{"id":70087,"date":"2026-08-08T21:41:40","date_gmt":"2026-08-08T18:41:40","guid":{"rendered":"https:\/\/lwallet.com.ua\/?p=70087"},"modified":"2026-08-15T18:43:54","modified_gmt":"2026-08-15T15:43:54","slug":"how-coldcard-was-hacked","status":"publish","type":"post","link":"https:\/\/lwallet.com.ua\/en\/how-coldcard-was-hacked\/","title":{"rendered":"How Coldcard Was Hacked \u2014 and Why a Firmware Update Won\u2019t Fix Your Seed"},"content":{"rendered":"\r\n\r\n\r\n<p class=\"wp-block-paragraph\">On July 30, 2026, a series of thefts began from Bitcoin wallets whose seeds had been created on vulnerable versions of Coldcard firmware. During the first major incident, <strong>1,082.65 BTC was drained from 1,196 addresses in just 41 minutes<\/strong>. The attackers did not need physical access to a Coldcard, phishing, or a transaction signed by the owner.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The cause was a firmware integration bug: when creating a wallet, the code called a software pseudorandom generator from MicroPython instead of the STM32 hardware random number generator it was supposed to use. As a result, seeds created by the built-in generator on affected firmware versions could contain far less entropy than a properly generated seed should.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Below, we explain what happened to Coldcard, which firmware versions were affected, why simply updating the device does not fix an already generated seed, and how to move funds safely to a new wallet.<\/p>\r\n\r\n\r\n<p>[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;] <strong>Does this affect you?<\/strong> If your seed was generated directly on a Coldcard and you cannot reliably determine the firmware version or how that seed was created, the official <a href=\"https:\/\/coldcard.com\/security\/migrate\" rel=\"nofollow noopener\" target=\"_blank\">COLDCARD Migration Guide<\/a> recommends migrating to a new seed. A seed that was securely generated on another device or by another trusted method and only later imported into Coldcard is not weakened by this bug. But if the seed was originally generated on an affected Coldcard, it remains affected even after recovery, import, or cloning. We explain the separate exception for 50+ independent private dice rolls below. [\/vc_message]<\/p>\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">How Coldcard was compromised: what happened on July 30<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" class=\"wp-image-70056\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic2-1024x573.jpg\" alt=\"Block 960183 in Blockstream Explorer during the first major attack on Coldcard wallets\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic2-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic2-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic2-768x430.jpg 768w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic2-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic2-350x196.jpg 350w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic2-680x381.jpg 680w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic2.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">The first major incident: 1,082.65 BTC in 41 minutes<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/x.com\/glxyresearch\/status\/2083181683067506899\" rel=\"nofollow\">Galaxy Research<\/a> traced a group of similar transactions made on July 30 between 01:10:20 and 01:51:26 UTC. During that period, funds were moved out of 1,196 Bitcoin addresses, for a total of <strong>1,082.65 BTC \u2014 roughly $70.2 million at the time<\/strong>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The transactions shared several distinctive traits, including the same unusually high fee of 30 sat\/vB and a similar structure. Those patterns helped researchers separate related transfers from normal network activity and estimate the scale of the attack.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Physical access to a Coldcard is not required for this type of attack. Candidate seeds can be tested offline, Bitcoin addresses can be derived from them, and those addresses can then be checked against addresses already visible on the blockchain.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">The attacks continued<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">More clusters of thefts appeared after the first incident. On July 31, Galaxy identified another 76.16 BTC taken from 1,478 addresses. The next major incident, which ran from July 31 into August 1, added roughly 208 BTC from 1,912 addresses.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">In its updates, Galaxy refers to the largest groups of related transactions as \u201cwaves,\u201d while tracking smaller clusters and other attack traces separately. In other words, this was not simply four individual transfers, but a series of thefts linked to the same vulnerability.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">According to <a href=\"https:\/\/x.com\/glxyresearch\/article\/2088329484332122241\" rel=\"nofollow\">Galaxy Research\u2019s August 14 update<\/a>, thefts totaling <strong>1,778.84 BTC from more than 8,600 addresses \u2014 about $112.7 million<\/strong> had been confirmed with high confidence. Including medium-confidence incidents and a fourth large transaction cluster that had not yet been fully confirmed, the estimate could rise to <strong>2,417.35 BTC \u2014 around $153 million<\/strong>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Galaxy had not identified any new confirmed attacks after August 6, but that <strong>does not mean affected seeds became safe<\/strong>. Researchers explicitly warned that thefts could resume and advised owners of single-sig wallets whose seed was generated on an affected Coldcard to <a href=\"https:\/\/x.com\/glxyresearch\/status\/2083560984422064516\" rel=\"nofollow\">move funds to a fresh seed as soon as possible<\/a>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Researchers also concluded that the vulnerability was likely being exploited by more than one attacker. The final loss figure may still change as additional victims continue to report affected addresses.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">If your funds have already been stolen<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">As of August 14, of at least 1,778 stolen BTC, around <strong>1,531 BTC remained unmoved at addresses controlled by the attackers<\/strong>, while roughly 246 BTC had already been moved. Galaxy Research said it was in direct contact with 190 victims.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">If you have already lost funds, do not throw away your Coldcard or destroy old backups. <a href=\"https:\/\/blog.coinkite.com\/update-sunday\/\" rel=\"nofollow noopener\" target=\"_blank\">Coinkite specifically asks users to keep affected devices<\/a>, because they may be useful in a future investigation or potential recovery process. Keep the affected addresses, transaction IDs (TXIDs), and any other wallet information that does not expose private keys.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">What Coinkite did<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/x.com\/nvk\/status\/2083216713693151552\" rel=\"nofollow\">Rodolfo Novak (NVK) publicly took responsibility for the firmware bug and apologized to affected users<\/a>. Coinkite published an <a href=\"https:\/\/blog.coinkite.com\/coldcard-mk3-seed-generation-warning\/\" rel=\"nofollow noopener\" target=\"_blank\">official security advisory<\/a>, then released fixed firmware for every affected model and a separate <a href=\"https:\/\/coldcard.com\/security\/migrate\" rel=\"nofollow noopener\" target=\"_blank\">step-by-step migration guide<\/a>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">After confirming the issue, the company <a href=\"https:\/\/blog.coinkite.com\/update-sunday\/\" rel=\"nofollow noopener\" target=\"_blank\">stopped shipments and destroyed remaining Coldcard inventory manufactured with vulnerable firmware<\/a>, while its team began working directly with customers who needed help migrating. TAPSIGNER, OPENDIME, and SATSCARD were not affected by this specific bug because they use a different codebase.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The incident is not fully closed, however. On the current <a href=\"https:\/\/coldcard.com\/security\/status\" rel=\"nofollow noopener\" target=\"_blank\">COLDCARD Security Status<\/a> page, Coinkite states that a <strong>formal technical postmortem is still being prepared<\/strong>. The generation fix is already available, but the full explanation of how the bug passed earlier reviews and what processes the company will change has not yet been published.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">What went wrong with Coldcard seed generation<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" class=\"wp-image-70059\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic3-1024x573.jpg\" alt=\"Coldcard RNG bug diagram showing the STM32 hardware TRNG and software Yasmarang generator\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic3-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic3-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic3-768x430.jpg 768w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic3-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic3-350x196.jpg 350w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic3-680x381.jpg 680w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic3.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">How a seed should be generated<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Every new Bitcoin wallet starts with a random number that should be practically impossible to predict. In BIP-39, a 12-word recovery phrase is based on 128 bits of initial entropy, while a 24-word phrase is based on 256 bits. The words shown to the user are simply a convenient way to record that secret.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">That is why the length of a recovery phrase is only part of the story. What also matters is <strong>how unpredictable the underlying data was when the phrase was created<\/strong>. If the generator can produce far fewer possible outputs, an attacker no longer has to search the full theoretical BIP-39 space.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">What went wrong<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">In March 2021, Coldcard changed part of the code responsible for obtaining random data during wallet creation. As Coinkite explains in its own <a href=\"https:\/\/blog.coinkite.com\/entropy-technical-backgrounder\/\" rel=\"nofollow noopener\" target=\"_blank\">technical backgrounder on the incident<\/a>, an integration bug caused the call that was supposed to use the STM32 hardware generator to bind instead to MicroPython\u2019s Yasmarang software generator.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The hardware random number generator did not \u201cfail\u201d while the device was running. The bug happened at firmware build time: the RNG call was linked to the wrong function implementation, while the build still completed without an error.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Block\u2019s technical report traces the vulnerable path back to code introduced in v4.0.0 in March 2021. Coinkite\u2019s current user guidance, however, defines the affected Mk2\/Mk3 range as <strong>4.0.1\u20134.1.9<\/strong>. That current matrix is the one users should follow when checking their wallet and planning a migration.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Why this made seeds guessable<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Yasmarang is a deterministic software generator: if its initial state can be reproduced, it will produce the same sequence of values. In Coldcard, that state depended on the microcontroller identifier and timing-related device values. Those inputs can make a search harder, but they are not a proper cryptographic source of randomness.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">On Mk2 and Mk3, no separate cryptographic source of randomness was added to those values. On Mk4, Mk5, and Q, data from secure elements was added during startup, but because of the way reseeding was implemented, only 32 bits of that value affected the software generator\u2019s state. That dramatically reduced the number of possibilities an attacker had to test.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Coinkite estimates an effective search space of roughly 40 bits for Mk2\/Mk3 and around 72 bits for Mk4, Mk5, and Q. That is far below what properly generated BIP-39 entropy should provide. Block separately cautions that practical attack difficulty depends on how much an attacker knows about a specific device and when the seed was generated. So these figures should not be read as a fixed number of attempts required for every wallet.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Once an attacker has a candidate seed, no interaction with the Coldcard is required. Bitcoin addresses can be derived from that seed and compared against public blockchain data. If the addresses match, the attacker has the correct key material and can sign a transaction independently.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Why a firmware update does not fix an existing seed<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>Fixed firmware changes how Coldcard generates a seed after the update. It cannot change a seed that was already created on vulnerable firmware.<\/strong> If that seed still controls funds, you need to create an entirely new wallet with a new seed and move the Bitcoin to the new wallet.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Restoring the same recovery words on a Trezor, BitBox, another Coldcard, or a software wallet does not solve the problem. You are restoring the same secret and the same set of keys that may already be easier to recover through brute force.<\/p>\r\n\r\n\r\n<p>[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;] If your seed was generated on affected Coldcard firmware, do not reuse the same recovery words as the basis of a \u201cnew\u201d wallet. First create a fresh seed on fixed firmware or on another trusted device, verify the receiving address, and only then move your funds. [\/vc_message]<\/p>\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Who is affected by the Coldcard vulnerability<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" class=\"wp-image-70062\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic4-1024x573.jpg\" alt=\"Coldcard Mk3, Mk4, and Q hardware wallets affected by the RNG vulnerability\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic4-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic4-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic4-768x430.jpg 768w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic4-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic4-350x196.jpg 350w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic4-680x381.jpg 680w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic4.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The key factor is not just the model you own, but <strong>the firmware version that was running when the specific seed was generated<\/strong>. Updating a Coldcard today is not enough if the wallet itself was created earlier on vulnerable firmware.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-table\">\r\n<table class=\"has-fixed-layout\">\r\n<thead>\r\n<tr>\r\n<th><strong>Model<\/strong><\/th>\r\n<th><strong>Firmware when the seed was generated<\/strong><\/th>\r\n<th><strong>Status<\/strong><\/th>\r\n<\/tr>\r\n<\/thead>\r\n<tbody>\r\n<tr>\r\n<td>Mk1<\/td>\r\n<td>all released versions through v3.0.6<\/td>\r\n<td>not affected by this regression<\/td>\r\n<\/tr>\r\n<tr>\r\n<td>Mk2, Mk3<\/td>\r\n<td>through v3.2.2<\/td>\r\n<td>not affected by this regression<\/td>\r\n<\/tr>\r\n<tr>\r\n<td>Mk2, Mk3<\/td>\r\n<td>v4.0.1 \u2014 v4.1.9<\/td>\r\n<td>affected versions<\/td>\r\n<\/tr>\r\n<tr>\r\n<td>Mk4, Mk5<\/td>\r\n<td>before v5.6.0 on Standard or before v6.6.0X on Edge<\/td>\r\n<td>affected versions<\/td>\r\n<\/tr>\r\n<tr>\r\n<td>Q<\/td>\r\n<td>before v1.5.0Q on Standard or before v6.6.0QX on Edge<\/td>\r\n<td>affected versions<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<\/figure>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Which firmware versions are fixed<\/h3>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li><strong>Mk2 and Mk3:<\/strong> 4.2.0 or later.<\/li>\r\n\r\n\r\n\r\n<li><strong>Mk4 and Mk5, Standard:<\/strong> 5.6.0 or later.<\/li>\r\n\r\n\r\n\r\n<li><strong>Q, Standard:<\/strong> 1.5.0Q or later.<\/li>\r\n\r\n\r\n\r\n<li><strong>Mk4 and Mk5, Edge:<\/strong> 6.6.0X or later.<\/li>\r\n\r\n\r\n\r\n<li><strong>Q, Edge:<\/strong> 6.6.0QX or later.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Before generating a new seed, check the latest status on <a href=\"https:\/\/coldcard.com\/security\/status\" rel=\"nofollow noopener\" target=\"_blank\">COLDCARD Security Status<\/a> and download firmware only from the <a href=\"https:\/\/coldcard.com\/downloads\" rel=\"nofollow noopener\" target=\"_blank\">official Coldcard firmware page<\/a>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>Standard and Edge are separate release branches.<\/strong> A 6.x version number may look newer than 5.6.0, but an older Edge release is not fixed just because its number is higher. Edge users need 6.6.0X or later on Mk4\/Mk5, and 6.6.0QX or later on Q.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">If you added dice rolls when generating the seed<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The bug affected randomness generated by the device itself. Independent dice rolls entered through Add Dice Rolls provided a separate source of entropy. According to Coinkite\u2019s current assessment:<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li><strong>50\u201398 honest, independent, private rolls:<\/strong> at least 128 bits of additional entropy;<\/li>\r\n\r\n\r\n\r\n<li><strong>99 or more:<\/strong> roughly 256 bits;<\/li>\r\n\r\n\r\n\r\n<li><strong>fewer than 50, or you do not remember the exact number:<\/strong> do not rely on the dice-roll exception and migrate to a new seed.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Coinkite does not consider a seed vulnerable to this specific RNG issue if at least 50 honest, independent, private dice rolls were added when it was created and the roll sequence was never recorded or exposed. If you are not sure those conditions were met, the safer option is to create a new seed.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">The problem affected more than wallet seeds<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/engineering.block.xyz\/blog\/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware\" rel=\"nofollow noopener\" target=\"_blank\">Block also found<\/a> that the same flawed random-data path was used for more than seed generation. It also fed private keys for paper wallets, random Seed XOR masks, and a number of internal Coldcard keys and passwords. The level of risk differs between those features, but the underlying issue extended beyond the standard New Wallet flow.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">What about multisig?<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Multisig protects against this issue only if an attacker cannot recover enough keys to satisfy the signing threshold. In a 2-of-3 setup, for example, compromising one key is not enough. But if two or three seeds were independently generated on vulnerable Coldcards without additional entropy, an attacker could potentially recover enough keys to reach quorum.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">That is why protection against a single vendor failure depends not simply on the number of devices, but on how independently the keys were generated and on the implementations used to create them.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">What Coldcard owners should do now<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" class=\"wp-image-70065\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic5-1024x573.jpg\" alt=\"Coldcard Q, a metal seed backup plate, and dice used for additional entropy\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic5-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic5-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic5-768x430.jpg 768w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic5-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic5-350x196.jpg 350w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic5-680x381.jpg 680w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic5.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">If your seed was created on affected firmware and the independent-dice-roll exception does not apply, the main goal is to <strong>move your funds to a completely new seed<\/strong>. Follow the process carefully so you do not lose access during the migration itself.<\/p>\r\n\r\n\r\n\r\n<ol class=\"nm-block-list wp-block-list\">\r\n<li><strong>Find out which firmware version was used when the seed was generated.<\/strong> If you cannot determine this reliably, take the cautious approach and treat the seed as potentially affected.<\/li>\r\n\r\n\r\n\r\n<li><strong>Verify your old backup and access to the wallet.<\/strong> Before resetting anything, make sure the recovery words are recorded correctly and that the wallet fingerprint (XFP) matches.<\/li>\r\n\r\n\r\n\r\n<li><strong>Install fixed firmware before generating a new seed.<\/strong> Confirm the version on the device itself and use only the official firmware file.<\/li>\r\n\r\n\r\n\r\n<li><strong>Create an entirely new seed.<\/strong> You can do this on a Coldcard with fixed firmware or on another trusted hardware wallet. Do not restore the old recovery words and treat that as a \u201cnew\u201d wallet.<\/li>\r\n\r\n\r\n\r\n<li><strong>Record and verify the new backup.<\/strong> Check the XFP and receiving address directly on the hardware wallet screen.<\/li>\r\n\r\n\r\n\r\n<li><strong>Send a small test amount first.<\/strong> Make sure it arrives in the new wallet before moving the rest.<\/li>\r\n\r\n\r\n\r\n<li><strong>Do not destroy the old backup until migration is complete.<\/strong> Keep it until the entire balance has reached the new wallet and the transactions have confirmed.<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Coinkite has published a separate official guide covering different migration scenarios: <a href=\"https:\/\/coldcard.com\/security\/migrate\" rel=\"nofollow noopener\" target=\"_blank\">COLDCARD Migration Guide<\/a>. If you use passphrase wallets, BIP-85 child wallets, multisig, or multiple accounts derived from the same affected seed, review the Special Cases section \u2014 every wallet that actually controls funds needs to be migrated.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">If your Mk2 or Mk3 is your only device<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">You do not need to buy another Coldcard just to migrate. Coinkite confirms that Mk2 and Mk3 running firmware 4.2.0 or later can correctly generate a new seed.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">If you do not have a second device, migration is still possible, but you will need to switch between the old and new wallets several times. Coinkite recommends the following order:<\/p>\r\n\r\n\r\n\r\n<ol class=\"nm-block-list wp-block-list\">\r\n<li>Verify the backup of the affected seed and record its XFP.<\/li>\r\n\r\n\r\n\r\n<li>Install and confirm fixed firmware version 4.2.0 or later.<\/li>\r\n\r\n\r\n\r\n<li>Once you are certain the old wallet can be restored, remove the seed from the device using Coldcard\u2019s built-in function and create an entirely new seed.<\/li>\r\n\r\n\r\n\r\n<li>Record and verify the new seed backup, its XFP, and the receiving address.<\/li>\r\n\r\n\r\n\r\n<li>Restore the old seed, verify its XFP, and send a small test amount to the verified new address.<\/li>\r\n\r\n\r\n\r\n<li>Restore the new seed, verify its XFP, and confirm that the test amount arrived.<\/li>\r\n\r\n\r\n\r\n<li>Restore the old seed again, verify its XFP, and move the remaining balance.<\/li>\r\n\r\n\r\n\r\n<li>Restore the new wallet and verify the full balance. Keep the old backup until every check is complete.<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">If the XFP or address does not match what you expect at any stage, <strong>do not send funds and do not destroy any backup<\/strong>. If you have a second device with fixed firmware, the official guide recommends using it so you do not have to keep restoring two seeds on the same Coldcard.<\/p>\r\n\r\n\r\n<p>[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;] News about wallet vulnerabilities is almost always used for phishing. Do not follow links in emails or private messages telling you to \u201curgently update Coldcard.\u201d Download firmware only from the official website. Recovery words should never be entered on a website or shared with support \u2014 they are only needed to restore a wallet in a trusted environment. [\/vc_message]<\/p>\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Passphrase: when it helps and when it does not<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" class=\"wp-image-70068\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic6-1024x573.jpg\" alt=\"BIP-39 passphrase as an additional layer of protection for a Coldcard wallet\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic6-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic6-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic6-768x430.jpg 768w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic6-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic6-350x196.jpg 350w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic6-680x381.jpg 680w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic6.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>A BIP-39 passphrase is not the device PIN.<\/strong> It is used together with the recovery phrase and defines a separate wallet. The same words with a different passphrase produce a different set of keys and different addresses.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A strong, unique passphrase that has never been exposed creates an additional independent barrier. Coinkite explicitly says that it reduces the immediate risk, but does not fix an affected seed. A short, common, predictable, or reused passphrase can still be guessed alongside a candidate seed.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>A passphrase does not fix an affected seed.<\/strong> Even if it is strong enough to provide meaningful protection, Coinkite still recommends moving to a new seed once you can do so safely. The passphrase itself must also be stored separately and accurately: losing it means losing access to that wallet.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">How to reduce the risk of similar failures in the future<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" class=\"wp-image-70071\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic7-1024x573.jpg\" alt=\"Hardware wallets from different manufacturers used in a multisig setup\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic7-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic7-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic7-768x430.jpg 768w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic7-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic7-350x196.jpg 350w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic7-680x381.jpg 680w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-coldcard-compromised-08-08-2026-content-pic7.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Additional independent entropy<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">With fixed Coldcard firmware, dice rolls are not required to eliminate this specific vulnerability: normal seed generation has already been corrected. But private dice rolls can still be added as an independent extra layer of protection. If you use this method, do not photograph or digitally record the roll sequence, and follow <a href=\"https:\/\/coldcard.com\/security\/migrate#dice-exception\" rel=\"nofollow noopener\" target=\"_blank\">Coinkite\u2019s official conditions<\/a>.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Multisig with independently generated keys<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>The value of multisig is not simply having more keys, but having independent failure paths.<\/strong> The practical lesson from this incident is straightforward: if you use multisig to protect against a problem affecting one vendor, the keys need to be generated independently and the recovery process needs to be tested in advance. Otherwise, the added complexity can become a risk of its own.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">How other manufacturers generate seeds<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">After the Coldcard incident, it is worth looking beyond whether a device simply has a \u201chardware RNG.\u201d A better question is whether the system uses independent sources of randomness and what happens if one of them fails.<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li><strong><a href=\"https:\/\/github.com\/trezor\/trezor-firmware\/blob\/main\/docs\/common\/message-workflows.md\" rel=\"nofollow noopener\" target=\"_blank\">Trezor<\/a>:<\/strong> when creating a new wallet, combines entropy generated inside the device with external entropy supplied by the host. This reduces dependence on a single generator.<\/li>\r\n\r\n\r\n\r\n<li><strong><a href=\"https:\/\/support.ledger.com\/article\/4415198323089-zd\" rel=\"nofollow noopener\" target=\"_blank\">Ledger<\/a>:<\/strong> for a 24-word Secret Recovery Phrase, generates 256 random bits using a TRNG inside the Secure Element.<\/li>\r\n\r\n\r\n\r\n<li><strong><a href=\"https:\/\/bitbox.swiss\/bitbox02\/security-features\/\" rel=\"nofollow noopener\" target=\"_blank\">BitBox02 and BitBox02 Nova<\/a>:<\/strong> combine five entropy sources, including generators in the Secure Chip and microcontroller, a unique value created during manufacturing, host-provided entropy, and a cryptographic value tied to the device password.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Multiple sources do not guarantee security by themselves \u2014 what matters is how they are combined and implemented in code. But independent sources can prevent a single failure from automatically weakening the entire seed-generation process.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">If this incident makes you switch to a hardware wallet from another manufacturer, the core rule remains the same: <strong>do not restore the old Coldcard recovery phrase on the new device as a way to \u201cescape\u201d the vulnerability<\/strong>. The new hardware wallet needs to generate a new seed, after which the funds should be transferred to new addresses with a normal Bitcoin transaction.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>Check the current firmware version before creating a new wallet, not just the condition of the device when you buy it.<\/strong> A new device should also be verified and updated if necessary before you generate the seed that will actually hold funds.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Open-source code does not mean bug-free code<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The vulnerable Coldcard code had been public for years, but simply having an open repository does not guarantee that every security-critical line has already been thoroughly reviewed. Open-source code makes independent audits and reproducible builds possible, but it is not a certificate that a project is free of bugs.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">On the current <a href=\"https:\/\/coldcard.com\/security\/status\" rel=\"nofollow noopener\" target=\"_blank\">COLDCARD Security Status<\/a> page, Coinkite has collected results from targeted independent checks of the fix, including testing on a real Mk4, source-code review, and reproducible builds for some releases. The same page makes clear that these checks validate specific parts of the fix and are not a full independent audit of the entire firmware.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Did AI help the attackers?<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">It is not known exactly which tool was used to discover the vulnerability. However, <a href=\"https:\/\/x.com\/glxyresearch\/article\/2088329484332122241\" rel=\"nofollow\">Galaxy Research considers it highly likely that the attackers used AI models without restrictions on cyber tasks<\/a> and cites Kimi K3 as an example of that class of model. Coinkite has also suggested that older versions of its public code may have been analyzed with AI.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">That does not mean any specific model definitely found this particular bug. In its <a href=\"https:\/\/blog.coinkite.com\/entropy-technical-backgrounder\/\" rel=\"nofollow noopener\" target=\"_blank\">technical backgrounder<\/a>, Coinkite says that just weeks before the incident, it had used one of the strongest available AI models to review the code \u2014 and that model did not find the issue. The right conclusion is therefore not \u201cAI hacked Coldcard.\u201d Rather, this incident shows that AI has become another tool for large-scale code analysis, without guaranteeing that a critical vulnerability will actually be found.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Does the Coldcard incident mean hardware wallets do not work?<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">No. Bitcoin itself was not broken, and signature verification was not bypassed. The network accepted correctly signed transactions. The failure happened earlier, when the secret used to sign those transactions was created.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A hardware wallet can isolate private keys from a phone or computer, but that isolation does not help if the key was created with insufficient randomness in the first place. That is why the Coldcard attackers did not need access to the device itself: they were trying to reconstruct the keys independently.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">This incident shows that seed generation is just as much a part of the security model as protecting the keys after they are created. Firmware, entropy sources, backups, and the recovery process all work together as one system.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Conclusion<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>If your seed was generated on affected Coldcard firmware and you did not add at least 50 honest, independent, private dice rolls under Coinkite\u2019s stated conditions, create a new seed and move your funds.<\/strong> If you cannot determine how the seed was generated, the official guide recommends migrating. Fixed firmware is required before generating the replacement wallet, but it cannot change an existing seed.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Do not restore the old recovery words on another device hoping to \u201cregenerate\u201d the keys \u2014 you will simply recreate the same wallet. Verify the new backup and receiving address on the hardware wallet screen, send a test transaction, and only then move the main balance.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">If you still need the basics of recovery phrase storage, start with our guide \u201c<a href=\"https:\/\/lwallet.com.ua\/en\/how-to-store-a-seed-phrase\/\">Top 5 ways to store a seed phrase safely<\/a>\u201d in the same blog.<\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>On July 30, 2026, a series of thefts began from Bitcoin wallets whose seeds had been created on vulnerable versions of Coldcard firmware. During the first major incident, 1,082.65 BTC was drained from 1,196 addresses in just 41 minutes. The attackers did not need physical access to a Coldcard, phishing, or a transaction signed by &hellip;<\/p>\n","protected":false},"author":10,"featured_media":70093,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2725],"tags":[],"class_list":["post-70087","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/70087","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/comments?post=70087"}],"version-history":[{"count":6,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/70087\/revisions"}],"predecessor-version":[{"id":70626,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/70087\/revisions\/70626"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media\/70093"}],"wp:attachment":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media?parent=70087"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/categories?post=70087"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/tags?post=70087"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}