Wallets & Custody

The Coldcard exploit

A 2021 firmware bug made Coldcard seeds guessable. In 2026 thieves took 1,367 bitcoin.

In plain words

A Seed phrase is only as strong as the randomness behind it. In March 2021 a build mistake routed Coldcard's seed generation to a software fallback generator instead of the hardware one: the code checked whether a setting existed, not whether it was on. The seeds looked ordinary. They were guessable. Five years later someone noticed, and in July 2026 attackers emptied thousands of wallets. Coinkite shipped fixed firmware the next day.

Why it matters

  • Keys are only as good as the randomness that made them.
  • Open source is necessary, not sufficient: this sat in public code for five years.
  • New firmware cannot repair an old seed. Only a new seed, and moved coins, can.

Numbers that matter

  • ~40 bits — effective randomness on affected Mk2/Mk3, against 128 expected.
  • 1,367 BTC — taken across three waves, roughly $89 million.
  • 4.0.1–4.1.9 — affected Mk2/Mk3 firmware; also Mk4/Mk5 before 5.6.0, Q before 1.5.0Q.

Not to be confused with

  • A stolen device — nothing was touched. The seeds were computed from afar.
  • A Bitcoin flaw — the protocol did exactly its job. One vendor's build did not.

Go deeper

Updated 2026-08-05