Coldcard Firmware Flaw Exposes Wallets to Hackers
A security flaw in the Coldcard firmware has exposed weak seed randomness across several Coldcard models. This weakness allows attackers to recreate private keys, making it easier for them to drain wallets. The affected seeds were created between 2021 and 2026 on Mk3 devices using firmware versions 4.0.1 through 4.1.9, as well as on Mk4 and Mk5 devices before version 5.6.0 and Q seeds created before version 1.5.0Q.
The flaw was discovered after a major Coldcard wallet theft, which drained around 594 BTC (worth approximately $38 million) from about 500 wallets within a 25-minute period. Researchers linked the losses to the firmware weakness during seed creation. Coinkite, the firm behind Coldcard, has released fixed firmware for each affected model, but installing an update does not repair existing seeds.
Users who added at least 50 private, independent dice rolls during seed creation may have enough external entropy to protect their wallets. Strong BIP-39 passphrases also add protection, although Coinkite still advises migration. A device PIN does not provide the same level of security as a separate passphrase.
The Bitcoin price has held steady near $62,600, keeping the $60,000 support level in focus. The market has been volatile, and while the Coldcard wallet theft adds pressure, it has not caused a confirmed market-wide selloff. A sustained move below $60,000 could bring the $58,000 area into focus.