- Coldcard users are being urged to move their Bitcoin to newly generated wallets over a security flaw linked to the theft of $38 million.
- A hacker whose identity is still unknown managed to steal around 594 BTC from nearly 500 single-signature wallets in as little as 25 minutes on July 30-31, 2026.
- Crash fears spread across the bitcoin market following reports of the attack, with the bitcoin price dropping but remaining above its key $60,000 support level.
- Coinkite and Block security researchers have publicly warned users to migrate funds to newly generated wallets due to the vulnerability.
- The vulnerable seed-generation firmware dates back to March 2021, affecting Coldcard Mk3 firmware versions 4.0.1 through 5.0.3, along with Mk4 and Mk5 devices before firmware 5.6.0.
- The core problem was a seed-generation weakness where a hardware random number generator was replaced by a predictable software substitute, reducing entropy from the intended 128 bits to 72 bits.
- The risk depends on which firmware was installed when the seed was first created, and updating an affected wallet now won’t repair its existing seed.
- The attack has fed fears that the widespread adoption of artificial intelligence tools will lead to an increase in attacks on bitcoin and crypto software.
- Security researchers have warned that if a seed generated in a vulnerable Coldcard is exported to another wallet, that same insecure seed remains affected.
Coldcard hardware wallets are facing scrutiny after a security flaw led to the theft of approximately 594 BTC (around $40 million) from nearly 500 wallets. The vulnerability, linked to predictable seed generation in older firmware versions, has raised alarms in the Bitcoin community.2
According to Block's security researchers, the issue affects Coldcard Mk3 devices with firmware versions 4.0.1 and above, as well as Mk4 and Mk5 devices before version 5.6.0. The flaw stems from a replacement of a hardware random number generator with a predictable software substitute, reducing entropy from the expected 128 bits to 72 bits.8

Coinkite, the manufacturer, has advised users to generate new seeds on unaffected devices and transfer their funds, stating, “Updating the firmware does not repair a seed that was generated by affected firmware.” The incident has sparked panic among Bitcoin holders, with fears that the price could drop below $58,000 as a result of the attack.

The attack, which occurred over a span of 25 minutes, has led to concerns about the potential for future exploits, especially with the rise of artificial intelligence tools that could facilitate such attacks. As one user noted, “I imagine there are dozens of hacking teams now researching how to exploit this.” The situation underscores the importance of understanding wallet security and the risks associated with seed generation.10
Coinkite has emphasized the need for users to verify firmware and follow security advisories carefully, as the safest path involves not just owning a hardware device but also understanding how the seed was generated and how backups are stored.
“An unknown hacker drained around 594 BTC from nearly 500 single-signature wallets in about 25 minutes, according to Block's researchers. Coinkite warned that seeds created with a BIP-39 passphrase or at least 50 dice rolls are not considered at risk, and urged users to generate a fresh seed on a newer device.”
