Updated July 31, 2026. This is a fast‑developing situation; always verify against the official Coinkite advisory for the latest.
Bitcoin is being drained from COLDCARD hardware wallets. If you generated your seed on a COLDCARD, read this now, because whether you are at risk comes down to a few specific details, and some owners need to act today.
Here is the situation, who is affected, and exactly what to do.
What Happened to COLDCARD Wallets?
COLDCARD, made by Canadian company Coinkite, disclosed a long‑standing firmware bug introduced around firmware 4.0.0/4.0.1 in March 2021. The bug caused seed generation to silently fall back to a weak, predictable software source instead of the device's proper hardware randomness. The result was seed phrases with far less entropy than the 128‑bit standard, meaning they can be guessed or brute‑forced.
On July 30, a coordinated on‑chain sweep drained roughly 594 BTC (about $38 million) from around 500 single‑signature addresses in a short window. Analysts, including Block engineers and Galaxy Research, later mapped the connected activity to a total of around 1,082 BTC, roughly $70 million. Many of the drained coins dated from 2021 onward and had been sitting dormant, matching the profile of weak‑seed reconstruction.
Which COLDCARD Models Are Affected?
This is the part that matters most, and the severity is not equal across models.
- Mk2 and Mk3: the most severe, roughly 40 bits of entropy in the worst cases. This is feasible to brute‑force at scale for single‑signature wallets without extra protection, and this is the tier the actual sweep primarily hit. Highest urgency.
- Mk4, Mk5, and Q (pre‑fix firmware): roughly 72 bits. Coinkite calls this "not as severe but still serious." A much larger search space than the Mk3 case, so these were not the main target of the sweep, but they still require action.
Coinkite's initial July 30 advisory covered only the Mk3 and said Mk4, Mk5, and Q were unaffected. That was overtaken within about a day. The updated advisory expanded the scope to include Mk4, Mk5, and Q on pre‑fix firmware, and Bitcoin Magazine's July 31 report urged immediate migration for anyone who generated a seed on these devices without sufficient dice‑roll entropy.
Who Is Actually Safe?
You are considered far lower risk if any of these apply:
- Your seed was generated with at least 50 independent dice rolls (ideally more).
- Your wallet is protected by a strong, unique BIP‑39 passphrase.
- Your seed was imported from a different device, not generated on the affected COLDCARD firmware.
Also unaffected: Coinkite's Tapsigner, Opendime, and Satscard, which use a different codebase entirely.
If you are unsure whether your seed had enough dice entropy, do not assume. Treat it as at risk.
What to Do Right Now
Act, but do not panic. Rushing is how people make a second mistake on top of the first.
- Move to another hardware wallet if you have one. If you own a non‑COLDCARD hardware wallet, send your funds there now. It is the fastest route to safety.
- No other device? Add a passphrase as interim cover. On your COLDCARD, add a strong BIP‑39 passphrase of at least six words from the BIP‑39 list, chosen randomly, not by you. Verify the fingerprint, restart the device, re‑enter the passphrase, confirm the fingerprint matches, then move your funds to that passphrase‑protected wallet. This buys you time; it is not the permanent fix.
- Update firmware, then generate a brand‑new seed. Fixed firmware is out for all models. Critical point: updating the firmware does not repair an already‑weak seed. You must generate a fresh seed on the fixed firmware and migrate your funds to it.
Whatever you do: verify every backup, verify every receiving address, send a small test transaction first, then move the rest. Do not follow storage advice from strangers replying to panicked posts. Go to the official source.
Verify Before You Act
Details are still refining. Confirm the latest fixed firmware versions and steps directly:
- Official Coinkite Mk3 Advisory
- Coinkite Entropy Technical Backgrounder
- Bitcoin Magazine: Immediate Action Required
Once your funds are safe, take a breath, then take stock. This incident has a lesson buried in it that protects you from the next one, whatever device it involves. It comes down to a single idea: your seed phrase is only as safe as the randomness behind it. I broke down what that means and how to get it right in Why Your Seed Phrase Is Only as Safe as Its Randomness.
And if you know anyone with a COLDCARD who might not be watching Bitcoin news today, tell them. Many affected people have no idea they are exposed.