Crimes and Fraud News

Coldcard Hardware Bitcoin Wallet Bug Puts Years of BTC Seeds at Risk

Denis O.
31 July 2026 2 min read

Coldcard users are being urged to move their Bitcoin to newly generated wallets over a security flaw linked to the theft of $38 million.

Hardware Bitcoin wallet Coldcard, built by the Canadian crypto firm Coinkite, is urging users to withdraw their funds due to a vulnerability that has been found in its random number generator leading to the theft of around $38 million worth of BTC$62,630.00.

A hacker whose identity is still unknown managed to steal around 594 BTC from nearly 500 single-signature wallets in as little as 25 minutes on Friday, according to an analysis by Block, the fintech firm founded by Jack Dorsey.

About 562 BTC was then consolidated into one address and has yet to move.

Block’s security researchers said affected Coldcard devices may have generated wallet seeds using “predictable periodic down-counter,” including the device’s serial number and internal clock, instead of sufficient hardware-generated randomness. Block added:

“This does not mean every remote attacker can immediately recover every seed. Practical cost depends on available UID information, boot timing, prior RNG calls and derivation cost. No end-to-end brute-force benchmark is claimed here.”

Coinkite stated in a blog post that it still has an ongoing investigation into the matter but “out of an abundance of caution” it added that there could be risks if the seed was created using the Coldcard Mk3 with the firmware of version 4.0.1 and above. The problematic firmware goes back to March 2021, the firm added.

Read also: Crypto Project Hacks Totaled $1.32B in H1 of 2026

Updating the Device Is Not Enough

And the problem appears to extend beyond the Mk3. According to Coinkite, seeds generated on Mk4 and Mk5 devices before version 5.6.0 and on Q devices before version 1.5.0Q had about 72 bits of entropy rather than the expected 128 bits. The company described the issue on those models as less severe but “still serious.”

TAPSIGNER, OPENDIME and SATSCARD, three other Coinkite wallet products, aren’t affected because they use different codebases, per the blog post.

The risk depends on which firmware was installed when the seed was first created. So updating an affected wallet now won’t repair its existing seed, the wallet developer noted.

Coinkite advises to generate a new seed on a newer device and verify the new address as well as test transaction to transfer any remaining BTC.

Read more: Ledger Is the ‘Worst’ Hardware Crypto Wallet, ZachXBT Says

Denis O.

Crypto news reporter at Bitcoin Foundation covering topics including crypto markets, DeFi exploits, and regulatory developments. He was previously a reporter at The Defiant, crypto.news, currency.com, iHodl, BeInCrypto, and other…