← Back to Home Security Advisory

The Coldcard Exploit: What Self-Custody Clients Must Do Now

The Coldcard seed-generation exploit has drained 1,816 BTC from 5,200+ wallets. Here is exactly what affected clients must do now.

Sovereign Wealth Engineering

Issued: August 14, 2026. This advisory is for our self-custody clients. It walks through what happened, whether you are affected, and the exact steps to protect your funds. Everything here traces back to a verified fact sheet and source-linked timeline prepared by our research and security teams. I will not inflate numbers I cannot back.

TL;DR

A flaw in Coldcard's seed-generation code quietly weakened the cryptography behind new wallets. It was introduced in March 2021 and went unnoticed for five years. Starting July 30, attackers exploited it remotely, with no physical access, and have drained roughly 1,816 BTC (about $116M) from more than 5,200 addresses so far. Updating your firmware does not fix this. If your seed was created on an affected Coldcard between March 2021 and now, you must generate a fresh seed on patched firmware and move your funds. Do this now, calmly, in the order below.

What happened

Coldcard hardware wallets are built around secure elements and are treated as the gold standard of self-custody. The attack did not break the Bitcoin network. It broke a specific product line. A compile-time guard in Coldcard firmware tested for the existence of a macro instead of its value, and the result silently swapped the hardware true-random generator for a predictable software imitation. Hardware wallets that were supposed to produce 128 bits of randomness were producing closer to 40 bits on older models and about 72 bits on newer ones. A key that was meant to be unbreakable became something a determined attacker could brute force offline.

The weakness does not require touching your device. Attackers generated candidate keys offline, checked them against the blockchain, and swept funds from wallets whose seeds were made with the broken generator. This is the largest hardware wallet theft in Bitcoin's history. TRM Labs calls the $116M figure preliminary because more victims surface over time.

Are you affected?

You are affected if your wallet's seed was generated on an affected Coldcard firmware version. It does not matter what device holds the seed today, or that you have since moved it to another wallet. Exposure is set by the firmware that created the seed, not the hardware that stores it now. Check your device: Advanced/Tools, then Danger Zone, then Firmware Version.

The affected versions are:

Two exceptions may put you outside scope. A seed created with at least 50 independent, private rolls of a six-sided die entered through the dedicated dice workflow is treated as safe, with 99+ rolls giving full strength. And a strong, unique BIP-39 passphrase adds a real barrier. But Coinkite itself tells passphrase users to migrate as soon as practical, because a passphrase does not repair the underlying seed. If you are not certain, treat the seed as compromised.

What to do now

Work through these steps in order. Do not panic, and do not skip ahead.

First, update your firmware. Download only from the official Coldcard site, verify the SHA-256 checksum against the published hash, and verify the PGP signature if one is published. Standard and Edge are separate tracks, so install the fix for your model's track, not a neighboring one.

Second, generate a new seed on the updated firmware. On Mk2 and Mk3 after 4.2.0 the normal new wallet flow is corrected. If you want maximum assurance, use the dice-only path with 99+ rolls, which never touches the device generator at all.

Third, migrate your funds in stages. Record and verify the new seed's backup first, then confirm a receiving address on the device screen. Send a small test transaction and wait for it to confirm. Only when it arrives move the rest, and hold onto the old backup until the full balance is confirmed in the new wallet.

A warning for SegWit multisig users with all-Coldcard signers. Do not broadcast the migration transaction directly. An attacker who knows your keys can replace it with a higher-fee version and steal the inputs. Use an out-of-band service to submit the transaction instead.

What not to do

Do not enter your seed phrase on any website, app, or so-called recovery tool, no matter how official it looks. Phishing is already active around this story. Do not pay anyone who claims they can recover your funds for a fee. Do not dispose of an affected device, because Coinkite says it may be needed if funds are recovered, and do not fall for fake firmware update links sent by email or direct message. The official download site is the only safe source.

What this means for multisig and the long term

If you run multisig, the question is whether any single spending path can be met using only affected Coldcard keys. A 2-of-3 with two Coldcards is compromised. A quorum that no single brand can satisfy is the structural defense, and it is what experts now recommend. Everything derived from an affected seed is also compromised. That includes Nostr keys, Lightning node seeds, SSH keys, and duress wallets, so regenerate those too if they came from the affected seed.

Sources and confidence

The root cause, the affected firmware table, and the fixed versions are confirmed by Coinkite's advisory, Block Engineering's independent technical analysis, and Wizardsardine's code trace. The ~1,816 BTC and $116M theft figure is preliminary per TRM Labs, and the number of distinct attackers is highly probable but not confirmed. Product lines outside the affected codebase, including TAPSIGNER, OPENDIME, and SATSCARD, are asserted not affected. A formal Coinkite postmortem is still in progress as of this writing.

The full technical detail lives in our fact sheet and source-linked timeline, which we are happy to share on request. The short version is simple. The Bitcoin network was not hacked. Your hardware wallet's firmware was. And if your seed came from the wrong firmware, updating alone will not save it. Replace the seed. That is the only real fix, and it has to happen before the attackers find your keys. They are already looking.

Check Your Coldcard Setup

Get a structured review of your cold storage, including whether your seed predates the fix and how to migrate to a fresh one without exposing your keys.

Book a Review

Sources: Coinkite Security Advisory; Coldcard Security Status Page; Wizardsardine, technical analysis; TRM Labs, on-chain analysis. Related reading: Coldcard Seed Vulnerability: $100 Million Gone, and Every Model Is Affected. This article is for education only and is not trading or legal advice.