The Coldcard Security Breach, Explained Simply
On July 30, 2026, Coinkite (the company behind the Coldcard hardware wallet) confirmed a firmware flaw that let an attacker steal roughly 594 bitcoin, about $38 million, in under 30 minutes. Here's what actually happened, and the one lesson worth taking from it.
The short answer
A bug in Coldcard's firmware, present since 2021, caused some devices to generate private keys in a predictable way instead of a truly random one. An attacker figured this out, worked backward to guess the keys, and swept roughly 500 wallets in a single 25-minute run. If you don't own a Coldcard, your Bitcoin was never touched by this. If you do, Coinkite has published exactly which firmware versions are affected.
What actually went wrong
Every hardware wallet needs a way to generate a private key that's truly unpredictable. Coldcard was built with a dedicated chip for this. But a coding mistake introduced in a 2021 firmware update caused some devices to skip that chip and fall back to a weaker, more predictable method instead, without telling the user anything was different.
The flaw sat there, unnoticed, for years. Coinkite says its own security review missed it too. The company now believes an attacker used an AI tool to comb through Coldcard's public, open-source code and found what human reviewers didn't.
Once the attacker could predict which keys were weak, they didn't need your seed phrase or physical access to your device. They just needed to guess correctly, and with the flaw mapped out, guessing correctly was fast. Around 500 wallets, mostly Coldcard Mk3 devices on the affected firmware, were emptied in one coordinated sweep.
The one workaround that sidesteps this entirely
This flaw only exists because the device generated the randomness for you. There's a way around that: rolling physical dice and using the results to build your own seed phrase by hand, instead of trusting any chip to do it. Economist Saifedean Ammous, who wrote up clear guidance on this event, put the safe threshold at 100 fair, independent, private dice rolls for a 24-word seed, with 50 or more also appearing safe. Do that correctly, and no firmware bug on any device can ever make your key guessable.
I mention it because it exists, not because I expect most people to do it. It's slow, unforgiving of mistakes, and genuinely not simple. For most people, multisig across a few trusted vendors gets you almost all of the same protection with far less friction.
If your Coldcard seed needs to move
If you generated your seed on a Coldcard without 100 private dice rolls, or you're not sure whether you did, or you're not sure which firmware you were on, treat your seed as affected. The safe process:
- Generate a completely new seed on a device that isn't affected, or an air-gapped computer.
- Carefully write down and verify the new backup.
- Check the wallet fingerprint and a receiving address against what the hardware wallet itself shows.
- Send yourself a small test amount first.
- Once the test transaction confirms and everything checks out, move the rest.
A strong BIP-39 passphrase adds a real extra layer, but only if it's strong and kept separate from the seed. Even with one, moving to a freshly generated seed is worth doing.
If all of that feels like too much right now, moving your funds to a reputable exchange temporarily, just until you're ready to set up a new seed safely, is a reasonable stopgap. It's not where Bitcoin should live long-term, but it beats sitting on a seed you don't trust while you figure it out.
For the latest official word, use Coinkite's own channels only: blog.coinkite.com and coldcard.com/docs/upgrade.
Why Coldcard, of all devices
If you've shopped for hardware wallets, you probably know Coldcard by reputation: air-gapped, open-source, built for people who want maximum control and don't mind a steeper learning curve. It's not the beginner-friendly option. It's the one serious, security-conscious people reach for.
That's exactly why this matters. This wasn't a cheap knockoff device or a careless company. It was one of the most respected names in Bitcoin hardware, and a coding mistake still slipped through for years. That's not a reason to distrust Coldcard specifically. It's a reason to stop assuming any single vendor is infallible, no matter how good their reputation is.
The lesson: don't put all your trust in one device
A single hardware wallet, from any brand, is one company's mistake away from a problem. For most people, holding a modest amount of Bitcoin on one well-chosen device is still perfectly reasonable. But once you're holding an amount that would genuinely hurt to lose, it's worth adding a second layer: multisig.
Multisig means your Bitcoin needs signatures from more than one key to move, and those keys can come from completely different hardware vendors. If one vendor has a flaw like this one, an attacker who compromises that single key still can't move your funds, because they don't have the others.
This is exactly the scenario multisig services like Casa are built for. Casa users who had a Coldcard as one of several keys in their setup weren't at risk of losing anything. Worst case, they rotate out one key. That's the entire point of spreading trust across more than one device.
If you're starting out
You don't need multisig on day one, and you shouldn't feel behind if you don't have it yet. What you do need, from the very beginning, is to get your Bitcoin off exchanges and into a wallet only you control. Every single-vendor flaw is still safer than leaving your Bitcoin sitting on a platform that can freeze it, lose it, or get hacked at the account level.
If you're looking for the simplest possible starting point, Bitkey is the easiest self-custody device to pick up, with no seed phrase to manage yourself. As your holdings grow, that's the point to start thinking about multisig.
Watch out for the scammers this brings out
Every time news like this breaks, scammers show up pretending to help: fake “urgent migration” tools, DMs asking you to “verify” your seed phrase, links to look-alike websites. Never type your seed words or passphrase into a website, computer, phone, chatbot, or anyone offering to “recover” your funds for you, no matter how official they sound. If something is telling you to move fast and hand over your words, slow down. That urgency is the scam.
Where I land
Jameson Lopp, who co-founded Casa and has spent years thinking about exactly this kind of risk, put it better than I can:
“This is the part where I remind folks once again that every hardware vendor is fallible. If you want to hedge against vendor risks and supply chain risks, the solution is multi-vendor multisig. We have plenty of Coldcard users over at Casa and this event will just be a minor annoyance for them to rotate out the compromised key with a securely generated one.”
He also had this for anyone worried their funds might already be at risk: “If your funds are on a seed phrase that was generated on a vulnerable Coldcard firmware and you're looking to re-secure them by sending to a freshly generated seed phrase, the most important thing is to not panic and not rush. Mistakes can be catastrophic.”
Common questions
I don't own a Coldcard. Does this affect me?
Not directly. But the lesson does: any single device, from any brand, can have a flaw nobody caught. That's true of every hardware wallet on the market, not just this one.
Should I move my Bitcoin off my Coldcard right now?
If your seed was generated with 100 private dice rolls, you're not considered at risk. If it wasn't, or you're unsure, treat it as affected and migrate to a freshly generated seed using the steps above, moving slowly and carefully rather than rushing.
Does this mean hardware wallets are unsafe?
No. It means any single hardware wallet, no matter how good, is one vendor's mistake away from a problem. That's exactly the risk multisig is built to remove.
Someone messaged me saying I need to move my funds immediately. Is that legit?
Treat it as a scam until proven otherwise. Breaking security news is prime time for scammers pretending to help. Coinkite will never DM you asking for your seed phrase, and neither will anyone else.