Critical Vulnerability in Coldcard Hardware Wallets: 594 BTC Stolen After Years-Long Entropy Flaw
Coinkite confirms seed generation weakness in Mk3, Mk4, Mk5, and Q models dating back to 2021, exposing wallets to brute-force attacks.
By Jane Doe
Published on Jul 31, 2026
⚡ Quick Take
- Coinkite issued an emergency advisory after 594 BTC ($38 million) was swept from 500 Coldcard wallet addresses in a coordinated attack on July 30, 2024.
- The vulnerability affects all Mk3 firmware versions since 4.0.1 (March 2021), plus early versions of Mk4, Mk5, and Q models, reducing entropy from 128 bits to approximately 72 bits.
- Attackers exploited weak device-generated seed phrases to brute-force private keys across 1,324 UTXOs in four consecutive blocks (960188–960191).
- Users are urged to immediately migrate funds to new seeds generated on patched firmware or different devices; multisig and Taproot wallets were not compromised.
What Happened
On July 30, 2024, an automated operation swept Bitcoin from 500 single-signature addresses controlled by Coldcard hardware wallets. The attack, which occurred across four consecutive Bitcoin blocks (960188 through 960191), moved 1,324 unspent transaction outputs (UTXOs) totaling 594.5 BTC—approximately $38 million at the time.
According to Atlas21, a blockchain intelligence firm that documented the incident, the attack showed clear signs of systematic exploitation: the thief knew exactly which addresses were vulnerable and executed the sweep with precision, spending only 0.044 BTC in transaction fees across the entire operation.
The first public warning came from a victim on Reddit who reported that their Coldcard Mk3 had generated a 24-word BIP-39 seed phrase in 2021. Critically, the victim stated the seed had never been entered on a computer or exposed to any online device—undermining the common assumption that such thefts only happen through phishing or malware.
Within hours of the theft becoming public, Coinkite—the Canadian company behind Coldcard—issued an emergency security advisory confirming a fundamental flaw in how certain firmware versions generated cryptographic entropy when creating new wallet seeds.
The Numbers
Distribution of Losses
Key statistics from the attack:
- Median loss per victim: 0.41 BTC
- Victims who lost more than 1 BTC: 110 wallets
- Largest single loss: 29.9 BTC
- Transaction fees spent by attacker: 0.044 BTC total
- Blocks affected: 960188, 960189, 960190, 960191
Methodology Note: How Atlas21 Tracked the Attack
Atlas21 identified the coordinated nature of this attack by analyzing blockchain transaction patterns across four consecutive blocks. The identical timing, systematic address selection, and efficient UTXO consolidation indicated automated exploitation of a known vulnerability rather than individual compromises through phishing or malware.
Why It Matters
This incident exposes a critical failure in hardware wallet security that challenges fundamental assumptions about cold storage.
Hardware wallets like Coldcard are marketed as the most secure method for storing Bitcoin, specifically because private keys are generated and stored entirely offline. Users trust that the device itself will produce cryptographically secure random numbers (entropy) when creating wallet seeds.
The fact that seeds generated on affected Coldcard devices contained only ~72 bits of entropy instead of the standard 128 bits means these wallets were vulnerable to brute-force attacks from the moment they were created—even if users followed every security best practice.
Industry-Wide Implications
- Trust erosion: Hardware wallet manufacturers have long positioned their devices as immune to the software vulnerabilities that plague hot wallets and exchanges. This attack proves that firmware flaws can undermine security at the foundation.
- Dormant risk: The vulnerability existed since March 2021, meaning thousands of wallets created over three years may remain at risk. Many users may not follow security advisories or even be aware their funds are threatened.
- Multisig vindication: No multisig or Taproot wallets were compromised in this attack. This reinforces the argument for multi-signature setups as a defense against single points of failure—including device-level flaws.
- Disclosure timing questions: While Coinkite acted quickly once the theft was public, questions remain about whether the company was aware of the entropy weakness before the attack occurred.
Technical Details
The vulnerability centers on insufficient entropy in the random number generation process used when Coldcard devices create new BIP-39 seed phrases.
What Is Entropy in Cryptocurrency Wallets?
Entropy is the randomness used to generate cryptographic keys. For a 12-word BIP-39 seed phrase, the standard requires 128 bits of entropy, which produces approximately 2128 possible combinations—a number so large that brute-force attacks are computationally infeasible with current technology.
With only ~72 bits of entropy, as Coinkite confirmed in affected devices, the possible combinations drop to approximately 272—still a large number, but within reach of a well-resourced attacker using specialized hardware.
Technical Background: How Much Weaker Is 72-bit Entropy?
The difference between 128-bit and 72-bit entropy is not linear—it's exponential. With 128 bits, an attacker would need to check roughly 340 undecillion combinations (340 followed by 36 zeros). With 72 bits, that drops to about 4.7 sextillion—a factor of roughly 72 quadrillion times easier.
While still large by everyday standards, modern GPU clusters and ASIC miners can perform trillions of calculations per second, making 72-bit security breakable given enough time and resources. The coordinated nature of the July 30 attack suggests the perpetrators had developed custom tools optimized for this exact entropy weakness.
Why Single-Signature Wallets Were Targeted
Single-signature wallets require only one private key to authorize transactions. If an attacker can derive that key through brute force, they gain complete control over the funds.
Multisig wallets, by contrast, require multiple keys from different sources (often different devices or even different manufacturers). Even if one key is compromised due to weak entropy, the attacker cannot move funds without the other keys. This architectural difference explains why no multisig wallets were affected.
Taproot wallets, which use a different key derivation scheme, were also unaffected, suggesting the vulnerability was specific to how legacy and SegWit single-signature keys were generated in the affected firmware versions.
Affected Devices & Firmware Versions
Coinkite's advisory specifies the following affected hardware and firmware:
Critically Affected: Coldcard Mk3
⚠️ Severe Risk: All Coldcard Mk3 devices running firmware version 4.0.1 or later (released March 2021 onwards). Every seed generated on these devices using device-generated entropy is potentially vulnerable.
Seriously Affected: Mk4, Mk5, and Q
- Mk4 and Mk5: Firmware versions before 5.6.0
- Coldcard Q: Firmware versions before 1.5.0Q
Coinkite stated the impact on these models is "less severe but remains serious," without providing specifics on the entropy level or attack feasibility differences compared to Mk3.
Not Affected
According to Coinkite, the following products are not affected because they use different codebases:
- TAPSIGNER
- OPENDIME
- SATSCARD
How to Check Your Firmware Version
On Coldcard devices, navigate to Settings > Advanced > Version Info to display the current firmware version. Compare this against the affected ranges listed above. If your device is running an affected version and you generated your seed using the device's built-in generator (not by importing an existing seed or using dice/external entropy), your funds may be at risk.
What Users Must Do Now
Coinkite provided step-by-step guidance for users to protect their funds. The core recommendation is simple: migrate to a new seed generated on unaffected firmware or a different device entirely.
For Mk3 Users
Since all Mk3 firmware since version 4.0.1 is affected and Coinkite has not released a patched version, Mk3 owners should:
- Obtain an unaffected device (Mk4/Mk5 with firmware 5.6.0+, Coldcard Q with 1.5.0Q+, or a hardware wallet from a different manufacturer)
- Generate a new seed on that device
- Back up and verify the new seed using pen and paper, stored securely offline
- Confirm a new receive address on the device screen
- Send a small test transaction to the new address and verify receipt
- Transfer all remaining funds from the old wallet to the new one
⚠️ Temporary Workaround if Mk3 Is Your Only Device: If you do not have access to another hardware wallet, Coinkite suggests using a strong, unique BIP-39 passphrase (sometimes called the "25th word") as a temporary measure. This adds an additional layer of protection but is not a permanent solution. Carefully verify the wallet fingerprint and receive address on the device before moving funds, and plan to migrate to an unaffected device as soon as possible.
For Mk4, Mk5, and Q Users
- Upgrade firmware first:
- Mk4/Mk5: Install firmware version 5.6.0 or later
- Coldcard Q: Install version 1.5.0Q or later
- Generate a new seed on the updated firmware
- Back up and verify the new seed
- Test with a small transaction before transferring all funds
- Migrate all assets from the old wallet to the new one
Critical Cautions
- Do not rush the transfer without testing. Sending all funds to an incorrectly generated or backed-up address can result in permanent loss.
- Verify every address on the device screen, not on your computer. Malware can alter addresses displayed in wallet software.
- Keep your old seed backed up until you have successfully verified the new wallet and moved all funds. Only then should you securely destroy the old seed backup.
Market Reaction
Despite the scale of the theft—594.5 BTC worth approximately $38 million—Bitcoin's price showed no significant reaction. At the time of the incident, Bitcoin continued trading near $64,000, according to the source.
This muted price response likely reflects several factors:
- Scale relative to daily volume: Bitcoin's daily trading volume regularly exceeds $20–30 billion; a $38 million liquidation, even if sudden, represents a small fraction of normal market activity.
- No exchange or protocol failure: The theft was isolated to a specific hardware wallet vulnerability, not a systemic issue with Bitcoin's network or major custodians.
- Limited contagion risk: Users of other hardware wallets or multisig setups were not affected, containing the impact to a specific user segment.
However, the incident may have longer-term implications for hardware wallet adoption and Coldcard's market position, particularly as competitors and security researchers scrutinize their own entropy generation processes.
What's Next
Coinkite stated that the advisory issued on July 30 reflects its "early analysis" and that a formal technical review will follow. Several key questions remain unanswered:
- Root cause analysis: Coinkite has not yet published a detailed post-mortem explaining exactly how the entropy weakness was introduced in firmware 4.0.1 or why it persisted through subsequent releases.
- Scope of exposure: How many devices and wallets are potentially affected? Given that firmware 4.0.1 was released in March 2021, potentially thousands of users may have generated seeds on vulnerable firmware over a three-year period.
- Attacker identity and methods: The coordinated nature of the sweep suggests sophisticated actors. Whether law enforcement agencies are investigating, and whether any of the stolen funds can be traced or recovered, remains unclear.
- Industry response: Other hardware wallet manufacturers may face increased scrutiny of their own entropy generation. Expect third-party security audits and potentially updated standards for verifiable randomness in consumer devices.
- Legal and reputational fallout: Affected users may seek recourse from Coinkite, though hardware wallet manufacturers typically disclaim liability for losses in their terms of service.
The incident underscores an uncomfortable truth in cryptocurrency security: even "cold" storage relies on trust in the hardware and firmware. True trustlessness may require multisig architectures, reproducible builds, and ongoing third-party verification—practices still uncommon among retail users.
Frequently Asked Questions
Check two things: (1) your device model and firmware version (navigate to Settings > Advanced > Version Info), and (2) how your seed was generated. If you have an Mk3 running firmware 4.0.1 or later, Mk4/Mk5 before version 5.6.0, or Q before 1.5.0Q, and you used the device's built-in seed generator (not dice, external entropy, or an imported seed), your wallet may be vulnerable. Coinkite recommends migrating funds immediately.
No. According to the source, no multisig or Taproot wallets were among the victims. The attack successfully targeted only single-signature wallets, because multisig setups require multiple keys from different sources. Even if one key had weak entropy, the attacker could not move funds without compromising the other keys as well.
Entropy is the randomness used to generate your wallet's seed phrase and private keys. Standard Bitcoin wallets use 128 bits of entropy, creating approximately 2128 possible combinations—far too many for any attacker to guess. Coinkite confirmed that affected Coldcard devices generated seeds with only ~72 bits of entropy (~272 combinations), reducing security enough that a determined attacker with specialized hardware could brute-force the keys.
No. Updating firmware does not fix seeds that were already generated with weak entropy. The vulnerability is permanently baked into any seed created on affected firmware. You must generate a new seed on unaffected firmware (or a different device) and migrate your funds. For Mk3 specifically, Coinkite has not indicated that a patched firmware version is available; the company recommends using a different device or model entirely.
While Coinkite's advisory and Atlas21's analysis did not specify the attacker's exact methods, the coordinated sweep of 500 addresses in four consecutive blocks suggests the attacker developed tools to brute-force private keys generated with weak entropy, then scanned the blockchain for funded addresses matching those keys. The precision and timing indicate this was not a random or opportunistic attack but a deliberate, systematic exploitation of a known vulnerability.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.