Skip to content
Back to Guavy Wire
Crypto

Coldcard Bug Exposed: Over 1,300 Bitcoin Stolen via Predictable Seed Phrase Generation

Instruments
BTC
Share

A security flaw in Coinkite's Coldcard hardware wallets has left over 1,300 Bitcoin stolen, worth around $88.6 million at the time of theft.

The bug dates back to a software update in March 2021 and was only recently discovered by Coinkite on July 30. The issue caused the devices to generate wallet seed phrases using a predictable software program instead of their dedicated chip for generating true randomness, leaving them vulnerable to hacking.

According to Coinkite, the affected models are the Mk2 and Mk3, which generated seeds with only about 40 bits of real randomness. The company has since released fixed software for every affected model, but installing the update does not fix a seed that was already generated on the flawed software.

The incident is a reminder that even hardware wallets can be vulnerable to security flaws if their software is not properly secured. Coinkite's code has been publicly viewable for years, which likely helped an outsider find the flaw first.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Real-time market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc