Security alert · Coldcard hardware wallet
Move your Bitcoin off any Coldcard seed created since March 2021 — today.
A firmware bug made affected Coldcards generate seed phrases with a predictable software RNG instead of the chip's hardware RNG. Attackers have already reconstructed the private keys offline and drained roughly 1,719 BTC across three confirmed waves, without ever touching a device — and a suspected fourth wave is still being traced. Updating the firmware does not repair a seed that already exists. If your seed was generated on a Coldcard on or after March 2021, treat it as compromised: move the coins now to a new seed on patched firmware, to a different hardware wallet, or — if you need somewhere immediately — to an exchange you already use, and sort out longer-term custody after the coins are safe.
Watch for follow-on scams. Events like this draw fake “migration” and “wallet checker” sites. Coinkite will never ask for your seed words, and no legitimate tool needs them. Type coldcard.com in by hand rather than following links from social media or email.
Am I affected? Version list and migration steps
The flaw cut seed randomness from the intended 128 bits to roughly 40 bits on Mk2/Mk3 and 72 bits on Mk4/Mk5/Q. Your seed is at risk if you generated it on the device while running:
- Mk2 / Mk3 —
4.0.1 through 4.1.9
- Mk4 / Mk5 — anything before
5.6.0 (standard) or 6.6.0X (Edge)
- Q — anything before
1.5.0Q (standard) or 6.6.0QX (Edge)
Two exceptions. Coinkite states seeds are not at risk from this bug if you supplied at least 50 fair, independent rolls through Add Dice Rolls and those rolls were never recorded or exposed. Seeds generated before firmware 4.0.1 (March 2021) are also outside the affected range. If you are not certain which applies to you, assume you are affected and move the coins.
If a sweep is already under way. Galaxy Research reports that some fourth-wave transactions have replace-by-fee enabled. If you find an unconfirmed transaction spending from your address sitting in the mempool, you may have a short window to broadcast your own higher-fee transaction and move the coins before the attacker's confirms. Galaxy also counts at least 15 separate attackers working through the remaining vulnerable addresses, so assume the sweeping is still going on.
Migration. Update the firmware, generate a brand-new seed, verify the backup and a receive address, send a test transaction, then move the remaining funds. Keep the old backup until the migration is confirmed.
Independent tracing by Galaxy Research attributes roughly 1,719 BTC (about $111M) drained across three confirmed waves, as of Aug 7, 2026 — up from 1,596 BTC on Aug 4, when Galaxy last put the address count at about 7,300. Counting a suspected but still unconfirmed fourth wave, Galaxy puts the possible total near 2,055 BTC (~$130M) across more than 7,700 addresses. Figures were still rising at the time of writing. Bitcoin Lending Intel is not affiliated with Coinkite and this is not financial advice. Verify firmware versions and guidance against Coinkite's own advisory before acting.