Coldcard Exploit Exposes Weakness in Air-Gapped Bitcoin Wallet Security
The Coldcard exploit has raised questions about air-gapped Bitcoin wallet security after Coinkite warned that seeds created on affected firmware may be at risk. The incident is not a break of the Bitcoin network or offline storage, but a failure of how one hardware wallet generated its random keys.
Coldcard's company behind it, Coinkite, published a security advisory on July 30, 2026, and updated it on August 1, 2026. They warned that funds controlled by seeds generated on affected firmware are at risk if they were created without at least 50 independent private dice rolls and without a strong unique BIP-39 passphrase.
The advisory sets a concrete threshold for extra user-supplied entropy on affected firmware. Coinkite says seeds generated on Mk4, Q, and Mk5 before the fixed firmware releases carried about 72 bits of entropy rather than the expected 128 bits, a material shortfall in the randomness that protects private keys.