Newsroom

Coldcard Firmware Flaw Enables $88 Million Bitcoin Drain, Sparking Custody Debate

2 August, 2026   /   News   /  AI   /   Tags:  seed, firmware, coinkite, coldcard, custody

Coldcard Firmware Flaw Enables $88 Million Bitcoin Drain, Sparking Custody Debate

A long-undetected seed generation bug in Coldcard hardware wallets allowed remote theft of over 1,367 BTC without physical access, prompting industry leaders to question self-custody security

A firmware vulnerability in Coldcard hardware wallets, present since a March 2021 code change, has enabled attackers to drain more than 1,367 Bitcoin worth approximately $88.6 million from thousands of addresses. Galaxy Research linked the activity to weak seed generation on affected devices manufactured by Coinkite, with the initial wave removing 1,082.65 BTC valued at about $70.2 million from 1,196 addresses in just 41 minutes on July 30.

Subsequent sweeps on July 31 and August 1 brought the observed total to 1,367.05 BTC across 4,585 addresses. The firm described the figure as preliminary and subject to further increases as additional on-chain activity is traced. The first two waves shared a common transaction fingerprint of 30 sat/vB fees with no change outputs, while the third used a different pattern, leaving open the possibility of either a change in tools or a second party exploiting the same issue.

How the Seed Generation Flaw Worked

The root cause was a configuration mismatch in Coldcard firmware. Code intended to activate the STM32 hardware random number generator instead checked only whether the setting existed, not whether it was enabled. As a result, devices fell back to MicroPython’s Yasmarang software pseudorandom number generator. This deterministic process started from fixed device data such as the unique identifier and timer state and did not collect fresh entropy after initialization.

According to analysis from Block, an attacker able to determine the device UID, timer values, and prior random calls could regenerate candidate seed streams on ordinary computers. Those candidates could then be tested against public blockchain addresses. Coinkite stated the effective entropy was roughly 40 bits on Mk3 devices and about 72 bits on Mk4, Mk5, and Q models—far below the 128 bits expected from a standard BIP-39 seed. No physical access, phishing, or malware was required.

Affected firmware included Mk2 and Mk3 versions 4.0.0 through 4.1.9 according to Block, with Coinkite listing Mk3 versions 4.0.1 through 4.1.9 as vulnerable and fixed in 4.2.0. Newer models were impacted before Mk4 and Mk5 version 5.6.0, Q version 1.5.0Q, and corresponding Edge builds. Coinkite released emergency firmware updates on July 31 for all affected models and release tracks. The patches do not repair seeds already generated; users must create new seeds on updated firmware and transfer funds. Restoring an old seed on a patched device leaves the weakness intact.

Seeds generated with at least 50 independent private dice rolls are not exposed by this bug alone. A strong BIP-39 passphrase creates a separate wallet but does not eliminate the need to replace the underlying seed, Coinkite advised. Multisignature setups help only when not every key is held on affected devices. Tapsigner, Opendime, and Satscard products use different codebases and remain unaffected.

Impact on Security-Conscious Users

The losses struck holders who followed recommended cold-storage practices. Jonathan Goodman reported losing roughly $1.6 million in Bitcoin kept on a Coldcard stored in a safety deposit box that had never connected to the internet. In a widely shared post he stated he had done everything right according to established guidance.

I did everything right.
Jonathan Goodman

The incident has intensified discussion about the practical limits of self-custody. Because the flaw sat inside the device’s own seed generation for years, some users questioned whether any hardware wallet can be presumed secure simply because no similar issue has yet been disclosed.

Industry Response and Custody Debate

Ari Paul, founder of BlockTower Capital, argued the episode demonstrated that every custody method ultimately depends on hardware and software that may contain undiscovered vulnerabilities. He said self-custody and third-party solutions each carry distinct risks, and that switching between them does not remove the possibility of loss. Paul noted legal systems in many developed countries still offer stronger protection for traditional financial assets, though cryptocurrencies may remain preferable where property rights are less reliable.

Erik Voorhees, founder of ShapeShift, countered that the Coldcard case does not prove cryptocurrencies cannot be stored securely. He maintained that every method of preserving wealth involves trade-offs and that self-custody remains effective when users understand the risks and apply consistent security practices. Investors have held hundreds of billions of dollars in cryptocurrencies for years under such conditions, he said.

Joe Burnett, vice president of Bitcoin strategy at Strive, described the past week as possibly one of the worst in Bitcoin’s history. He pointed to the single point of failure inherent in many self-custody setups and suggested large holders consider institutional custodians such as Fidelity and BitGo, which operate under different models than early exchanges. Strive itself holds approximately 20,000 BTC and ranks among the largest public company Bitcoin holders. Changpeng Zhao of Binance separately advised spreading holdings across multiple wallets, stating that nothing is 100 percent secure.

Galaxy Research reported no matching transaction patterns in the prior 30 days outside the identified sweeps, though it cautioned that the signature identifies an operator rather than confirming theft in every case. The episode follows a separate weak-pseudorandom-number-generator disclosure earlier in July involving older software wallets and more than $5 million in losses across several chains, underscoring that cryptographic strength elsewhere cannot compensate for insufficient entropy at the seed stage.

Coinkite has urged any user uncertain about how a seed was generated to migrate funds to a new seed created on patched firmware. No attacker has been publicly identified.

Associated cryptocurrencies
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.