Coldcard Seed Flaw Drains 1,367 BTC as Firmware Update Fails to Fix Old Wallets

Daily Feed
Coldcard Seed Flaw Drains 1,367 BTC as Firmware Update Fails to Fix Old Wallets

A flaw in certain Coldcard firmware versions has reportedly exposed a brutal weakness in one of Bitcoin self-custody’s most trusted tools: weak seed generation. Coindesk reported that more than 1, 367 BTC, worth nearly $89 million, has been drained from 4, 585 addresses tied to vulnerable Coldcard wallets.

  • Seed entropy failure
  • 1, 367 BTC drained
  • 4, 585 addresses hit
  • Updating firmware does not fix old seeds

That’s the kind of failure that punches straight through the whole “offline storage” comfort blanket. A hardware wallet can keep keys off the internet, but if the seed phrase itself was generated badly, the attacker doesn’t need to hack the device. They just need to reconstruct the secret. That’s not a Bitcoin problem. That’s a bad-randomness problem, and bad randomness is security’s dumbest possible failure mode.

Coldcard, built by Canadian firm Coinkite, has long marketed itself as an “ultra-secure” Bitcoin hardware wallet. Its website also leans on reviews describing it as “one of the most secure Bitcoin hardware wallets ever built.” Those claims sound great right up until a flaw in seed generation turns the vault into a very expensive guessing game.

Coinkite’s advisory says the issue affects Mk2, Mk3, Mk4, Mk5 and Q models, with different affected firmware ranges depending on the device. For Mk2 and Mk3, the vulnerable releases are 4.0.1 through 4.1.9 inclusive. Coinkite says fixed versions are available, but there’s a catch: updating firmware does not repair a seed already generated under the flawed process.

That last part matters. A lot.

What went wrong

In plain English, the wallet did not generate enough strong randomness when creating some seed phrases. Seed phrases are the recovery phrases that control access to a wallet. If someone gets them, or can guess them, they can take the coins. The device can be the most rugged little titanium brick in the world. If the seed is weak, the whole setup is cooked.

Coindesk described the problem as a predictable software randomizer being used instead of the device’s stronger hardware random source. Coinkite’s advisory frames it as insufficient entropy in seed generation. Either way, the result is the same: some seeds were much easier to reconstruct than they should have been.

That is the nightmare scenario for hardware wallets. The whole point is to move trust away from exchanges, apps, and web-connected systems. But if the seed generation step is flawed, “air-gapped” starts sounding more like marketing than protection.

How big is the damage?

Coindesk reported that the thefts total 1, 367 bitcoin, or nearly $89 million, across 4, 585 addresses. The reporting says the losses came in multiple waves, and the latest movements were designed to be harder to trace on-chain.

That on-chain tracing part is important. Bitcoin transactions are public, which means investigators can often follow stolen funds as they move from one address to another. Criminals know this, so they spread funds across many wallets and transaction paths to slow down analysis. In other words: the blockchain is transparent, and thieves still try to fog the glass.

Galaxy Research is cited in the reporting as estimating that funds were moved to around 600 attacker wallets. The number of unique attackers is still unclear, and that distinction matters. One operator can control many wallets, and many wallets can also be used by many operators. On-chain footprints tell a lot. They don’t always tell the whole story.

The early waves of draining appear to have been fast and coordinated. Coindesk reported one opening wave moving 1, 083 bitcoin from 1, 196 addresses in 41 minutes, followed by additional losses in later waves. Bitcoin Magazine also reported roughly 1, 000 BTC moving on-chain in connection with the issue. The total is now higher, and still moving in the wrong direction for anyone sitting on an affected seed.

Which users are actually at risk?

Not every Coldcard user is automatically toast. Coinkite’s advisory gives some important nuance here.

For some affected devices, users who added at least 50 fair, independent, private dice rolls when creating the seed would have introduced enough entropy to materially improve security. Coinkite says that level of dice input contributes at least 128 bits of entropy. With 99 or more rolls, the entropy rises to about 256 bits.

That means the people who took the extra step of adding their own randomness were better protected. Self-custody has a DIY tax, and this is one of those moments where the annoying, careful thing is the right thing. Crypto loves to sell sovereignty as freedom. The fine print is that sovereignty also comes with responsibility, and sometimes that means rolling dice like you’re in a very serious casino.

Coinkite also says a strong, unique BIP-39 passphrase adds another layer of protection. A passphrase is not the seed phrase itself; it is an extra secret layered on top of the seed. That can help, but it does not magically repair a weak seed that was generated under flawed conditions. A weak seed plus a weak passphrase is not “double security.” It’s just two problems wearing a trench coat.

What users should understand right now

This is not a case of Bitcoin itself being broken. The protocol did not get hacked. The failure happened at the wallet level, in the process that created the secret used to control funds. That distinction matters because it separates a Bitcoin protocol issue from a product security failure.

It also keeps the blame where it belongs. Hardware wallets are useful, but they are not sacred objects. They are pieces of software and hardware that can fail, especially when entropy generation is mishandled. Trust them, yes. Worship them, no.

Coinkite says affected users should migrate to fresh wallets generated with the fixed firmware and proper entropy. For users who are unsure whether their seed was created under the vulnerable process, the safe move is to treat it as exposed until proven otherwise.

Why this is a bigger lesson than one brand’s mess

This kind of failure should make everyone in crypto a little less lazy about security assumptions. A device can be branded “ultra-secure, ” praised by reviewers, and still fall apart at the one moment that matters most: generating a secret correctly.

That does not mean hardware wallets are useless. Far from it. They remain one of the best tools for Bitcoin self-custody. But they are only as strong as the implementation behind them. If the seed generation is weak, the wallet is not a vault. It is a very polished liability.

The broader takeaway is simple: security is math, implementation, and discipline. Branding is just paint.

Key takeaways and questions

  • What failed in Coldcard wallets?

    Some affected firmware versions generated seed phrases with insufficient randomness, making those seeds easier to reconstruct than they should have been.

  • How much bitcoin has been stolen?

    Coindesk reported losses of 1, 367 BTC, worth nearly $89 million, across 4, 585 addresses.

  • Does a firmware update fix an old seed?

    No. Firmware updates can prevent future bad seed generation, but they do not repair a seed that was already created under the flawed process.

  • Are all Coldcard users affected?

    No. The risk depends on the model, firmware version, and whether the seed was strengthened with enough independent dice-roll entropy or protected with a strong unique passphrase.

  • What should affected users do?

    Move funds to a fresh wallet created with fixed firmware and proper entropy. If there is any doubt about how the seed was generated, treat it as vulnerable and act fast.

Bitcoin’s self-custody model works best when users respect the boring parts: verifying firmware, understanding seed generation, and not assuming any device is magically safe by default. The hard truth here is that “offline” only helps if the secret was created properly in the first place.

Security is only as strong as the randomness behind it. When that cracks, the whole setup leaks.

Further reading

For the security nerds and anyone keeping coins on self-custody, these references add useful context.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog