wallet worked normally. But the randomness behind them was weak, so the lock was far easier to pick than anyone realized. At 40 bits, it moved from "impossible" into "a well‑resourced attacker can do this at scale," which is precisely what someone did.

This is the uncomfortable truth of self‑custody: a seed phrase is only as strong as the randomness used to create it.

How to Generate a Secure Bitcoin Seed Phrase

You do not need to be an engineer to protect yourself. You need a few habits that put the randomness back in your own hands instead of trusting a device blindly.

  • Add Your Own Entropy With Dice Rolls: Most quality hardware wallets, including COLDCARD, let you generate a seed using dice rolls instead of relying solely on the device. You roll a physical die a set number of times, at least 50 independent rolls, ideally more, and those rolls become the randomness behind your seed.
  • No firmware bug can weaken this: A physical die rolling on your table is genuine real‑world randomness that no software can fake or reduce. Users who did this were considered far lower risk in the COLDCARD incident, even on affected devices. That is the clearest takeaway of the whole event: real randomness comes from the physical world, not from blind trust in a chip.
  • Add a BIP‑39 Passphrase (the "13th Word"): Most wallets let you add an optional BIP‑39 passphrase, sometimes called a 13th or 25th word. It is a secret only you know, combined with your seed to unlock your funds, and both are needed together. I covered this in the seed phrase guide, including the one serious warning worth repeating: if you forget the passphrase, your funds are lost, exactly as if you had lost the seed itself.

In this incident, a strong unique passphrase meant far lower risk even if the underlying seed was weak, because reproducing the seed alone was not enough to get in. It is a powerful second layer.

Use Multisig for Larger Bitcoin Holdings

For larger holdings, multisig removes any single point of failure. Instead of one seed controlling your funds, you require two or three separate keys, ideally created on different devices from different manufacturers. If one device has a hidden flaw like this one, your funds are still safe, because an attacker would need to break multiple independent keys, not just one.

Never Blindly Trust a Single Hardware Wallet

The hardest lesson. COLDCARD is a genuinely respected, security‑focused company, and this still happened, across multiple models. The takeaway is not "hardware wallets are bad", they remain far safer than leaving Bitcoin on an exchange. The takeaway is that trust should be layered. Add your own randomness. Add a passphrase. Spread risk with multisig. Every layer you add is one you do not have to trust a manufacturer to get perfectly right.

What to Do If Your COLDCARD May Be Affected

If you generated a seed on an affected COLDCARD (Mk2, Mk3, Mk4, Mk5, or Q) on pre‑fix firmware, without at least 50 dice rolls or a strong passphrase, treat your funds as at risk and act, but calmly. Panic is how people make a second mistake on top of the first. Mk3 owners are in the most urgent tier; Mk4, Mk5, and Q owners are still seriously affected and should act, but were not the primary target of the sweep.

The consensus guidance from Coinkite and Bitcoin Magazine:

  1. If you have another non‑COLDCARD hardware wallet, move your funds there now. It is the quickest way to safety.
  2. If COLDCARD is all you have, add a strong BIP‑39 passphrase of at least six words from the BIP‑39 list, chosen randomly, not by you, as an interim shield. Verify the fingerprint, restart, re‑enter, confirm it matches, then move funds to the passphrase‑protected wallet. This is temporary breathing room, not a permanent fix.
  3. Update to fixed firmware, then generate a new seed. Fixed versions are out for all models. Important: updating firmware does not repair an already‑weak seed. You must generate a fresh seed on the fixed firmware (or by another secure method) and migrate your funds to it.

A few clarifying facts worth knowing: seeds you imported from elsewhere, rather than generated on the affected COLDCARD firmware, are outside this bug. And Coinkite's Tapsigner, Opendime, and Satscard products use a different codebase and are not affected.

Always verify against the official Coinkite advisory for the latest fixed version numbers and steps. Verify every backup and every receiving address, send a small test transaction first, then move the rest. Do not take storage advice from strangers in your replies. Go to the source.

What the COLDCARD Incident Teaches Every Bitcoiner

It is easy to read a story like this and conclude that self‑custody is too dangerous. That would be the wrong lesson. Roughly $70 million was lost, and every bit of it was preventable with habits that have been recommended for years: your own entropy, a passphrase, multisig for size.

Self‑custody is not "buy a device and trust it." It is a skill, and like any skill involving real money, it rewards the people who take the time to understand what they are doing. This incident is painful, but it is also the clearest possible teacher. Your Bitcoin is only as safe as the randomness at the root of your keys, and that randomness is something you can, and should, take into your own hands.

If you want to build that foundation properly, start with the fundamentals in What Is a Seed Phrase and Why It Matters, then come back and layer on dice, a passphrase, and multisig. Do it right, and no single bug, company, or attacker can touch what is yours.

This article is educational and not financial or security advice. This is a fast‑developing situation and details continue to refine; always refer to the official manufacturer advisory for the latest fixed firmware versions and steps, and take your time. Many people are stressed right now; move carefully and verify every step.

Frequently Asked Questions

Which COLDCARD models are affected?

Coinkite's initial July 30 advisory named the Mk3, and initially said Mk4, Mk5, and Q were not affected. The updated July 31 advisory expanded the scope: Mk2 and Mk3 seeds had the most severe weakness (~40 bits), while Mk4, Mk5, and Q on pre‑fix firmware were also affected at a less severe but still serious level (~72 bits). Tapsigner, Opendime, and Satscard use a different codebase and are not affected.

Is my COLDCARD safe if I used dice rolls or a passphrase?

Largely, yes. Seeds generated with at least 50 independent dice rolls, or protected with a strong unique BIP‑39 passphrase, are considered far lower risk even on affected devices, because both add randomness or a secret layer the firmware flaw could not weaken. Seeds imported from a different device are also outside the bug.

How much Bitcoin was stolen in the COLDCARD hack?

The initial coordinated sweep drained roughly 594 BTC (about $38 million) from around 500 addresses. Analysts, including Block engineers and Galaxy Research, later mapped the connected activity to a total of around 1,082 BTC, roughly $70 million.

Does updating the firmware fix my weak seed?

No. Updating to the fixed firmware prevents the bug going forward, but it does not repair a seed that was already generated weakly. You must generate a new seed on the fixed firmware (or another secure method) and carefully migrate your funds to it.

What is entropy in a seed phrase?

Entropy is the randomness used to create your seed phrase. Higher entropy means more possible combinations and a seed that is effectively impossible to guess. A standard 12‑word seed has 128 bits of entropy; the worst‑affected COLDCARD seeds had as little as 40 bits, which made them feasible to brute‑force.

Further reading: