Market Insider

Coldcard Security Flaw: How More Than 1,000 BTC Was Reportedly Stolen Without Touching the Devices

More than 1,000 bitcoin—worth about US$70 million at the time—was reportedly removed from 1,196 wallets during a 41-minute period on 30 July 2026. The suspected cause was not a breach of Bitcoin itself, but a serious random-number-generation flaw in certain COLDCARD firmware.

Illustration of a COLDCARD wallet security breach, showing the initially reported 594 BTC sweep
The 594 BTC shown was the initially reported sweep; later analysis put the suspected total above 1,000 BTC.

The incident has challenged a common assumption about cold storage: keeping a signing device offline can reduce exposure to online attacks, but it cannot protect a wallet if its recovery seed was predictable when it was created.

According to the manufacturer, Coinkite, affected firmware could generate seeds with substantially less randomness than intended. Security researchers say this may have allowed an attacker to reconstruct possible seeds offline, derive their Bitcoin addresses and compare them with addresses already visible on the public blockchain.

Key point: Bitcoin’s blockchain and core cryptography were not broken. The reported attack targeted weak key generation in specific COLDCARD firmware.

Were Bitcoin cold wallets really hacked?

Some COLDCARD-generated wallets appear to have been compromised, but describing the event as a hack of all Bitcoin cold wallets would be inaccurate.

A recovery seed—usually represented by 12 or 24 words—is the master secret from which a wallet’s private keys and addresses are derived. Properly generated seeds use enough cryptographic randomness to make guessing them impractical.

Block’s Bitcoin Engineering and Security team reported that a firmware integration error caused affected COLDCARD devices to use a deterministic software fallback rather than the intended hardware random-number generator. The fallback was initialised from predictable or constrainable information, including device identifiers and timer values.

For later models, secure-element entropy was added, but researchers found that only a limited portion reached the software generator’s state. Coinkite’s current advisory says pre-fix seeds from Mk4, Mk5 and Q devices are affected as well, although the impact is less severe than on Mk3.

This weakness could reduce the number of candidate seeds an attacker needed to test. The attacker would not need the physical device, malware or the victim’s written recovery phrase. A wallet could remain powered off and locked in a safe while candidate keys were tested elsewhere.

Read Block’s technical analysis

More than US$70 million reportedly swept away

Early reports identified a sweep of approximately 594 BTC from more than 500 addresses. That initial figure is the amount shown in the accompanying illustration.

Later analysis expanded the suspected incident to approximately 1,082.6 BTC taken from 1,196 wallets during a 41-minute window. At the time of reporting, the bitcoin was valued at about US$70 million.

The changing figures show why the total should be treated as an estimate while the investigation continues. Bitcoin Optech reported on 31 July that estimated losses exceeded 1,000 BTC and warned that the figure could rise as more evidence emerged.

Read CoinDesk’s updated investigation

Read Bitcoin Optech’s security summary

Which COLDCARD devices and firmware are affected?

Coinkite’s advisory, updated on 31 July 2026, identifies seeds generated on the following firmware as affected unless sufficient independent dice entropy was added:

  • Mk3: versions 4.0.1 through 4.1.9 inclusive
  • Mk4 and Mk5 standard: versions before 5.6.0
  • Q standard: versions before 1.5.0Q
  • Mk4 and Mk5 Edge: versions before 6.6.0X
  • Q Edge: versions before 6.6.0QX

Coinkite says TAPSIGNER, OPENDIME and SATSCARD are not affected because they use different codebases. Block’s analysis also identifies Mk2 devices running version 4 firmware as using the vulnerable path.

Exposure depends on the firmware used when the seed or secret was generated—not simply the device model or the firmware installed today.

Check Coinkite’s current security advisory and migration guidance

Why a firmware update is not enough

Updating to fixed firmware corrects future seed generation, but it does not repair a recovery seed that was already created with insufficient randomness.

If an attacker can reconstruct an existing seed, the wallet remains exposed after the device is updated. Potentially affected users need to install the correct fixed firmware before creating a replacement wallet, then carefully transfer funds to a newly generated seed.

Coinkite lists the fixed versions as Mk3 4.2.0 or later; Mk4 and Mk5 standard 5.6.0 or later; Q standard 1.5.0Q or later; Mk4 and Mk5 Edge 6.6.0X or later; and Q Edge 6.6.0QX or later.

Standard and Edge are separate release tracks. Users should verify the correct fixed release for their model and track on the official COLDCARD website.

Bitcoin itself was not hacked

The distinction matters. The Bitcoin network, blockchain and underlying signature system were not reported as broken.

The suspected failure occurred during key creation in a particular wallet implementation. A useful analogy is that the vault was not forced open; instead, the lock produced combinations that were easier to predict than intended.

Once a valid private key is reconstructed, transactions made with that key look valid to the Bitcoin network. The blockchain cannot determine whether the person signing a transaction is the legitimate owner or an attacker who recovered the same key.

What should potentially affected owners do?

Owners should rely on the latest manufacturer guidance for their exact model, firmware and release track. They should also be alert to secondary scams, because major security incidents often trigger fake support messages, malicious update sites and fraudulent recovery services.

Coinkite’s guidance includes the following precautions:

  • Read the official Coinkite advisory before taking action.
  • Install firmware only from the official COLDCARD website and verify the version on the device.
  • Do not generate a replacement seed until fixed firmware is installed.
  • Create and carefully back up a completely new seed.
  • Verify the new receiving address on the hardware-wallet screen.
  • Send a small test transaction and confirm it arrives.
  • Move the remaining balance only after the test succeeds.
  • Keep the old backup until the migration is complete and confirmed.
  • Never enter a recovery phrase into a website, email form or unsolicited application.

A strong, unique BIP-39 passphrase may add an independent barrier, but it is not the same as the device PIN. Coinkite still recommends migration for affected seeds. Users who relied on dice entropy should check the advisory’s specific exception rather than assuming they are protected.

People holding significant amounts may also wish to seek independent professional security assistance and consider a carefully designed multisignature setup using independently generated keys.

A warning for the self-custody industry

This incident does not prove that cold storage is fundamentally unsafe. Properly designed and correctly operated hardware wallets can still reduce many risks associated with internet-connected devices.

It does, however, expose an important limitation: keeping a key offline only helps if the key was securely generated in the first place.

Cold storage cannot compensate for defective randomness, compromised firmware, unsafe backups or poor operating procedures. Security depends on the entire lifecycle of the key—from generation and backup to signing and eventual migration.

For self-custody users, “not your keys, not your coins” is no longer the whole lesson. If keys were not generated securely, they may never have been yours alone.

Sources and status: This article reflects information available on 1 August 2026 from Coinkite, Block Bitcoin Engineering and Security, Bitcoin Optech and CoinDesk. The investigation is continuing, and reported losses or affected products may change. Readers should check the manufacturer’s current advisory before acting.

This article is provided for general information and education only. It does not constitute financial, investment or cybersecurity advice.

Share with your friends!

Leave a Reply

Your email address will not be published. Required fields are marked *