COLDCARD Disaster: Weak Entropy Bug Enables Drain of Funds from Seeds Generated Since 2021
A build error present in COLDCARD firmware for more than five years made seeds generated on affected devices predictable, enabling attackers with no access to the hardware to reconstruct private keys offline and sweep the matching addresses.
ONGOING EXPLOIT: If you generated a seed on a COLDCARD between 29 March 2021 and 31 July 2026, treat it as compromised and move your funds. Affected firmware: 4.0.1–4.1.9 (Mk2/Mk3), 5.0.0-mk4–5.5.1 (Mk4), up to 5.5.1 (Mk5), 0.0.3Q–1.4.1Q (Q). This applies even if the seed now lives on a different brand of device. Multisig is at risk wherever affected keys alone can meet a spending threshold.
- More than 1,816 BTC — nearly $116M — has been swept from 5,200+ addresses since 30 July. More sweeps are happening as you read this. You can track the progress here. Loss figures are rising daily and should be read as a floor.
- Coinkite has shipped fixed firmware for every affected model, halted shipments, and destroyed remaining affected stock. The fixes protect seeds you create from now on but don't repair seeds you've already generated.
More technical explainers of the bug have been published by WizardSardine, bitcoin++ Insider, and Block.
Who's affected
Whether you're affected or not depends solely on which firmware was running when your seed was generated — not when you bought the device, not when you last updated it.
- Funds controlled by a seed generated on Mk2 or Mk3 version 4.0.1 (in production since March 29, 2021) through 4.1.9 inclusive are at very high risk if:
- the seed was created WITHOUT at least 50 fair, independent, private dice rolls;
- the funded wallet is NOT PROTECTED by a strong, unique BIP-39 passphrase.
- Seeds generated on Mk4, Q, and Mk5 before the fixed firmware releases are also at risk, with about 72 bits of entropy rather than the expected 128 bits.

If you can't confirm which firmware or device you were on when your seed was created, assume affected.
- Unaffected: seeds created before March 29, 2021, or on older firmware (v3 and lower, plus Mk1 devices).
- Seeds imported from elsewhere, including generated on Mk1 / pre-v4 Mk2–Mk3.
- Also unaffected: TAPSIGNER, OPENDIME, and SATSCARD, which run separate codebases.
- According to the WizardSardine blog, the second-order effects of the bug also touch anything derived from a compromised seed: BIP-85 children — including Nostr keys, Lightning node seeds, SSH keys, and generated passwords — plus duress wallets tied to trick PINs, and microSD 2FA.
"Even if you did not generate your seed on an affected Coldcard, multiple advanced features of the Coldcard devices are broken. Dice rolls do not protect you here," states the blog post.
- A second category of broken regardless of how your seed was made, including dice-generated and imported seeds, because these features call the faulty generator directly:
- Paper wallets — the private key is the generator output. Every COLDCARD paper wallet made since 2021 has an enumerable key unless created with dice.
- Device clone files — the SD-card key exchange is recomputable, so anyone holding a clone file can decrypt it and recover the seed in the clear.
- Key Teleport — the transfer password is 40 bits by design and drawn from the broken generator.
- CCC co-signing "C key", HSM mode 2FA secrets, the Secure Notes & Passwords generator, and the optional Seed XOR random-split mode.

Quick migration options
Sending your funds out of vulnerable wallets is of utmost importance. The more time passes, the higher the likelihood that your funds are going to be taken over by someone else.
- Build the new destination for rescued funds on a non-COLDCARD hardware wallet. New seed, different manufacturer — don't reuse the old one if you can avoid it.
- No additional hardware signer at the moment? Consider these temporary options:
- MetroVault, dedicated Android software, turns an old Android device into an offline Bitcoin signing device.
- Roll dice on your COLDCARD to generate a new mnemonic, if you have nothing else.
- Send your coins to your exchange account if you use it regularly.
- Last resort option: a software wallet with hot keys. If possible, set it up as a multisig across a couple of phones, or a phone plus a computer. It's not secure, but it could still be enough to save your coins.
- No additional hardware signer at the moment? Consider these temporary options:
- Test the new wallet. Verify the backup and a receive address on the new wallet's screen; receive a small amount; self-send it within the new wallet. If you can, verify the destination before spending from the compromised wallet. Do not lose coins to panic!

- Broadcast by wallet type:
- Single-sig — normally, with a high fee so it confirms fast.
- Multisig — do not broadcast normally. It publishes your public keys in the mempool. Submit the raw signed transaction via MARA Slipstream.

- Keep the old COLDCARD until the balance confirms in the new wallet, then upgrade it to the latest firmware.
Why step 3 matters. Rob Hamilton of AnchorWatch warns that where compromised COLDCARDs alone meet a multisig threshold, an attacker can grab your broadcast transaction, fee-bump it with the compromised keys, and redirect the funds. Wizardsardine issued the same warning and expects the technique to become routine.
- Caution on updating: reports of the emergency firmware bricking devices are circulating, and Coinkite has not yet published guidance.

- Staying on Coldcard instead? Coinkite's advisory route remains a valid option, but note the bricking reports: update to the fixed release, generate a new seed on it (dice optional on fixed firmware), verify backup, fingerprint and a receive address, send a small test transaction, keep the old backup until confirmed.

IMPORTANT: Do not throw out your COLDCARD devices. In case of a successful retrieval of stolen funds, your hardware wallet may be needed to prove ownership.
Coinkite's response
Coinkite has released emergency hot fixes for all affected models:
- v4.2.0 for Mk2 and Mk3;
- v5.6.0 for Mk4 and Mk5;
- v1.5.0 for COLDCARD Q;
- Edge (experimental track): v6.6.0X for Mk4 and Mk5 and v6.60QX for Q devices.
Updating the firmware does not repair a faulty seed generated with affected firmware.

- In response to the ongoing emergency, Coinkite CEO NVK has issued a public apology letter and has already stepped down from the OpenSats board.
"As a team that has dedicated our lives to securing the Bitcoin held by millions of individuals, businesses, and families, this is our core responsibility, and we fell short. If you know anyone who owns a Coldcard, please make sure they see this. Some affected users may not be watching social media right now, and every hour matters," reads the letter.
- The company has published a report on dealing with the crisis, and has announced the destruction of all units with affected firmware.

"Why destroy affected inventory? COLDCARD has a series of high-security system locks. Once programmed, it cannot be re-upgraded until the user initializes it. We cannot ship units with affected firmware and risk users missing the upgrade. The safest action was to destroy all the affected inventory and ship only those with the new fixed firmware," was posted on X.
If you've lost your funds
- Document everything; report to police and cybercrime authorities; ignore anyone promising recovery; don't act rashly; talk to someone if you need support.
- Record before it's lost: theft transaction IDs, drained addresses, device model and firmware version, and roughly when and how the seed was created.

- Coinkite said it will provide a written incident summary specific to your loss plus available transaction data for police reports and insurance claims, and is cooperating with investigators.
- Galaxy has referred ~600 suspected attacker addresses to federal investigators and compliance firms.

- Expect scams. Recovery services cannot retrieve stolen coins. Coinkite will never ask for your PIN or seed words. Ignore unsolicited offers of help.
Privacy implications
- Any Coldcard seed created since 2021 should be treated as public, which makes its entire transaction history public — retroactively and permanently.
- Two second-order effects:
- Coinjoin/payjoin anonymity sets shrink for everyone, including people who never owned a Coldcard, because identifiable participants reduce the effective set. This applies retroactively to every mix since 2021 and cannot be undone.
- Chain-surveillance firms gain a large, permanently labellable address set, and your counterparties see part of their own transaction graph exposed by association.

Coinkite's Security Advistory / Archive
Coinkite's Technical Deepdive / Archive
Block's Report / Archive
Wizardsardine Guide / Archive
Bitcoin-Safe Guide / Archive
Rob Hamilton's Guide / Archive
btc++ deep dive / Archive
COLDCARD Hack Tracker