Coldcard Firmware Flaw Tied to $88.6M Bitcoin Drain, Users Urged to Migrate
AI Market Summary
Onchain analysis links a Coldcard firmware entropy regression to suspected theft waves totaling ~1,367 BTC (~$88.6m) across thousands of addresses, triggering urgent guidance to migrate funds and never reuse affected seeds. While the Bitcoin protocol is not implicated, the incident raises near-term self-custody risk perception and could increase preference for third-party custody solutions. Loss estimates remain unconfirmed pending Coinkite's report and further forensics.
Impact level
● Medium
Affected assets
BTC/USDT+1.35%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Coldcard hardware wallet users are being urged to move funds immediately after on-chain investigators linked a firmware defect to a large cluster of suspected Bitcoin thefts.
Dogecoin contributor Mishaboar said on Aug. 1 that anyone who has ever used a Coldcard should "migrate your funds to a new wallet immediately," and warned users not to reuse any seed phrase generated on a Coldcard device.
Galaxy Research: three suspected waves, 1,367 BTC
Galaxy Research said its on-chain analysis points to three suspected attack waves that together swept 1,367.05 BTC—about $88.6 million at the time of reporting—from 4,585 addresses. Galaxy described the $88.6 million as an "estimated observed size" and noted the figure has not been independently confirmed by Coinkite, law enforcement, or every affected user.
According to Galaxy, the first wave moved 1,082.65 BTC from 1,196 addresses in roughly 41 minutes on July 30. A later third wave drained about 208 BTC from 1,912 addresses, with the average balance in that cluster dropping to about 0.1 BTC per address. Galaxy said the pattern suggests attackers shifted from targeting larger balances to sweeping many smaller wallets.
Galaxy added that each wave appeared internally consistent with a single operator, though it could not confirm whether the same actor executed all three. The third wave showed different operational details—separate destination addresses, batching multiple victims per transaction, and checking only the default derivation path—suggesting tactics evolved over time.
The firm also cautioned that pattern matching may miss some thefts, and that other attackers could produce valid transactions that do not match the same fee, destination, or collection patterns.
Coinkite: which devices and firmware are in scope
Coinkite's advisory limits the risk to specific models and firmware versions:
- Seeds generated on Mk2 and Mk3 devices running firmware 4.0.1 through 4.1.9 are affected.
- Seeds created on Mk4 and Mk5 devices before standard v5.6.0 or Edge v6.6.0X are also covered.
- Coldcard Q users are affected if their seed was created before standard v1.5.0Q or Edge v6.6.0QX.
Coinkite said Mk1 devices are outside the reported firmware regression. TAPSIGNER, OPENDIME, and SATSCARD are not affected because they use different codebases.
Root cause: deterministic fallback in seed generation
Block's Bitcoin engineering and security team traced the issue to a firmware integration error. In the affected code path, wallet secrets could be generated using a deterministic MicroPython routine rather than the STM32 hardware random-number generator. Block said Mk2 and Mk3 v4 firmware added no cryptographic entropy in this fallback path, while later models received some limited secure-element reseed.
Block emphasized its assessment reflects the current technical understanding and is not based on exhaustive device testing. Coinkite said its investigation remains ongoing and that it plans to publish a formal technical report.
Fixes are available—but old seeds cannot be repaired
Coinkite has released updated firmware for each affected model and release track. The updates fix seed generation for newly created wallets, but they cannot retroactively add entropy to seed phrases already generated.
As a result, moving a vulnerable seed into another wallet—hardware or software—does not remove the weakness.
Recommended steps for users
Coinkite and security researchers recommend migrating funds using cautious procedures:
1) Install the fixed firmware for your device before generating a replacement seed.
2) Generate a new seed on the updated device; do not reuse the old Coldcard seed phrase.
3) Record and verify the new backup, and confirm the receiving address on the device screen.
4) Send a small test transaction and verify receipt before transferring the remaining balance.
5) Keep the old backup until migration is fully verified, but do not enter the old seed into any computer or internet-connected device.
Additional guidance and exceptions
Security experts reiterated that seed phrases should never be typed into an internet-connected computer. Mishaboar also recommended maintaining multiple offline copies stored in separate secure locations to reduce exposure to phishing, malware, or cloud sync risks during a rushed migration.
Coinkite noted a narrow exception: users who added at least 50 fair, independent, and private dice rolls before the final seed words were produced—providing at least 128 bits of independent entropy—may be protected. Users who entered fewer than 50 rolls, cannot recall the count, or exposed the roll sequence are advised to migrate.
A strong, unique BIP39 passphrase can add protection but does not repair a compromised seed. Short, reused, or predictable passphrases may remain guessable, and users are advised to replace the underlying seed as soon as practical.
Market implications and what to watch
Bitcoin investor Anthony Pompliano said the episode underscores the operational complexity of self-custody. The Bitcoin protocol itself was not compromised; attackers were able to reproduce weak wallet keys offline after a third-party firmware issue weakened key generation.
The incident has also renewed debate over institutional custody. Some spot Bitcoin ETF proponents argue it strengthens the case for investors seeking price exposure without managing private keys, while critics note ETF custody introduces its own counterparty risks.
Next catalysts include Coinkite's promised technical review and further address analysis from Galaxy Research. Until then, the $88.6 million figure should be treated as an on-chain estimate rather than a final confirmed loss. The immediate priorities remain installing patched firmware, generating a new seed on updated devices, and completing an offline, carefully verified migration.