Coldcard Hack: What Happened, Who Is at Risk, and What to Do

The Coldcard hack was a major cryptocurrency security incident caused by a flaw in how some Coldcard wallets generated seed phrases. The vulnerability made certain seeds predictable, allowing attackers to recreate wallets and steal millions worth of Bitcoin.

The Coldcard hack has left many wondering whether hardware wallets, long considered the safest way to store crypto, are actually just as vulnerable as cold wallets. The problem is serious: attackers have stolen roughly 1,816 BTC, worth about $116 million at the time, from more than 5,200 addresses.

The good news is that you don’t need to guess whether you’re affected. The vulnerability only applies to specific Coldcard seed-generation conditions, and Coinkite has released firmware updates to fix the problem for newly created wallets. However, updating your Coldcard doesn’t fix an existing affected seed.

In this guide, you’ll learn what caused the Coldcard vulnerability, which models and firmware versions are affected, how to check whether your wallet is at risk, and what to do if your seed may be compromised. 

What Happened in the Coldcard Hack?

The Coldcard Hack came down to a problem with how some Coldcard wallets generated their seeds. But to understand what exactly went wrong, we have to start with what a seed phrase is.

Understanding the Basics

A seed phrase (or recovery phrase) is a list of words, usually 12 or 24, that represents a large random number your wallet generates when you set it up. Then, your wallet turns that number into a chain of private keys, and each private key controls a specific Bitcoin address. Whoever has the seed can recreate all of those private keys and spend everything they control, no matter who originally set up the wallet.

Because the seed grants total control, it has to be something nobody else could guess or reproduce. If the process generating the seed has any pattern to it, an attacker doesn’t need your device or your written-down phrase. They can just reproduce the same process and land on the same seed you did.

This is what entropy measures: how much genuine unpredictability is in a number. High entropy means the seed could be one of an astronomically large number of possibilities, too many to realistically search. Low entropy shrinks that possibility down to something an attacker could actually figure out. 

A wallet’s security depends entirely on its seed having enough entropy to make guessing practically impossible, and that’s exactly where Coldcard failed. 

What Should Have Happened?

Normally, a Coldcard generates a new seed using its hardware random number generator, a physical component built to produce numbers that can’t be predicted. That hardware source is what gives the seed its entropy.

What Went Wrong?

What went wrong

In 2021, Coldcard’s developers moved part of the device’s code to a library called libNgU. A mistake in that migration caused some devices to generate seeds using a software pseudorandom number generator instead of the hardware one. 

A software PRNG produces numbers through a mathematical formula rather than a physical, unpredictable process, so it can end up far more predictable, even though the resulting words still look perfectly normal. They still displayed as a normal 12- or 24-word phrase. But the process behind them had much less entropy than intended, shrinking the pool of realistic possibilities.

How the Attack Happened

Once the attackers found that flaw, they could reconstruct that same narrowed pool of seeds without ever touching a physical device. 

They worked through candidate seeds, derived the private keys each one produced, and checked whether any controlled a real Bitcoin balance. A match let them recreate a victim’s keys from scratch and move the funds out.

So the hack wasn’t a stolen phrase or a phishing attack. It was a single code change that swapped secure randomness for weaker randomness, reducing the entropy the whole system relied on and turning an unguessable seed into one attackers could work out on their own.

How Much Bitcoin Was Stolen in the Coldcard Hack?

At the time of TRM Labs’ initial analysis, around 1,816 BTC worth roughly $116 million had been stolen from more than 5,200 Bitcoin addresses. The theft began on July 30, 2026, in multiple waves.

But investigators have continued following where those coins went. Some of the stolen funds have since been moved through crypto mixers, which combine cryptocurrency from different users to make individual transactions harder to trace. Bitquery’s latest tracking shows 136.39 BTC has passed through CoinJoin mixing rounds, while 649 ETH converted from the stolen Bitcoin was sent to Tornado Cash.

That matters because once stolen funds enter a mixer, following the exact path from the original victim wallet becomes significantly more difficult.

Which Coldcard Models and Firmware Versions Are Affected?

If you’re trying to figure out which Coldcard models are affected, start with the firmware version your device was running when you created your seed. That’s more important than the version currently installed on your Coldcard. The table below shows the firmware ranges linked to the Coldcard firmware vulnerability and the versions that fixed the issue.

Coldcard modelAffected firmwareFixed firmware
Mk2/Mk34.0.1–4.1.94.2.0+
Mk4/Mk5Before 5.6.05.6.0+
QBefore 1.5.0Q1.5.0Q+
Mk4/Mk5 EdgeBefore 6.6.0X6.6.0X+
Q EdgeBefore 6.6.0QX6.6.0QX+

The versions in the third column fixed the seed-generation problem. However, newer security updates have since been released. For example, Coinkite released 5.6.2 for Mk4/Mk5 and 1.5.2Q for Q in September 2026. So don’t treat the minimum fixed version as the latest version available. Check Coinkite’s current security information before updating your device.

There’s another detail that’s easy to miss. Updating your Coldcard now doesn’t fix a seed that was already created on affected firmware. The problem happened when the seed was generated. Changing the firmware afterward can’t change how that seed was created.

So if your seed was created while your Coldcard was running affected firmware, you’ll need to check whether it falls within the conditions of the vulnerability. If it does, the next step is to move your Bitcoin to a new, secure seed rather than relying on the firmware update alone.

Is My Coldcard Wallet at Risk?

If you’re wondering whether your Coldcard wallet is affected, the most important thing to know is how and when its seed was created.

Step 1: Was the Seed Generated on a Coldcard?

If you imported an existing seed into your Coldcard, this vulnerability does not apply to that seed. The problem only affects seeds that were generated by a Coldcard.

If your Coldcard generated the seed, the next thing to check is the firmware it was running at the time.

Step 2: What Firmware Was Installed?

Firmware is the software that controls how your Coldcard works. It controls things like how the device generates and manages your wallet.

The vulnerability was caused by a problem in specific firmware. That means the important version is the one installed when you created your seed. Your current firmware does not tell you whether an old seed was affected.

Updating your firmware now is still important. But it only fixes the problem for future seed generation. It cannot change how an existing seed was originally created.

Step 3: Did You Use at Least 50 Dice Rolls?

Coldcard can let you add your own randomness by rolling dice when creating a seed. Each roll adds unpredictable information to the seed-generation process.

This matters because the vulnerability affected the randomness generated by the device. Your dice rolls provide an independent source of randomness.

Coinkite says that at least 50 fair, independent, and private dice rolls are enough to protect a seed from this RNG issue alone.

If you used fewer than 50 rolls, or don’t remember how many you used, treat the seed as potentially affected.

Step 4: Did You Use a BIP-39 Passphrase?

A BIP-39 passphrase is an extra secret that you can add to your seed. It creates a different wallet from the same seed.

This means someone who only discovers your seed cannot automatically access the wallet created with your passphrase. They would also need the passphrase.

But the passphrase does not make the original seed itself more random. If your seed was created under vulnerable conditions, you should still consider migrating to a new seed.

What If You’re Not Sure?

If you cannot confirm how your seed was created, which firmware was installed, or whether you used enough dice rolls, treat the seed as potentially affected.

The solution is to migrate your Bitcoin to a new seed. First, update your Coldcard. Then create a completely new seed under secure conditions. Verify the new wallet and move your Bitcoin to it.

Once the funds are safely transferred, retire the old seed. A firmware update cannot repair an old seed. Migration replaces it with a new one.

Can I Recover the Crypto I Lost in the Coldcard Hack?

If your Bitcoin is still in the wallet, you can protect it by moving it to a new wallet. If it has already been stolen, the process is different.

A new seed cannot bring back Bitcoin that has already been transferred. Bitcoin transactions are generally irreversible, so the focus shifts to tracing the stolen funds and working with authorities and blockchain-forensics firms. 

Read our guide on how to recover stolen or lost crypto for a more detailed explanation of that process.

That process is already underway in the Coldcard case. Blockchain researchers and security firms have been tracking the stolen Bitcoin as it moves between addresses. The latest tracking shows that most of the stolen funds are still sitting in identifiable addresses, while some have been moved through THORChain and CoinJoin transactions to make the trail harder to follow. 

Can I Recover the Crypto I Lost in the Coldcard Hack?

Galaxy Research reported that 97.09 BTC from the third wave had been moved through these routes by September 7.

This does not mean the funds have been recovered. Tracing shows investigators where the Bitcoin moves, but recovery can require identifying the people controlling those funds and involving the relevant authorities or platforms.

If your Bitcoin was stolen, save the affected wallet addresses and transaction records. Report the theft and share those details with investigators. Be especially careful with anyone promising guaranteed crypto recovery. Scammers often target victims after a theft by claiming they can get the money back.

Who Was Behind the Coldcard Hack?

There is still no confirmed identity behind the Coldcard Hack. But investigators now have more evidence that it was not necessarily the work of a single attacker.

What We Know

Galaxy Research initially identified several separate theft waves. As its investigation expanded, it identified at least 33 additional attacker footprints. It has not been able to determine whether all of these attacks were carried out by the same people or by separate groups.

The stolen Bitcoin has also continued to move. Most of it remains in attacker-controlled addresses, but some funds have been routed through THORChain and CoinJoin transactions to make the trail harder to follow. 

On September 7, Galaxy reported that the attacker behind the third wave had moved about 45% of that wave’s stolen funds through these methods.

Blockchain investigators have shared identified attacker addresses with exchanges, compliance firms, and law enforcement so the funds can potentially be flagged or frozen if they reach a regulated service.

Frequently Asked Questions

Are Coldcard Multisig Wallets Affected?

Yes. A multisig wallet can still be at risk if one or more of its keys were created under the affected conditions. Multisig does not automatically protect a compromised key. The risk depends on how many keys are required to spend the Bitcoin and how many of those keys may be affected.

Is Self-Custody Safe?

Self-custody can be safe, but it means you’re responsible for protecting your own keys. The Coldcard Hack is a reminder that even a hardware wallet can have software or firmware flaws. Using a reputable device, keeping its firmware updated, verifying wallet backups, and following proper migration procedures all reduce your risk. No hardware wallet is completely risk-free.

Is Trezor Safe?

Trezor devices were not affected by the Coldcard vulnerability. Trezor says its devices don’t use Coldcard’s firmware or code, and wallets originally created on Trezor aren’t affected by this incident.

However, if you originally created your wallet on an affected Coldcard and later restored that same wallet on a Trezor, moving it to Trezor doesn’t fix the problem. You’d need to create a new wallet and move your Bitcoin to it.

Is Ledger Safe?

Ledger says its devices were not affected by the Coldcard vulnerability. Ledger devices use a hardware true random number generator built into their Secure Element for seed generation.

That doesn’t mean Ledger or any other hardware wallet is guaranteed to be vulnerability-free. It means this specific Coldcard seed vulnerability doesn’t affect Ledger devices.

Check out our full list of the best hardware wallets after the Coldcard hack for more.