Coldcard Firmware Flaw Exposes Wallets to Entropy Risk
Coldcard users are reevaluating their wallet safety after reports surfaced of a seed-generation flaw in older device firmware versions. The issue, which has led to a reported sweep of around 594 BTC from roughly 500 single-signature wallets on July 30 and 31, 2026, highlights the importance of entropy in Bitcoin security.
The problem relates to Coldcard Mk3 firmware versions 4.0.1 through 5.0.3, as well as Mk4 and Mk5 devices before firmware 5.6.0, and Q devices before 1.5.0Q. A hardware random number generator was replaced by a predictable software substitute, reducing entropy from the intended 128 bits to 72 bits.
This weakness can make it easier for attackers to guess or derive seed phrases, putting wallets at risk even if users have never shared their phrase or exposed private keys. Seeds generated with a BIP-39 passphrase or sufficient dice rolls are not considered at risk under the validated notes.
For Coldcard users, determining whether their seed was generated on affected firmware and whether additional entropy or passphrase protection was used is crucial. Users with exposure should follow official guidance and avoid entering seed phrases into any website or unknown tool claiming to check vulnerability status.