Understanding the Coldcard Firmware Vulnerability and Its Impact on Bitcoin Security

By Patricia Miller

3 min read

A vulnerability in Coldcard devices has led to the theft of 1,367 BTC. Learn how this affects self-custody users and what actions to take.

The primary function of an air-gapped hardware wallet is to keep your cryptocurrency keys offline, preventing unauthorized access from hackers and malware. Coldcard is renowned in the Bitcoin self-custody space for delivering this security promise. However, a firmware vulnerability has put that promise in jeopardy.

A flaw that has existed in Coldcard devices since March 2021 has been exploited, resulting in the theft of approximately 1,367 BTC, valued between $88.6 million and $89 million. This exploit did not require the device to be online; it leveraged a weakness in the randomness that produces recovery seeds. As a consequence, an attacker had the capability to generate predictable seeds that could be reproduced offline.

#How Did This Vulnerability Occur?

The vulnerability was present in Coldcard firmware versions 4.0.0 to 5.0.3. A critical firmware update applied in March 2021 unintentionally set the device to rely on a predictable software Random Number Generator for seed generation rather than the intended hardware-based True Random Number Generator. This change compromised the fundamental security that users rely on. Researchers at Block found that this predictable fallback allowed attackers to enumerate potential seeds, enabling them access to user funds without needing physical access to devices or network connectivity.

Research conducted by Galaxy Research shows that this exploit involved three distinct waves of attacks, indicating that a single advanced operator was responsible for these incidents. The attackers effectively brute-forced recovery phrases in an offline manner, eliminating the need to breach any networks or devices.

The first wave of attacks struck on July 30, 2026, within a short window of about 25 minutes, leading to the loss of approximately 594 BTC (around $38 million) from nearly 500 different addresses. By August 2, the cumulative losses grew to approximately 1,367 BTC spread across at least 4,585 wallets. A common vulnerability among compromised wallets was that their recovery seeds were generated without a BIP-39 passphrase. In contrast, wallets utilizing multisignature setups avoided being affected by this exploit.

#What Should Self-Custody Users Do Now?

Following this incident, Coinkite, the company behind Coldcard, has urged all users affected by the vulnerability to create new recovery seeds using updated firmware. Although updating firmware is essential, it does not rectify seeds generated during the period of vulnerability. Users must create a completely new seed on a patched device and move their assets to wallets derived from this new seed.

Reports suggest that numerous Bitcoin holders are shifting their funds back to exchanges in the wake of these events. Analysts speculate that this situation may accelerate the acceptance of institutional custody solutions, possibly including Bitcoin ETFs.

#Key Actions for Current Coldcard Users

For those using Coldcard devices, it is crucial to act quickly. If you generated a recovery seed with firmware versions 4.0.0 through 5.0.3, treat that seed as vulnerable. Generate a new recovery seed with updated firmware and a BIP-39 passphrase, and promptly transfer all your funds to a new wallet. Those using multisig do not appear to be at risk.

Keep an eye out for potential on-chain analysis that may identify the wallets of the attackers. The indication of a single operator across multiple waves suggests that law enforcement and blockchain forensics teams are already working to trace the perpetrators behind this exploit.

A sharper way to see the markets in just 5 minutes.

Same news, different lens. We cut through the noise and hand you the overlooked ideas and the deeper read the crowd misses. Join 38,000+ investors seeing the markets differently.

I agree to the privacy policy.

Important Notice And Disclaimer

This article does not provide any financial advice and is not a recommendation to deal in any securities or product. Investments may fall in value and an investor may lose some or all of their investment. Past performance is not an indicator of future performance.