A firmware bug made affected Coldcards generate seed phrases with a predictable software RNG instead of the chip's hardware RNG. Attackers have already reconstructed the private keys offline and drained roughly 1,719 BTC across three confirmed waves, without ever touching a device — and a suspected fourth wave is still being traced. Updating the firmware does not repair a seed that already exists. If your seed was generated on a Coldcard on or after March 2021, treat it as compromised: move the coins now to a new seed on patched firmware, to a different hardware wallet, or — if you need somewhere immediately — to an exchange you already use, and sort out longer-term custody after the coins are safe.
Watch for follow-on scams. Events like this draw fake “migration” and “wallet checker” sites. Coinkite will never ask for your seed words, and no legitimate tool needs them. Type coldcard.com in by hand rather than following links from social media or email.
The flaw cut seed randomness from the intended 128 bits to roughly 40 bits on Mk2/Mk3 and 72 bits on Mk4/Mk5/Q. Your seed is at risk if you generated it on the device while running:
4.0.1 through 4.1.95.6.0 (standard) or 6.6.0X (Edge)1.5.0Q (standard) or 6.6.0QX (Edge)Two exceptions. Coinkite states seeds are not at risk from this bug if you supplied at least 50 fair, independent rolls through Add Dice Rolls and those rolls were never recorded or exposed. Seeds generated before firmware 4.0.1 (March 2021) are also outside the affected range. If you are not certain which applies to you, assume you are affected and move the coins.
If a sweep is already under way. Galaxy Research reports that some fourth-wave transactions have replace-by-fee enabled. If you find an unconfirmed transaction spending from your address sitting in the mempool, you may have a short window to broadcast your own higher-fee transaction and move the coins before the attacker's confirms. Galaxy also counts at least 15 separate attackers working through the remaining vulnerable addresses, so assume the sweeping is still going on.
Migration. Update the firmware, generate a brand-new seed, verify the backup and a receive address, send a test transaction, then move the remaining funds. Keep the old backup until the migration is confirmed.
Enter your loan and collateral to see the exact Bitcoin price that would liquidate you — then save an alert so you're warned before it happens, not after.
Save your warning price and we'll set up your alert. Email warnings are launching now — add your email and you'll be among the first notified, and we'll email you when Bitcoin approaches your liquidation price.
We store your email and your warning price only, to send this alert and the weekly rate update. No spam; unsubscribe anytime. This tool is for planning and is not financial advice — confirm your lender's exact liquidation terms before relying on any figure.
Your collateral's value falls with Bitcoin's price while the loan stays fixed, so your loan-to-value (LTV) rises as the price drops. Liquidation triggers when LTV hits your lender's threshold — so the liquidation price is simply loan ÷ (BTC collateral × liquidation LTV). The warning price sits above it by the cushion you choose, to give you time to add collateral or pay down the loan before a forced sale. For the full picture of what a liquidation actually involves — fees, partial vs full, and the tax hit — read what happens when a Bitcoin loan gets liquidated.
The single best protection is a low starting LTV. Compare each lender's liquidation threshold and custody model in the comparison table, and see why holders borrow instead of selling in borrowing against Bitcoin without selling.