Coldcard Seed Flaw Exposes $116M Self-Custody Risk in Bitcoin Wallets

Daily Feed
Coldcard Seed Flaw Exposes $116M Self-Custody Risk in Bitcoin Wallets

A Coldcard seed-generation flaw has exposed one of the nastiest risks in self-custody: if the randomness is weak, the wallet can look secure while quietly setting users up for a very expensive loss.

  • TRM Labs estimated about 1, 816 BTC, roughly $116 million, was taken.
  • More than 5, 200 addresses were affected, according to TRM.
  • The problem was a firmware and entropy failure, not a Bitcoin protocol break.
  • Coinkite says affected users must generate a new seed and migrate funds.

Coinkite’s Coldcard wallets are built for Bitcoin self-custody, but a seed-generation bug undercut that promise for some users. The issue hit seed creation on specific firmware versions and device models, and TRM Labs says it was bad enough to allow thefts without anyone needing to open, steal, or tamper with the hardware.

That’s the ugly part. A hardware wallet is supposed to keep private keys offline and out of reach. But if the seed is generated with weak randomness, the security model starts to fall apart at the starting line. In Bitcoin, whoever controls the private keys controls the coins. If the seed can be guessed, the “cold” in cold storage does not buy much.

According to Coinkite, the affected range includes Mk2 and Mk3 devices running firmware versions 4.0.1 through 4.1.9. The company also said vulnerable Mk4, Mk5, and Q devices generated about 72 bits of entropy instead of the expected 128 bits. TRM Labs went further on the older devices, saying some seeds may have had as little as 40 bits of effective entropy.

Entropy is the randomness used to create a wallet seed. More entropy makes the seed much harder to guess. Less entropy means attackers have a much smaller search space, which is exactly the kind of mathematical gift nobody wants to hand out.

TRM Labs said the flaw came from a build configuration error introduced with firmware version 4.0.1, with the vulnerable behavior tied to a broader issue that began in March 2021. Coinkite disclosed the problem on July 30, and TRM said the thefts appeared in four suspected waves starting that same day.

TRM’s preliminary estimate puts the losses at about 1, 816 BTC, worth roughly $116 million. The firm also said the losses came from more than 5, 200 addresses. Those numbers are significant, but they are still preliminary, so the final tally could change as investigators verify more victims.

The critical point is that this was not a Bitcoin failure. The base layer was not hacked. The problem was upstream, in wallet seed generation. That distinction matters, because crypto critics love to blur the line between “Bitcoin broke” and “a wallet vendor shipped bad code.” Those are not the same thing, no matter how convenient the confusion may be.

What affected users need to do

Coinkite says a firmware update alone does not fix an already-created weak seed. The old seed remains the problem. Users need to install the correct firmware, generate a completely new seed, verify the fingerprint and receiving address, and send a small test transaction before moving the rest of their balance.

That’s the part nobody likes, because it means a full wallet migration instead of the usual “update and move on” routine. But security does not care what is convenient. If the seed was generated on vulnerable firmware, it needs to be treated as compromised until proven otherwise.

Coinkite released fixed firmware for the affected devices:

  • 4.2.0 for Mk2 and Mk3
  • 5.6.0 for standard Mk4 and Mk5
  • 1.5.0Q for standard Coldcard Q

There is one important exception. Coinkite said users who entered at least 50 fair, private, and independent dice rolls while creating their seed are not considered at risk from the random-number-generator flaw alone. Between 50 and 98 rolls added at least 128 bits of entropy, and 99 or more added about 256 bits.

That means manual randomness really can matter. Dice rolls are a way for the user to inject extra randomness into the seed process instead of relying only on the device’s internal RNG. In plain English: if the wallet maker’s randomness is shaky, your own randomness can help save the day.

The catch is that the dice rolls had to be fair, private, and independent. If users can’t remember how many rolls they entered, whether the process was private, or which final seed words they kept, Coinkite advised them to migrate their funds. That’s not a casual suggestion. It’s the safest move when there’s no clean way to prove the seed was protected.

How the theft appears to have worked

TRM Labs said the attack could be carried out without opening the wallet, stealing it, or modifying it. The flaw weakened the seed itself, which is the part of the security chain that actually matters. Once the seed is predictable enough, the attacker does not need the physical device. The math does the dirty work.

TRM also said there has been limited laundering activity so far. The firm noted a 64.9 BTC deposit to Wasabi on Aug. 4 and 200 ETH sent through Tornado Cash. That is not exactly a masterclass in clean exits. It looks more like a slow, messy attempt to move funds around while keeping attention on the ground.

TRM said the transaction patterns may suggest multiple attackers, so attribution remains open. For now, the bigger takeaway is simple: weak entropy can turn a security product into a liability, and in crypto that liability gets measured in real money, not vibes.

Why this hit such a nerve

This incident has reignited the custody debate, which is always lurking just under the surface in Bitcoin. Self-custody is the ideal for many users because it removes third-party control. No exchange can freeze your funds. No custodian can “pause withdrawals.” No middleman gets to decide when your money is yours.

But self-custody also means you carry the burden of every security step. If the device ships with broken entropy, the user may never know until it is too late. That is the harsh truth: sovereignty is powerful, but it only works when the tools are sound and the operator is paying attention.

Bobby Gray, founder of TEXITcoin, argued that the flaw shows how dangerous blind trust in wallet makers can be. He said:

“Some of these wallets were generating seeds with as little as 40 bits of entropy instead of the 128 they promised.”

That is the core of the problem. A wallet vendor can promise strong security, but if the randomness underneath is broken, the promise is worthless. Cryptography is not marketing copy. It is math, and math does not care how polished the product page looks.

Gray also pushed back on the idea that users should abandon self-custody because one device failed. His point is that running to an exchange simply replaces one risk with another. That is fair. Exchanges can be convenient, but they are custodians, and custodians bring counterparty risk, withdrawal risk, internal control risk, and all the usual human nonsense that comes with handing over control.

A custodian is a third party that holds assets for you. In exchange for convenience, you accept that someone else controls access. That may be a sensible trade for some users, but it is not self-custody, and it should not be sold as if it were.

What about Bitcoin ETFs?

Bloomberg Intelligence analyst Eric Balchunas said the losses strengthen the case for regulated spot Bitcoin ETFs. That is his view, and it makes sense from a certain angle: ETFs remove the need for users to manage private keys themselves.

BlackRock’s iShares Bitcoin Trust ETF (IBIT) uses Coinbase Custody as its main custodian and may also use Anchorage Digital Bank. IBIT shareholders get price exposure to Bitcoin, but they cannot withdraw the underlying BTC to a personal wallet or use it for payments.

That is the trade-off in one sentence. ETFs make Bitcoin easier to hold for some investors, especially those who do not want to deal with wallets, backups, and recovery phrases. But that convenience comes with a cost: you do not control the coins.

IBIT’s filing also lists risks including hacking, employee misconduct, technical failures, and unauthorized transfers. That is standard risk language, not proof of a specific incident. Still, it is a useful reminder that regulated wrappers are not risk-free. They just shift where the risk lives. Failed to extract title

For some users, that shift is worth it. For others, it defeats the point of owning Bitcoin in the first place. The right answer depends on whether convenience or sovereignty matters more to you. There is no magic product that gives you both without compromise.

What this means for hardware wallets

This is not a reason to throw hardware wallets in the bin. Properly built and properly used, they remain one of the best ways to hold Bitcoin without trusting a third party. But the incident is a brutal reminder that hardware wallets are not magical talismans. They depend on firmware, entropy, and user behavior.

That should push the industry to treat seed generation with the same seriousness as signing logic. Open source helps. Audits help. Air-gapping helps. None of it matters much if the seed source is weak. Randomness is not a footnote. It is the foundation.

Multi-signature setups can reduce the damage from a single bad device or weak seed. In a multisig wallet, multiple keys are required to move funds, so one compromised wallet does not automatically blow up the whole stack. That adds complexity, sure, but security often does. Convenience and safety are not always on the same team.

Coinkite also said TAPSIGNER, OPENDIME, and SATSCARD are not affected because they use different codebases. That matters, because this is not a blanket indictment of every Coldcard product, and it is definitely not evidence that Bitcoin itself is broken.

Technical Deep Dive into the Entropy Issue

Coldcard flaw exposed $116M self-custody risk: Gray

The Largest Hardware Wallet Exploit of 2026: Inside the USD

Wallet Drain Megathread (Check Your Balances)

Coldcard Hardware Wallet Flaw Linked to $70 Million

Coldcard Firmware Flaw Sparks Bitcoin Wallet Exodus as

Bitcoin ETFs Log Strongest Inflow Week Since April as

Key questions and takeaways

  • What should affected users do now?
    Install the correct firmware, generate a completely new seed, verify the fingerprint and receiving address, and move funds with a small test transaction first. A firmware update alone does not repair an old vulnerable seed.
  • Was Bitcoin hacked?
    No. The problem was in Coldcard seed generation, not in the Bitcoin protocol. Weak entropy in wallet firmware created the opening.
  • How serious was the loss?
    TRM Labs estimated about 1, 816 BTC, worth roughly $116 million, from more than 5, 200 addresses. That figure is still preliminary.
  • Who was protected from the flaw?
    Coinkite says users who entered at least 50 fair, private, independent dice rolls while creating their seed are not considered at risk from the RNG flaw alone.
  • Are exchanges safer than self-custody?
    They can be safer for people who cannot manage keys well, but they introduce custodial and counterparty risk. You trade one set of problems for another.
  • Do Bitcoin ETFs solve custody risk?
    They reduce key-management burdens, but they also remove direct control over Bitcoin. ETFs are exposure products, not self-custody.

The real lesson here is uncomfortable but simple: self-custody is powerful, but it is only as good as the tools and the process behind it. Blind trust in a wallet maker, a firmware build, or a shiny security brand is not a strategy. Verification is.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog