A five-year-old firmware bug in Coldcard hardware wallets let attackers drain $116 million in Bitcoin this summer — and if you generated a seed on one between 2021 and July 2026, your coins might still be exposed.
Coldcard built its reputation on being the hardware wallet security people trust with real money — air-gapped, open-source, Bitcoin-only. On July 30, 2026, attackers started proving that reputation had a five-year-old hole in it. A firmware bug shipped in March 2021 had been quietly weakening the random numbers Coldcard used to generate wallet seeds. By the time Coinkite, the company behind Coldcard, patched it, roughly 1,816 BTC, about $116 million, had been drained from more than 5,200 addresses.
Updated 25 Sep 2026: are you affected, and what to do
Which seeds are affected, and the first fixed firmware (per Coinkite)
Mk2 / Mk3
Seeds at risk if generated on…
Firmware 4.0.1 (March 2021) through 4.1.9 inclusive
Update to (before making a new seed)
4.2.0 or later
Mk4 / Mk5 (standard)
Seeds at risk if generated on…
Any version before 5.6.0
Update to (before making a new seed)
5.6.0 or later
Mk4 / Mk5 (Edge)
Seeds at risk if generated on…
Any version before 6.6.0X
Update to (before making a new seed)
6.6.0X or later
Q (standard)
Seeds at risk if generated on…
Any version before 1.5.0Q
Update to (before making a new seed)
1.5.0Q or later
Q (Edge)
Seeds at risk if generated on…
Any version before 6.6.0QX
Update to (before making a new seed)
6.6.0QX or later
Seeds at risk if generated on…
Update to (before making a new seed)
Mk2 / Mk3
Firmware 4.0.1 (March 2021) through 4.1.9 inclusive
4.2.0 or later
Mk4 / Mk5 (standard)
Any version before 5.6.0
5.6.0 or later
Mk4 / Mk5 (Edge)
Any version before 6.6.0X
6.6.0X or later
Q (standard)
Any version before 1.5.0Q
1.5.0Q or later
Q (Edge)
Any version before 6.6.0QX
6.6.0QX or later
Two points from Coinkite that the early coverage, including ours, underplayed. First, it isn't only old devices: per the advisory, seeds generated on Mk4, Q and Mk5 before their fixed releases are also affected, "with about 72 bits of entropy rather than the expected 128 bits." Coinkite says that impact is "not as severe but is still serious," and its status page says "Do not treat later hardware as outside the affected scope." Second, Standard and Edge are separate release tracks: Coinkite warns not to assume an older Edge 6.x release is fixed "merely because its version number is higher."
If you added at least 50 dice rolls: per the advisory, if you entered "at least 50 fair and independent rolls, and the rolls were not recorded or exposed," Coinkite does "not consider the resulting seed at risk from this RNG issue alone." Fewer than 50, or you can't remember? Coinkite says to migrate.
If you use a BIP-39 passphrase: a strong, unique passphrase is "an independent barrier," but Coinkite says it "does not repair the affected seed" and passphrase users "should also migrate as soon as practical." A short, common, patterned or reused passphrase should be treated as at risk. Migrate immediately. (This means the BIP-39 passphrase, not your PIN.)
If you're unsure which words you used, how many rolls you entered, or whether they were private: Coinkite's answer is to migrate to a new seed.
Coinkite's migration steps
Confirm the fixed firmware version for your model is installed. Coinkite's status page says to verify the signed download before generating a seed.
Generate a new seed on the updated COLDCARD.
Record and verify its backup before depositing funds.
Verify a new receive address on the COLDCARD screen.
Send a small test transaction and confirm the new wallet works.
Only then move the remaining funds.
Keep the old backup until the migration is complete and confirmed.
If a Mk2 or Mk3 is your only device, Coinkite says firmware 4.2.0 lets it generate a correct replacement seed, so you don't need a newer COLDCARD. But it involves carefully switching between the old and new seed on one device. Coinkite's full step-by-step migration guide covers that, and an optional advanced dice-only route (at least 99 rolls; see its dice-roll method). Coinkite's closing advice applies to everyone: "Rushing a wallet migration can create a more immediate risk than the issue you are trying to address." Go slowly, test with a small amount first, and never type your seed or passphrase into anything but the device.
How a hardware chip got skipped for five years
The bug itself is almost embarrassingly simple to explain, per The Hacker News' technical writeup. Coldcard devices are supposed to pull randomness for a new wallet seed from a dedicated hardware random-number generator built into the chip — the part of the security story that's supposed to make a hardware wallet meaningfully safer than software. A production configuration error in the March 2021 firmware build set a flag called MICROPY_HW_ENABLE_RNG to zero, which silently rerouted seed generation to MicroPython's software fallback generator instead. That dropped the effective entropy from the 128 bits a secure seed needs down to somewhere between 40 and 72 bits depending on the model, weak enough to brute-force without ever touching the physical device.
~1,816
BTC stolen
Roughly $116 million at time of theft
5,200+
Addresses hit
Across four separate waves
5 years
Bug lifespan
March 2021 to July 2026
$1.2B+
2026 crypto losses so far
Across 276 incidents, per TRM Labs
How the theft unfolded
Mar 2021
Coinkite ships firmware 4.0.1 with the RNG misconfiguration, unnoticed for five years.
Jul 30, 2026
First wave: about 594 BTC (~$38M) drained from roughly 500 addresses in 25 minutes.
Jul 31, 2026
Coinkite posts an emergency advisory and ships patched firmware for every model within a day.
Aug 1–3, 2026
Two more waves push the total to roughly 1,367 BTC (~$89M) from 4,585 addresses.
Aug 7, 2026
Coinkite reverses its data-deletion policy, citing anticipated legal obligations.
Coinkite's CEO, who goes by NVK, didn't soften the warning when the advisory went out: 'If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further.' That's not boilerplate. Installing the new firmware only protects seeds generated after you update it. Anything created on a vulnerable Coldcard between March 2021 and the patch needs to be treated as burned, full stop, even if it's sitting untouched today.
Hardware wallets are supposed to keep private keys away from any internet-connected device — this bug undermined that at the source. · Unsplash
Who actually got hit, and how they're being caught
Galaxy Research and TRM Labs have been running the on-chain math since the first wave, and the pattern is uglier than a single opportunistic hacker cashing in. Transaction construction differs across the four waves enough that researchers think multiple attackers may be working the same vulnerability independently. TRM traced part of the stolen funds through a 64.9 BTC deposit into Wasabi Wallet and roughly 200 ETH routed through Tornado Cash on August 4, standard mixing playbook, not a sign anyone's slowing down. Canadian holders took the largest share of the losses, around a quarter of the total, ahead of victims in the US and Thailand.
The part that should worry every hardware-wallet owner
The fallout is already reaching lawyers. Thomas Braziel of 117 Partners is examining product liability and class-action claims against Coinkite on behalf of affected holders, and legal experts are split on how strong that case actually is — a defect claim is plausible, but device makers have historically had wide latitude to disclaim this kind of loss in their terms of service. Coinkite's decision to stop automatically deleting customer records, a reversal of a policy the brand built its entire privacy pitch around, is itself the clearest signal that the company expects to end up in court.
Self-custody relocates risk rather than eliminating it.
TRM Labs
Is my Coldcard still vulnerable?
Updating the firmware protects new seeds, but it doesn't repair a seed that was already generated on affected firmware. Per Coinkite, that's Mk2/Mk3 firmware 4.0.1 through 4.1.9, Mk4/Mk5 before 5.6.0 (Edge before 6.6.0X), and Q before 1.5.0Q (Edge before 6.6.0QX). Those seeds need to be replaced by generating a new seed on fixed firmware and moving funds, unless you added at least 50 private, fair dice rolls when creating it. See the "what to do" section above and Coinkite's migration guide.
How much was actually stolen?
Roughly 1,816 BTC, worth about $116 million at the time of the thefts, taken from more than 5,200 addresses across four waves between July 30 and early August 2026.
What caused the bug?
A March 2021 firmware build (version 4.0.1) mistakenly disabled the hardware random-number generator, routing seed creation through a much weaker software fallback instead.
Can I get my funds back?
Not through Coinkite directly for coins already stolen. Some victims are pursuing legal claims through firms like 117 Partners, but recovery isn't guaranteed and experts describe the legal case as genuinely uncertain.
Are other hardware wallets affected?
No reports have tied this specific bug to other manufacturers, it's a Coldcard/Coinkite firmware defect, not an industry-wide flaw. But it's a reminder that 'hardware wallet' isn't a synonym for 'unhackable' — the same lesson applies to enterprise gear that's supposed to be locked down too.
Watch two things from here. First, whether Coinkite ever publishes a real number instead of the range analysts have pieced together on-chain, reporting says the company still won't estimate its own losses. Second, whether the class-action threat turns into an actual filing, because that outcome will set the precedent for how liable a hardware-wallet maker can be held when the failure is in the chip, not the user. Until then, if you've ever owned a Coldcard, check your firmware version before you do anything else today.