SecurityAugust 5, 2026

A firmware fault made Coldcard seeds guessable: 1,367 bitcoin gone

A mistake dating from March 2021 left Coldcard wallets generating their seed with a software generator instead of the hardware chip. On 30 July, 1,196 addresses were emptied in 41 minutes. What to check if you own one of these devices.

Article image for: A firmware fault made Coldcard seeds guessable: 1,367 bitcoin gone

A hardware wallet is meant to be the safest place for your bitcoin. With Coldcard that turned out not to hold for five years, and the bill arrived on 30 July 2026.

What went wrong

During a firmware migration in March 2021, seed generation was routed through MicroPython's pseudo-random number generator rather than the device's own true hardware generator. The result: a seed that should carry 128 bits of entropy carried far less in practice. Roughly 40 bits on the Mk2 and Mk3, roughly 72 bits on the Mk4, Mk5 and Q.

Forty bits is not a theoretical concern. That is a search space an attacker can walk through with ordinary hardware. Anyone who created a seed on such a device effectively held a key that could be guessed.

41 minutes, 1,196 addresses

The first wave ran on 30 July between 01:10 and 01:51 UTC. In those 41 minutes, 1,082.65 bitcoin was taken from 1,196 addresses, worth roughly 70.2 million dollars at the time, or about 61.4 million euros. The latest count stands at 1,367.05 bitcoin across 4,585 addresses in three waves: around 88.6 million dollars, or roughly 77.5 million euros.

For comparison: all 24 DeFi protocols hit during July lost 132.2 million dollars between them, about 115.7 million euros. One fault in one wallet therefore weighed more heavily than an entire month of exploits.

Which models and which versions

Coinkite shipped emergency firmware on 31 July. Vulnerable are: Mk2 and Mk3 on versions 4.0.0 through 4.1.9, fixed in 4.2.0. Mk4 and Mk5 on anything before 5.6.0. The Q on anything before 1.5.0Q. For the Edge builds it concerns anything before 6.6.0X (Mk4 and Mk5) and 6.6.0QX (Q).

Tapsigner, Opendime and Satscard run on a different codebase and were not affected.

What to do now

Updating alone is not enough. New firmware repairs the generator, but not the seed you created in 2021 or later. That one stays weak.

If you had a seed generated on one of the listed devices, create a new seed on patched firmware and move your coins across. Do not restore the old seed on another device, because that simply carries the problem with you. Coinkite notes that a seed built from at least fifty fair, independent dice rolls is not crackable through this fault alone.

What this means for you

The practical point is not that Coldcard is bad. The point is that "hardware wallet" is no guarantee in itself: you are trusting one piece of code you cannot inspect while it runs. Anyone who adds their own entropy with dice, or verifies a seed through two independent methods, is not hanging on that single assumption.

And if you have an old device in a drawer and no longer remember which firmware was on it: that is exactly the case where moving the coins costs less than finding out.

Sources: The Hacker News (1 August 2026), Privacy Guides (2 August 2026), Coinmonks monthly review (4 August 2026), Coinkite firmware advisory. Converted to euros at a rate of 0.875. Last checked: 5 August 2026.

#security#wallet#bitcoin#hardware wallet#Coldcard