Coldcard hardware Bitcoin wallet bug puts years of BTC seeds at risk as reported surprise attack sparks sudden crash fears
Jack DorseyCobraColdcardBlockCoinkite

Coldcard hardware Bitcoin wallet bug puts years of BTC seeds at risk as reported surprise attack sparks sudden crash fears

A security flaw in Coldcard hardware wallets has prompted urgent warnings for users to transfer their Bitcoin to new wallets, following the theft of approximately 594 BTC, valued at around $40 million. The vulnerability stems from predictable seed generation in older firmware versions, raising concerns about future attacks.

Bitcoin Foundation+2 sources31 July 2026 · 17:59 UTC
CuriousCats Full Story

Coldcard hardware wallets are facing scrutiny after a security flaw led to the theft of approximately 594 BTC (around $40 million) from nearly 500 wallets. The vulnerability, linked to predictable seed generation in older firmware versions, has raised alarms in the Bitcoin community.2

According to Block's security researchers, the issue affects Coldcard Mk3 devices with firmware versions 4.0.1 and above, as well as Mk4 and Mk5 devices before version 5.6.0. The flaw stems from a replacement of a hardware random number generator with a predictable software substitute, reducing entropy from the expected 128 bits to 72 bits.8

Coinkite, the manufacturer, has advised users to generate new seeds on unaffected devices and transfer their funds, stating, “Updating the firmware does not repair a seed that was generated by affected firmware.” The incident has sparked panic among Bitcoin holders, with fears that the price could drop below $58,000 as a result of the attack.

The attack, which occurred over a span of 25 minutes, has led to concerns about the potential for future exploits, especially with the rise of artificial intelligence tools that could facilitate such attacks. As one user noted, “I imagine there are dozens of hacking teams now researching how to exploit this.” The situation underscores the importance of understanding wallet security and the risks associated with seed generation.10

Coinkite has emphasized the need for users to verify firmware and follow security advisories carefully, as the safest path involves not just owning a hardware device but also understanding how the seed was generated and how backups are stored.

Key Insight
“An unknown hacker drained around 594 BTC from nearly 500 single-signature wallets in about 25 minutes, according to Block's researchers. Coinkite warned that seeds created with a BIP-39 passphrase or at least 50 dice rolls are not considered at risk, and urged users to generate a fresh seed on a newer device.”
CuriousCats studied:
1
Bitcoin Foundation
Coldcard users are being urged to move their Bitcoin to newly generated wallets over a security flaw linked to the theft of $38 million.
Bitcoin Foundation →
2
TradingViewTradingView
“A Coldcard security issue has put Bitcoin hardware-wallet safety back under the microscope after reports that a firmware flaw affected seed generation on some older device versions.”
TradingView →
3
ForbesForbes
“Bitcoin and crypto holders have been left reeling by an attack on cold hardware wallet Coldcard that's seen around $40 million worth of bitcoin stolen.”
Forbes →
Ask CuriousCats
What is the Coldcard wallet bug?
Who reported the Bitcoin theft incident?
Why did Coinkite issue a fresh seed warning?
How does this incident compare to past Bitcoin hacks?
Are hardware wallet vulnerabilities increasing significantly?
Get your CIA-level briefing,
in real time.
CuriousCats monitors the internet every minute for you and brings you the most personalized brief of videos, social media posts, news and more.
Download the App
If you liked this, you’ll love your CuriousCats brief.
News, videos, opinions and more — without the noise.
Get CuriousCats