Coldcard's $111M Nightmare: The 'Safest' Bitcoin Wallet Had a Fatal Seed Flaw
It was supposed to be the safest way to hold bitcoin: a small, air-gapped device that never touches the internet, storing the keys to your coins behind a PIN and a seed phrase written on steel. Coldcard, the bitcoin-only hardware wallet from Toronto’s Coinkite, built its reputation on exactly that promise — and for years, security-minded American bitcoiners trusted it with their savings.
That promise is now broken. On August 7, blockchain intelligence firm Galaxy Research confirmed that 1,719 BTC — roughly $111 million at current prices — has been stolen from Coldcard users, with total losses “likely to exceed $130 million.” The thieves never touched a single device. They never tricked a single user into revealing a seed phrase. They simply found a flaw in the random number generator inside Coldcard’s own firmware — and reconstructed the private keys from thin air.
A bug from 2021, exploited in July
The vulnerability traces back to a firmware update released in March 2021. On affected versions, Coldcard devices generated recovery seeds with insufficient randomness: newer models (Mk4, Mk5 and Q) produced roughly 72 bits of entropy instead of the expected 128 bits, while older Mk2 and Mk3 units on firmware 4.0.1 through 4.1.9 generated even weaker seeds.
The math is unforgiving. With 72 bits of entropy, a seed is no longer a needle in a haystack — it is a needle in a very searchable pile. Attackers precomputed the universe of weak seeds the flawed generator could produce, then matched them against funded bitcoin addresses until private keys fell out. No physical access required. No malware on the user’s computer. The “cold” wallet turned out to be cracked before it ever left the factory floor.
Coordinated theft waves began around July 30, the same day Coinkite quietly published its Coldcard Security Advisory warning users to “move your funds now.” Galaxy Research now tracks more than 25 distinct attack patterns across three waves, and says the evidence points to multiple independent threat actors racing to sweep weak keys — not a single sophisticated group.
The human cost: people who “did everything right”
What makes this exploit uniquely painful is who it hit. These were not exchange accounts with lax passwords or users who clicked phishing links. Galaxy Research describes the confirmed victims as everyday bitcoin savers rather than large whales — the crowd that bought a hardware wallet precisely because they did not trust exchanges or hot wallets.
The researcher operating as @intangiblecoins has now received reports from more than 250 victims, with a backlog still to process. One victim, Jonathan Goodman, told TechCrunch he lost $1.6 million from a Coldcard wallet:
“I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes. None of it mattered.”
His post-mortem is a gut punch for the entire self-custody movement: the hardware that created his seed phrase had one vulnerable line of code, baked in five years ago.
Are you affected? Check this list
The confirmed scope, per Galaxy Research and Coinkite:
- Affected models: Coldcard Mk3, Mk4, Mk5 and Q running firmware released after March 17, 2021.
- Not affected: TAPSIGNER, OPENDIME and SATSCARD (different codebases), and devices that never received the flawed firmware.
- No evidence the bug affects other hardware wallets or signing devices — but the industry is watching closely.
Two important exceptions, per Coinkite: if you generated your seed with at least 50 independent, private dice rolls, the added entropy (128+ bits) makes your seed safe from this flaw alone. And a strong, unique BIP-39 passphrase adds a separate barrier an attacker must also break — but Coinkite still recommends migrating.
What to do now
This part matters, so read it twice: updating the firmware does not repair an existing seed. The fix only protects new seeds generated after the update.
- Update your device first. Fixed releases are out for every model: Mk2/Mk3 on version 4.2.0 or later, Mk4/Mk5 standard on 5.6.0+, Q standard on 1.5.0Q+, and separate Edge-track releases (6.6.0X / 6.6.0QX). Edge users must install the Edge fix — a higher Edge version number is not automatically safe.
- Do not generate a new seed before updating.
- Generate a brand-new seed on the fixed firmware and migrate your funds to the new wallet, moving bitcoin in small test transactions first.
- If you are unsure whether your seed was generated on affected firmware — or you can’t prove 50+ private dice rolls — assume you are at risk and migrate.
Coinkite says its investigation is ongoing and a formal technical review is coming. The company has also suspended its automatic customer-data deletion policy, citing expected litigation.
A body blow to the “not your keys” creed
TRM Labs calls this the largest hardware wallet exploit of 2026 — and it lands in an already brutal year: the firm counts more than 200 hacks against crypto companies in 2026, with over $950 million lost in total. The Coldcard incident is different, though. It attacks the very foundation of self-custody: the assumption that a device holding your keys offline is a fortress.
The practical takeaways for US bitcoiners are uncomfortable but clear. Hardware wallets remain dramatically safer than hot wallets for most people — but no single vendor should hold your entire stack. Diversify across manufacturers, add dice-based entropy and passphrases, consider multisig for meaningful amounts, and treat firmware upgrades as security events, not chores.
It is also a reminder that the regulatory debate in Washington carries real stakes: the FBI recently reported more than $11 billion in crypto-related losses, and New York Attorney General Letitia James cited figures like these in pressing Congress to act on the CLARITY Act. Security incidents and legislation may seem like separate worlds — but the erosion of trust in self-custody is precisely the argument that keeps crypto regulation in the headlines.
Bitcoin itself took the news in stride: BTC traded near $64,000 on August 8, its highest level of the month, with prediction markets pricing a better than 97% chance it closes above $64,000 on Sunday. The market’s indifference, however, is small comfort to 250 families whose “unhackable” wallets are gone. This is not investment advice — it is a security wake-up call. Check your firmware version tonight.
Sources: Galaxy Research (X, Aug. 7), Coinkite Security Advisory (updated Aug. 8), TechCrunch (Aug. 4), CBC News (Aug. 4), The Crypto Times (Aug. 8).