Roughly 594 BTC was drained from about 500 Coldcard-generated wallets in a coordinated sweep that began July 29, Coinkite confirmed, tracing the theft to a flaw in how some of its devices generated wallet seeds.
The incident has forced Bitcoin holders to reassess a basic assumption of cold storage: that keeping a device offline is enough to protect funds.
The vulnerability was traced to the way certain Coldcard devices generated wallet seeds. The weakness potentially allowed attackers to reconstruct vulnerable private keys from insufficiently random seed-generation processes.
A coordinated sweep exposes the vulnerability
The first major warning signs emerged after Bitcoin began moving unexpectedly from a large number of Coldcard-generated wallets on July 29. The transfers were not isolated incidents.
Blockchain observers identified a coordinated sweep involving hundreds of addresses, with approximately 594 BTC ultimately taken.
The scale of the operation distinguished it from conventional phishing campaigns or individual wallet compromises. The affected devices were not necessarily connected to the internet when the funds were stolen.
Instead, the attackers appear to have exploited weaknesses in the entropy used when vulnerable wallets were originally created.
A hardware wallet is designed to keep private keys away from internet-connected computers. Coldcard describes its products as Bitcoin-only devices designed for users who want full control of their funds, with private keys kept offline.
But the security of a wallet ultimately depends on the quality of the secret generated at its creation. If that secret can be predicted or reconstructed, keeping the hardware offline does not solve the underlying problem.
Coinkite, the company behind Coldcard, acknowledged the vulnerability in a security advisory published July 30 and subsequently updated it as investigators learned more about the affected devices.
“Funds controlled by seeds generated on affected firmware are at risk if the seed was created without at least 50 independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase.” Coinkite, in its Coldcard Security Advisory.
The Problem Was Inside Seed Generation
The core issue was not a conventional remote hack of Bitcoin itself. The Bitcoin network was not compromised, and the underlying cryptography securing properly generated private keys remains intact.
Instead, the vulnerability affected the randomness used to create some Coldcard seeds.
According to Coinkite’s updated advisory, Mk2 and Mk3 devices running firmware versions 4.0.1 through 4.1.9 were exposed when seeds were created without sufficient independent dice-generated entropy or a strong BIP-39 passphrase.
The company also said that seeds generated on Mk4, Mk5 and Q devices before their respective fixed firmware releases were affected to a lesser degree.
The distinction matters because a Bitcoin seed phrase is effectively the root of a wallet. Every private key and address associated with that wallet can be derived from it.
If an attacker can reproduce the seed, they do not need to break Bitcoin’s blockchain or defeat the hardware wallet’s physical protections.
Coinkite acknowledged the seriousness of the issue, stating: “Updating the firmware does not change or repair an existing seed.”
That means simply installing a security update is not enough for users whose existing wallets were generated under affected conditions. The vulnerable wallet must be migrated to a newly generated seed.
The company has released fixed firmware for the affected product lines, including version 4.2.0 or later for Mk2/Mk3, version 5.6.0 or later for standard Mk4/Mk5 devices and version 1.5.0Q or later for the Q model.
Cold storage’s security promise faces a reality check
The Coldcard incident is unlikely to undermine Bitcoin’s cryptography, but it could have a lasting effect on how investors evaluate hardware-wallet security.
For years, cold storage has been promoted as one of the strongest ways for individuals to protect large Bitcoin holdings.
The basic proposition is straightforward: remove private keys from internet-connected systems and eliminate dependence on exchanges or custodians.
Self-custody does not remove risk; it changes where the risk sits. Instead of trusting an exchange to protect assets, users must trust their wallet-generation process, backup procedures, firmware, physical security and recovery practices.
Coinkite’s own documentation makes that broader threat model explicit, identifying remote attacks, physical theft, coercion, loss and user error as separate categories of Bitcoin-security risk.
The company has also emphasized that independently supplied entropy can materially strengthen seed generation.
Its advisory says users who entered at least 50 fair, independent and private dice rolls during seed creation are not considered at risk from this particular randomness issue alone.
That guidance is particularly relevant for sophisticated Bitcoin holders. Multisignature custody, geographically separated backups, independent entropy and strong passphrases can reduce the consequences of a single point of failure.
Investors now face a broader self-custody question
The Coldcard attack arrives as institutional adoption has pushed Bitcoin further into mainstream finance.
Bitcoin ETFs, corporate treasuries and professional custody services have expanded the number of ways investors can gain exposure without directly managing private keys.
For sophisticated users, self-custody can still provide advantages that custodians cannot replicate.
Bitcoin remains a bearer asset, and controlling the private key provides direct control over the underlying coins. But the Coldcard episode shows that the phrase “not your keys, not your coins” is incomplete without another question: how were those keys generated?
Bitcoin’s underlying network remains unaffected by the Coldcard vulnerability. The incident instead highlights a less visible layer of the ecosystem, the software and hardware used to create the credentials that control Bitcoin.
Coinkite says its investigation remains ongoing and that additional technical details will follow.
Coinkite advises users to install the appropriate fixed firmware, generate a new seed, verify the backup and receiving address, conduct a small test transaction and only then move the remaining Bitcoin.
The broader lesson for crypto investors is more consequential. Cold storage can dramatically reduce certain classes of risk, but it cannot compensate for flawed key generation.
As Bitcoin holdings become larger and custody infrastructure becomes more sophisticated, security is no longer simply a question of whether coins are held online or offline.
It is a question of whether every layer between the investor and the blockchain can withstand failure.