Urgent Coldcard Seed Migration Alert: Move Bitcoin Now

Coldcard users are urged to migrate Bitcoin to new seed phrases after researchers estimate 1,367.05 BTC was drained. Coinkite released firmware fixes but warns existing seeds remain vulnerable; follow safe migration steps now.

Daniel RiversDaniel Rivers.
Urgent Coldcard Seed Migration Alert: Move Bitcoin Now

7 Minutes

Immediate seed migration urged for Coldcard users

Security researchers and community contributors have issued an urgent advisory for Coldcard hardware wallet owners to migrate Bitcoin funds to new wallets created from freshly generated seed phrases. The warning follows Galaxy Research's on-chain analysis estimating that roughly 1,367.05 BTC, about 88.6 million USD at the time of the analysis, was removed from 4,585 addresses across three suspected attack waves. The pattern and scale of the activity have heightened concerns about vulnerable seed generation in specific Coldcard firmware releases and reinforced debates about self-custody risk versus institutional custody alternatives such as spot Bitcoin ETFs.

Key facts at a glance

  • Galaxy Research attributes three suspected attack waves to the drain of 1,367.05 BTC from thousands of addresses.
  • Coinkite, the maker of Coldcard, has released patched firmware for affected models but emphasizes that firmware updates cannot fix seed phrases already generated under vulnerable code.
  • Community contributor Mishaboar publicly urged all users who have ever used a Coldcard device to migrate funds and never reuse compromised seed phrases, and to avoid entering recovery phrases into internet-connected devices.

What the on-chain analysis found

Galaxy Research's analysis identified three clusters of suspicious transactions that together represent an observed outflow of 1,367.05 BTC from 4,585 addresses. The first wave swept 1,082.65 BTC from 1,196 addresses in roughly 41 minutes on July 30. A later wave targeted many smaller balances, removing about 208 BTC from 1,912 addresses, which reduced the average per-address balance to just over 0.1 BTC. This shift suggests attackers adapted from collecting larger wallets to harvesting many smaller ones.

The firm noted that each wave showed internal consistency in transaction patterns, fees, and destination formats, implying a single operator per wave. However, Galaxy Research could not confirm whether the same actor controlled all three waves. It also warned that its heuristics may not catch every theft, and different attackers could drain wallets while using distinct transaction structures or fee profiles.

Why this matters for Bitcoin security and private keys

The incident highlights that Bitcoin itself was not compromised; rather, the flaw affected how certain Coldcard devices generated wallet secrets. Once an attacker reproduces or predicts a private key, they can create valid transactions that appear on-chain as owner-authorized, allowing immediate transfer of funds without attacking Bitcoin's protocol, cryptography, or consensus.

Coinkite technical advisory: which devices and firmware are affected

Coinkite has published an official security advisory identifying the vulnerable models and firmware tracks. Affected devices include Mk2 and Mk3 units running firmware v4.0.1 through v4.1.9. For Mk4 and Mk5 models, seeds created before standard version 5.6.0 or Edge version 6.6.0X are covered. Coldcard Q devices require standard version 1.5.0Q or Edge version 6.6.0QX as the fixed releases. Importantly, Mk1 devices are not implicated in the firmware regression, and other Coinkite products that use different codebases, such as TAPSIGNER, OPENDIME, and SATSCARD, are also reported as unaffected.

Block, the security team that traced the issue, reported that a firmware integration error caused some devices to use a deterministic MicroPython fallback rather than the intended STM32 hardware random-number generator. On vulnerable Mk2 and Mk3 v4 firmware, the affected path reportedly added no cryptographic entropy when generating seed phrases. Later devices or firmware releases incorporated a secure-element reseed to mitigate the risk.

Limitations of the technical analysis

Both Block and Coinkite caution that the current technical findings represent ongoing investigations. Block described its view as preliminary and said it did not rely on exhaustive empirical testing of every device in circulation. Coinkite continues to examine the issue and has promised a formal technical report to provide full details and verification steps.

Why firmware updates do not rescue compromised seeds

Coinkite has released patched firmware across affected models and release tracks to ensure that seed generation for new wallets uses proper entropy sources. However, those updates cannot retroactively add entropy to seed phrases that were already created under the vulnerable firmware. Any seed phrase generated on an affected device remains weak even if transferred to another hardware or software wallet, because the underlying words already encode the defective randomness. The only definitive remedy is to generate a new seed using corrected firmware and transfer funds to that new wallet.

Safe migration checklist

  • Install the fixed firmware for your Coldcard model before attempting any migration.
  • Create a brand-new wallet and record the new seed securely, following best practices for offline backups.
  • Verify a receiving address on-device and send a small test transaction to confirm the new wallet is functioning and the funds arrive.
  • After confirmation, move the remaining balance from the old seed to the new wallet.
  • Retain the old backup until the full migration is confirmed, but do not reuse the old seed under any circumstances.
  • Never type your seed phrase or recovery words into an internet-connected computer. Prefer offline verification, hardware-only address checks, and multiple secure offline copies stored separately.

Coinkite added an exception for users who manually added at least 50 fair, independent, and private dice rolls before finalizing the seed. Those dice rolls must have contributed at least 128 bits of independent entropy. Users who entered fewer than 50 rolls, cannot remember the count, or exposed the roll sequence should treat their seed as compromised and migrate.

Passphrases, security trade-offs, and remaining risks

A strong, unique BIP-39 passphrase can raise the barrier to attackers but does not repair a seed that was generated with insufficient entropy. Short or reused passphrases remain vulnerable to guessing or brute-force approaches. Coinkite and security advisors therefore recommend replacing the underlying seed as soon as practical even for users who used a strong passphrase.

Mishaboar, a contributor in the Dogecoin community who has been vocal about the issue, reinforced that users should never reuse affected Coldcard seed phrases or enter recovery words on devices connected to the internet. He also recommended setting additional passphrase layers where supported, such as Coldcard's 25th-word or 13th-word password options, during the creation of a new seed.

Wider implications for self-custody and institutional custody

The incident has reignited debate over the operational complexity of self-custody. High-profile investors and analysts have highlighted that hardware wallet failures, software bugs, and human operational errors expose private keys to risk even when the underlying blockchain remains secure. Some argue such incidents increase the appeal of spot Bitcoin ETFs, which provide price exposure without direct private-key management, while others emphasize that institutional custody shifts trust to third parties and introduces different systemic risks.

Bitcoin investor commentary has stressed that this was not a network failure but a third-party firmware bug. Nevertheless, the financial impact for affected individuals has been severe, and observers say the episode underscores the importance of robust device engineering, extensive testing, and clear user guidance in the hardware wallet ecosystem.

What to watch next

  • Coinkite's promised formal technical report, which should explain the root cause, affected builds, and recommended verification steps.
  • Further Galaxy Research address analysis and on-chain tracking as investigators may discover additional clusters or refine loss estimates.
  • Law enforcement engagement and potential recovery or tracing of stolen funds through coordinated investigations.

Until those updates arrive, the best immediate steps for users are to confirm whether their Coldcard model and firmware version are in the official advisory, update devices to the fixed firmware, and migrate funds to a new seed generated after the firmware fix. Treat any seed created on a listed vulnerable release as compromised and avoid typing recovery phrases into online devices or reusing old seeds under any circumstances.

This incident is a reminder that secure private-key custody requires both trusted hardware and rigorous software processes. For self-custody users, regular firmware maintenance, careful migration procedures, and conservative operational practices remain essential to reduce exposure to phishing, malware, and implementation bugs. For those weighing custody models, the trade-offs between personal control and institutional risk continue to shape investor preferences and product demand.

Final note

At present, the 88.6 million USD figure is an on-chain observed estimate and not a confirmed total loss. Affected users should prioritize following Coinkite's advisory, migrate only after installing fixed firmware, and verify transactions with test transfers. Ongoing investigations by Coinkite, Block, and Galaxy Research should clarify the full impact and lead to more detailed mitigation guidance in the days ahead.

Daniel Rivers
"Hey there, I’m Daniel. From vintage engines to electric revolutions — I live and breathe cars. Buckle up for honest reviews and in-depth comparisons."

Leave a Comment

Comments

No comments yet. Be the first.