Coldcard Hacked, 1,367 BTC Lost: Are Hardware Wallets Still Safe?

2026-08-04

Coldcard Hacked, 1,367 BTC Lost Are Hardware Wallets Still Safe.webp

The Coldcard security incident has shaken confidence in independent Bitcoin custody. Approximately 1,367 BTC, worth nearly US$89 million at the time of the incident, was linked to a wave of fund transfers from thousands of addresses allegedly using compromised seeds.

However, the term "Coldcard hacked" needs to be understood precisely. The attackers were not reported to have compromised individual devices, stolen PINs, or penetrated the Bitcoin network.

The main problem lies in the process of forming the seed phrase in certain firmware.

The entropy or randomness of the seed becomes lower than it should be, so some of the seeds have the potential to be reconstructed offline.

Key Takeaways

  • The loss of approximately 1,367 BTC was attributed to a Coldcard seed created using the affected firmware, but the investigation and address attribution are still ongoing.

  • Updating the firmware does not automatically fix the old seed. Users will need to create a new seed on the secure firmware and transfer funds.

  • Hardware wallets are still useful, but security depends on the quality of the seed, firmware, backup process, and storage architecture used.

What Happened in the Coldcard Case?
Coldcard Diretas, 1.367 BTC Hilang Hardware Wallet Masih Aman - image.webp

Source: AI

In late July 2026, security researchers identified a series of suspicious transactions draining Bitcoin from old addresses.

Subsequent estimates linked approximately 1,367 BTC to the incident.

Coldcard is a Bitcoin-specific hardware wallet developed by Coinkite. It's designed to keep private keys offline and supports air-gapped transaction signing.

However, physical protection and internet isolation are not enough if the wallet's master secret is weak from the moment it is created.

Bitcoin Engineering Block stated that there was an error in the integration of the random number generator or RNG in the Coldcard firmware.

The software path uses a deterministic generator as a fallback, instead of relying entirely on the expected cryptographic randomness source.

The analysis was published early because the exploit is believed to be ongoing, so technical details may evolve after further investigation.

Read Also: The Best Crypto Wallets of 2026 to Secure Your Assets!

How Can Coldcard Seed Phrases Be Exploited?

The seed phrase is the root of all private keys and addresses in a wallet.

A secure seed must come from a random number with high entropy, so that the space of possibilities that an attacker must examine is too large to explore.

In the case of Coldcard, the bug made certain processes rely on a pseudo-number generator that could be reproduced if an attacker was able to estimate device information, boot time conditions, and the RNG call history.

On the affected Mk2 and Mk3, the path does not receive sufficient additional cryptographic entropy.

On the Mk4, Q, and Mk5, the device does add entropy from the secure element, but Block's analysis suggests the reseed process only retains 32 bits.

The end result looks random, but the number of possible seeds that need to be tested can be much narrower than normal security standards.

The attacker can then generate candidate seeds offline and match them to the public address or extended public key.

Once the correct seed is discovered, the attacker does not need a physical device or Coldcard PIN to control the Bitcoin.

Register at Bittime to buy Bitcoin easily and safely, always protect your seed phrase and use a wallet that suits your risk profile.

Which Coldcard Models and Firmware Are Affected?

Coinkite states that seeds created on the following configurations should be considered affected:

  • Mk2 and Mk3 with firmware 4.0.1 to 4.1.9.

  • Mk4 and Mk5 before standard firmware 5.6.0 or Edge 6.6.0X.

  • Coldcard Q before standard firmware 1.5.0Q or Edge 6.6.0QX.

The seeds on the Mk4, Mk5, and Q are reported to have around 72 bits of entropy, lower than the 128 bit target.

The risk level is not always the same for every device, but it is still serious enough to require migration.

What matters is not when the device was purchased, but rather the firmware used when the seed was created.

Moving the old seed to another hardware wallet also doesn't solve the problem because the weakness is inherent in that seed.

Exceptions may apply if the seed is generated by at least 50 independent, fair, and secret dice rolls.

A long and unique BIP-39 passphrase also adds a layer of protection, but does not fix a weak seed.

Read Also: Multiple Crypto Wallets: A Safe Strategy to Avoid Losing Assets

Are Hardware Wallets Still Safe?

The answer:can still be a powerful storage method, but is not a guarantee of absolute security.

Hardware wallets protect private keys from computer malware, online credential theft, and some remote attacks.

However, a device remains a system consisting of hardware, firmware, seed generation processes, backup mechanisms, and user behavior.

The Coldcard case illustrates an important difference betweensave seeds offline And produce seeds safely. 

An easily predictable seed is still dangerous thoughnever connected to the internet.

For large Bitcoin holdings, users may also consider multisignature, which uses devices from different manufacturers.

With a 2-of-3 structure, one seed or one problematic device is not automatically enough to move funds.

However, multisig is only effective if the number of secure signers still meets the quorum.

Read Also: ZachXBT Calls All Hardware Wallets "Trash," Suggests a Dedicated iPhone as a Replacement

How to Secure Bitcoin in a Hardware Wallet

Use official firmware and check the signature or hash of the file before installation.

Do not buy used hardware wallets or from unverified sellers.

Create a new seed directly on the updated device.

Do not photograph, type, or store seeds in the cloud, email, messaging apps, or internet-connected devices.

Store physical backups in a location protected from fire, water, theft, and unauthorized access.

If using a passphrase, store it separately and test the recovery process before storing large balances. To reduce the risk of error, make a test transaction of a small amount before moving all the Bitcoin.

Read Also: Phantom Wallet: A Guide to Creating a Crypto Wallet Account

What Should Coldcard Users Do?

Users need to check the model, Standard or Edge firmware path, current firmware version, and, most importantly, the version used when the old seed was created.

Install the official repair firmware first. After that, create a new seed, record and verify the backup, check the wallet fingerprint and recipient address on the Coldcard screen, and then send a small test transaction.

If everything is in order, transfer the remaining balance and keep the old backup until the transaction receives sufficient confirmation.

Don't just update the firmware and then stick with the old seed. Coinkite emphasizes that updates fix the creation of new seeds, not restore the entropy of existing seeds.

Read Also: 4 Best Physical Crypto Wallets to Store Coins Safely

Conclusion

The Coldcard incident isn't proof that all hardware wallets are insecure. This case demonstrates that self-custody security doesn't stop with offline devices.

The quality of the seed generator, firmware audits, device diversification, passphrases, multisig, and migration procedures are just as important as keeping the hardware wallet isolated.

Coldcard users whose seeds were created on affected firmware should not wait for confirmation about whether their addresses have been targeted. Migrating to a new seed is the most relevant protective measure.

bittime biaya withdrawal murah

Let’s start trading crypto with the largest assets, such as BTC/IDR and ETH/IDR, right in the Bittime app.

Bittime is a licensed and regulated Digital Financial Asset Trader (PAKD) supervised by Indonesia’s Financial Services Authority (OJK) — where you can buy Bitcoin in Indonesia and hundreds of other crypto assets starting from just Rp10,000. The registration process is fast, secure, and you can get started today.

Track USDT to IDR conversions and monitor your favorite crypto assets in real time. Everything is available in one crypto investment app that you can download for free on the Play Store

Ready to start? Register now on Bittime and execute your investment strategy with a platform trusted by millions of users in Indonesia.

FAQ

Did all Coldcard users lose Bitcoin?

No. The risk depends on the model, the firmware version when the seed was generated, the use of additional entropy from the die, the strength of the passphrase, and whether the user's address has been targeted.

Is a firmware update enough to secure funds?

Not applicable to old seeds. The update only improves the process for generating subsequent seeds. Funds must be transferred to a wallet with the new seed.

Does moving the Coldcard seed to Ledger or Trezor solve the problem?

No. If the initial seed has weak entropy, the risk remains with the seed even if it is imported to another device.

Does the BIP-39 passphrase protect the wallet?

A strong and unique passphrase adds an independent barrier to attackers. However, users are still advised to migrate, as passphrases don't fix the underlying seed's weaknesses.

Is multisig more secure than a single hardware wallet?

Multisig can reduce single points of failure if signers use secure seeds and multiple devices. Its setup is more complex and requires testing with proper recovery procedures.

Disclaimer: The views expressed belong exclusively to the author and do not reflect the views of this platform. This platform and its affiliates disclaim any responsibility for the accuracy or suitability of the information provided. It is for informational purposes only and not intended as financial or investment advice.

Campaign Deposit Trade
Auto Earn Ramadan

Bittime Blog

What Is Teresa by Virtuals ($TRSA)? AI Futures on Robinhood Chain
What Is Teresa by Virtuals ($TRSA)? AI Futures on Robinhood Chain

Teresa by Virtuals ($TRSA) is an AI trading infrastructure on Robinhood Chain. Learn how it works, its token functions, pricing, and risks.

2026-08-04Read