Update — August 2, 2026: Galaxy Research estimates that three separate attack waves have now drained approximately 1,367.05 BTC, worth about $88.6 million at the time of its analysis, from 4,585 Bitcoin addresses. This is an on-chain estimate and has not yet been confirmed by Coinkite as a final loss figure.

🚨 A 3rd wave in what we suspect are hacks of Coldcard-generated addresses has been identified in which 207.7294 BTC has been drained.
A 3rd wave in what we suspect are hacks of Coldcard-generated addresses has been identified in which 207.7294 BTC has been drained.

Coinkite Warns Users to Move Funds From Affected Wallets

Coinkite published an emergency security advisory on July 30 after receiving reports of funds being removed from wallets whose recovery seeds had been generated on vulnerable COLDCARD firmware.

The company initially focused on the COLDCARD Mk3, but an updated advisory published on August 1 expanded the list of affected products. Seeds may be vulnerable if they were generated using:

  • COLDCARD Mk2 or Mk3: firmware versions 4.0.1 through 4.1.9;
  • COLDCARD Mk4 or Mk5: standard firmware released before version 5.6.0 or Edge firmware before version 6.6.0X;
  • COLDCARD Q: standard firmware released before version 1.5.0Q or Edge firmware before version 6.6.0QX.

Coinkite has released corrected firmware for the affected models. However, installing an update does not repair a seed that was generated using vulnerable firmware. Users must create a new seed after installing the fixed version and then transfer their Bitcoin to addresses controlled by the new wallet.

TAPSIGNER, OPENDIME and SATSCARD are not affected because they use different software codebases.

Weak Randomness Could Allow Private Keys to Be Reconstructed

A recovery seed is typically represented by a sequence of words generated under the BIP-39 standard. COLDCARD normally creates 12- or 24-word seed phrases, which can be used to restore a wallet and regain access to its Bitcoin.

The security of such a wallet depends on the seed being generated from sufficiently unpredictable information, known as entropy. If the number-generation process is predictable, the real number of possible seeds can become much smaller than users expect.

An investigation by Block’s Bitcoin Engineering and Security teams found that affected COLDCARD firmware contained an integration error in its random-number generator. Instead of consistently using the device’s cryptographic hardware generator, part of the firmware could fall back to a deterministic software generator called Yasmarang.

On affected Mk2 and Mk3 firmware, the fallback process did not add cryptographically secure entropy. It relied on values such as the device identifier and internal timer state, which may be predictable or narrowed down by an attacker.

Newer Mk4, Q and Mk5 devices added entropy from their secure elements, but Block’s analysis found that only 32 bits of this information were used to reseed the software generator. Coinkite estimates that affected seeds on these models had around 72 bits of entropy rather than the expected 128 bits. This makes the issue less severe than on the older devices but still serious enough to require migration.

Three Attack Waves Drain More Than 1,367 BTC

The security warning followed reports of a coordinated movement of Bitcoin from wallets believed to have been created using vulnerable COLDCARD firmware.

An early analysis identified approximately 594.48 BTC moving through hundreds of transactions during a short sequence of Bitcoin blocks. Researchers initially suspected that weak seed entropy had allowed an attacker to narrow the range of possible private keys and test candidates against publicly visible wallet addresses.

Further analysis later identified additional affected wallets. By August 2, Galaxy Research estimated that three attack waves had drained 1,367.05 BTC from 4,585 addresses. The third wave targeted smaller balances and used more complex transaction patterns than the earlier activity.

Galaxy Research believes each individual wave was probably carried out by a single operator. However, public blockchain data does not establish whether the same attacker was responsible for all three waves.

Moving a Vulnerable Seed to Another Device Does Not Fix It

The vulnerability depends on how the original seed was generated, not on which hardware wallet currently stores it. Restoring an affected Mk3 seed on a newer COLDCARD, another hardware wallet or a software wallet does not make the seed secure.

An attacker who can reconstruct the original seed can access every wallet derived from it regardless of the device currently being used.

According to Coinkite, affected users should first install the corrected firmware, generate a completely new seed, record and verify the new backup, confirm a receive address on the hardware-wallet screen and send a small test transaction. The remaining funds should be transferred only after the new wallet has been verified.

Users should retain the old backup until the full transfer has been confirmed, but they should not continue receiving funds to addresses derived from the vulnerable seed.

Dice Rolls and BIP-39 Passphrases May Reduce Exposure

Coinkite says seeds created with at least 50 fair, independent and private dice rolls are not considered vulnerable to this random-number-generation issue alone. The dice rolls added an independent source of entropy that was combined with the device-generated data.

A strong and unique BIP-39 passphrase also creates an additional barrier because an attacker must recover both the weakened seed and the passphrase. However, short, reused or predictable passphrases may still be guessed.

Coinkite continues to recommend migration even for users protected by a strong passphrase. The passphrase can reduce immediate exposure, but it does not repair the underlying seed.

More than $38M has been stolen due to a Coldcard wallet vulnerability.
More than $38M has been stolen due to a Coldcard wallet vulnerability.

The Incident Renews Debate Over Hardware-Wallet Security

The incident shows that keeping private keys offline does not eliminate every security risk. Hardware wallets reduce exposure to malware and remote attacks, but their security still depends on firmware quality, random-number generation, backup procedures and the way users verify transactions.

FORECK.INFO has also examined modern hardware-wallet architecture, seed backups and secure-element design in its Trezor Safe 7 hardware wallet review.

Bitcoin price fluctuations over the past 24 hours, screenshot from CoinGecko at 3:00 PM on July 31, 2026.
Bitcoin price fluctuations over the past 24 hours, screenshot from CoinGecko at 3:00 PM on July 31, 2026.

Coinkite says its investigation remains ongoing and that a full technical report will be released later. Until then, anyone whose seed was generated using affected firmware should treat the wallet as potentially compromised and follow the official migration guidance.

For readers choosing a safer way to store digital assets, FORECK.INFO has prepared a detailed ranking of the best crypto wallets, comparing hardware and software options, supported assets, security features and ease of use.

Sources