BTC Security

Coldcard's Seed Generation Bug Has Drained $114 Million—And It's Still Running

2026-08-04

Coldcard users are getting the urgent talk. A firmware flaw from March 2021 has sat dormant for five years, and now it's actively draining bitcoin. Fourth wave of attacks. $114 million gone. Over 5,200 wallets hit. Roughly 1,816 bitcoin stolen in coordinated sweeps since late July.

Here's what happened. A single commit on March 1, 2021, did the damage. The Coldcard firmware switched its seed-generation routine from the hardware random number generator on the STM32 chip to a broken software path instead. Result: reproducible keys that anyone with the right knowledge can work out offline.

The entropy loss varies by model. Mk3 users got hit hardest—their seeds dropped from 128 bits of entropy down to about 40 bits. Mk4, Mk5 and Q owners are looking at roughly 72 bits. Single-key setups got compromised. Multisig wallets stayed safe.

In the first large sweep on July 31, an attacker drained 594 bitcoin (around $38 million) from 500 wallets in 25 minutes. Then the subsequent waves came. Three distinct attack phases swept 1,367 bitcoin—nearly $89 million—from 4,585 addresses. The latest attacks are getting smarter: smaller balances, harder-to-trace transaction patterns, replace-by-fee tactics to stay ahead of victims in the mempool.

That last bit might actually matter. If you spot your coins in the mempool, you could theoretically outbid the attacker and move them first. Potential recovery window, if you're fast.

Coinkite's guidance depends on your hardware. Mk3 owners on firmware 4.0.1 or later should move funds now. Mk4, Mk5, and Q users below firmware versions 5.6.0 or 1.5.0Q should update, create a new wallet, then migrate everything. But—and this is important—firmware updates can't fix seeds that are already compromised. New seed generation only.

There is one exception. Did you add manual entropy during setup? Dice rolls, coin flips, something genuinely random? If you added 50 or more fair rolls, you're probably fine. The bug only affected the device-generated portion. Same goes for strong, unique BIP-39 passphrases—they create a separate derivation path that stays protected.

Coinkite is now claiming the attacker likely used AI to comb through its open-source firmware for vulnerabilities. The irony is thick: Coinkite ran its own AI review weeks before the exploit began and found nothing serious. It missed the bug entirely. Now Galaxy Research is saying every vulnerable device will eventually get emptied. They've handed 600 suspected attacker addresses to federal investigators.

This is self-custody at its worst. Bitcoin's price has held up fine, but the infrastructure risk is real. The attack happened at the key generation stage—the moment users rely most heavily on systems they never directly see or interact with. No warning signs. No obvious failure. Just a dormant flaw and an attacker who found it.

The move is straightforward: check your device model and firmware version, generate a new seed on patched hardware, move your funds. Do it now.


Source & further reading:

Sources