FacebookTwitterLinkedInTelegramCopy LinkEmail
Crime and Investigations

Coldcard Warns Users to Move Bitcoin After Firmware Flaw

Coldcard Warns Users to Move Bitcoin After Firmware Flaw

Coldcard manufacturer Coinkite has urged some customers to move their Bitcoin after discovering a firmware vulnerability that weakened the randomness used to generate wallet seed phrases, potentially making affected wallets vulnerable to recovery by attackers.

Summary:

  • Coldcard has urged affected users to migrate their Bitcoin after identifying a firmware flaw in wallet seed generation.
  • The vulnerability reduced randomness during seed creation on certain devices, potentially exposing wallets to brute-force attacks.
  • Researchers separately traced the theft of nearly 594.5 BTC, though no confirmed link to the firmware issue has been established.
  • Users who relied on manual dice rolls or a BIP-39 passphrase are believed to face little or no additional risk.

The advisory from 30th July applies primarily to Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3, as well as certain seed-generation configurations on older Mk4, Mk5 and Q firmware. The company said users who generated wallets using the affected firmware should create a new seed on a verified device and transfer their funds as soon as practical.

Firmware Bug Reduced Cryptographic Security

According to Coldcard post in X, the issue stems from how affected firmware generated wallet entropy during initialization.

Instead of relying exclusively on the hardware’s true random number generator, some firmware versions could fall back to a weaker pseudo-random number generator under specific conditions. That significantly reduced the effective randomness protecting newly generated seed phrases, making them substantially easier to recover through automated brute-force techniques than properly generated wallets.

The vulnerability affects seed generation rather than transaction signing or private key storage. Existing wallets are only considered at risk if their recovery phrases were originally created under the vulnerable firmware conditions.

Affected Devices Status
Coldcard Mk3
Firmware 4.0.1–5.0.3 affected
Coldcard Mk4
Certain older firmware configurations affected
Coldcard Mk5
Certain older firmware configurations affected
Coldcard Q
Certain older firmware configurations affected
Protected Users
Wallets created with manual dice rolls or a BIP-39 passphrase 

Separate $38 Million Theft Remains Under Investigation

The disclosure coincided with a large Bitcoin theft that has drawn attention across the security community.

Blockchain researcher Rob Hamilton tracked the theft of approximately 594.48 BTC, worth roughly $38 million, after an attacker drained nearly 500 single-signature wallets over a period of about 30 minutes. Most of the stolen funds – around 562 BTC -were subsequently consolidated into a single address.


READ MORE: Three DeFi Exploits Expose Growing Security Weaknesses


Despite the timing, security researchers have not established that the theft resulted from the Coldcard vulnerability. The two events remain separate, and investigators have not publicly identified the attack method used in the theft.

Who Should Move Their Bitcoin

The warning primarily applies to users who created recovery phrases directly on affected Coldcard devices without adding additional entropy during wallet setup.

Users who generated seeds using manual dice rolls bypassed the vulnerable random number generation process, while those who protected wallets with a BIP-39 passphrase gain an additional cryptographic layer that security researchers believe largely mitigates the weakness.

For users whose wallets may be affected, the recommended response is to generate a new recovery phrase on verified firmware or another trusted hardware wallet, confirm the destination with a small test transaction and then transfer the remaining balance.

The incident serves as a reminder that hardware wallet security depends not only on physical device protection but also on the quality of the cryptographic processes used when wallets are first initialized. Even when private keys never leave a device, weaknesses in random number generation can undermine the security assumptions on which self-custody depends.


The information presented in this article is intended for informational purposes only and should not be interpreted as financial, investment, or trading advice. Coinspress.com does not promote or advocate for any particular investment strategy, asset, or cryptocurrency project. Cryptocurrency markets are highly volatile and unpredictable – always perform your own research and seek guidance from a qualified financial professional before making any investment decisions.

Author
Alexander Stefanov - Editor-in-Chief at Coinspress
Alexander Stefanov

Reporter at CoinsPress

Alex is Editor-in-Chief of Coinspress and co-founder of Millennial Media Group, with nearly a decade of experience covering financial markets - crypto first, then everything else. It started in 2016 with Bitcoin. Like most people at the time, he didn't fully understand it - so he kept digging. Blockchain, tokenomics, the projects, the cycles. That curiosity never stopped, and eventually pulled him into traditional markets too: equities, commodities, macro. Not because he left crypto behind, but because you can't properly understand one without the other. What drives him is straightforward: he wants to know why something is happening, not just that it's happening. Most market coverage stops at the headline - price up, price down, here's a chart. Alex finds that kind of reporting actively unhelpful. If you walk away from an article without understanding the mechanism behind the move, what did you actually learn? He holds a degree in Tourism from New Bulgarian University - not the most obvious path into financial markets, but markets have a way of pulling in people who are simply too curious to stay out. He has authored over 200 in-depth analyses and more than 10,000 articles across crypto and traditional finance. He still thinks every day in markets teaches him something new. That's probably why he hasn't stopped.

Learn more about crypto and blockchain technology.

Glossary