Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Coldcard releases firmware update after seed flaw led to $88.6m Bitcoin theft
00

Coldcard releases firmware update after seed flaw led to $88.6m Bitcoin theft

Aug 20, 2026

Coinkite releases Coldcard firmware updates 5.6.1 and 1.5.1Q following a critical seed-generation flaw that led to the theft of up to 1,816 Bitcoin, valued between $88.6 million and $112 million. The vulnerability, introduced in March 2021, reduced entropy by using a software fallback instead of the hardware random-number generator. While the updates introduce mandatory user-supplied entropy and tighter transaction checks, affected users must generate entirely new seeds and migrate their funds to secure their assets.

Coldcard seed-generation flaw

  • ▪The Coldcard seed-generation flaw reduced the effective entropy of generated seeds from the intended 128 bits to approximately 40 bits on Coldcard Mk2 and Mk3 devices, and about 72 bits on Mk4, Mk5, and Q devices.
  • ▪The Coldcard seed-generation flaw occurred because a safety check in a supporting library failed to detect that the built-in hardware generator had been disabled, dropping seed generation to a software fallback.
  • ▪The affected Coldcard devices include Mk2 and Mk3 models running firmware versions 4.0.1 through 4.1.9, Mk4 and Mk5 devices running firmware before version 5.6.0, and Coldcard Q devices running firmware before version 1.5.0Q.
  • ▪A firmware flaw introduced in March 2021 caused certain Coldcard hardware wallets to generate private keys using the device's serial number and internal clock instead of the dedicated random-number generator chip.

Firmware update security measures

  • ▪Coinkite released Coldcard firmware versions 5.6.1 for Mk4 and Mk5 devices and 1.5.1Q for Coldcard Q devices to address the seed-generation vulnerability and introduce additional security measures.
  • ▪The Coldcard firmware update restricts several seed-related functions in Delta Mode, limits USB downloads to the latest device-produced result via an encrypted session, and adds checks for hardware random-number generator faults.
  • ▪The updated Coldcard firmware requires every newly generated seed to incorporate at least one source of user-supplied entropy, such as 65 key presses, 50 physical dice rolls, or 128 physical coin flips.
  • ▪The new Coldcard firmware introduces staged verification of partially signed Bitcoin transactions (PSBTs) immediately before signing to detect if a connected computer has modified the transaction data.

Bitcoin theft attack mechanics

  • ▪Blockchain researchers and investigators estimated the total theft from the Coldcard vulnerability at 1,367 to 1,816 Bitcoin, with monetary loss estimates ranging from $88.6 million to $112 million.
  • ▪Galaxy Research and Block's engineering team analyzed the stolen funds, identified an unusual sweep pattern linked to a blockchain-services provider query, and provided leads to law enforcement.
  • ▪Attackers exploited the predictable Coldcard seeds to reconstruct wallets offline and steal Bitcoin without requiring physical access to the hardware devices or their PINs.
  • ▪On July 30, 2026, an attacker stole 594 Bitcoin from approximately 500 inactive Coldcard wallets in a 25-minute period.

Wallet migration requirements

  • ▪Coinkite warned that installing the new firmware does not secure previously generated seeds, and affected users must generate an entirely new seed and migrate their funds to the replacement wallet.
  • ▪Coldcard users who previously added at least 50 private, independent physical dice rolls during setup are exempt from the migration requirement, as the rolls provided sufficient independent entropy.
  • ▪Following the Coldcard thefts, centralized cryptocurrency exchange OKX recorded unusually high deposit inflows as some users reconsidered self-custody.
  • ▪Importing an affected Coldcard seed phrase into a different hardware or software wallet, or adding a BIP-39 passphrase, does not repair the underlying vulnerability of the seed.

AI-assisted security vulnerabilities

  • ▪Coinkite ran an advanced artificial intelligence model over the vulnerable Coldcard codebase to search for security issues a few weeks before the theft, but the review failed to detect the flaw.
  • ▪The Coldcard incident highlights an asymmetry in AI-assisted security, where defenders must find every vulnerability while attackers only need to find a single exploitable path.

3 sources

Thenationalnews
How a hidden flaw in Coldcard wallets led to an $88.6m Bitcoin theft | The National
View source article
Crypto
Coldcard firmware update requires affected users to move Bitcoin
View source article
Cryptotimes
Coinkite Updates COLDCARD After Seed Flaw Exposed Bitcoin Wallets
View source article

Story comments

Loading comments…

Related Projects

Bitcoin

Topics

Hardware wallet vulnerabilitiesBitcoin security & risksCryptocurrency theftBitcoin wallets & custodyCrypto security