Wallets generated by COLDCARD at risk of theft: On 30 July 2026, some Bitcoin users discovered that funds from their COLDCARD wallets had been stolen in a series of unexpected transactions on 29 July. Over the course of the day, a bug was identified in the firmware of the COLDCARD Mk3 that causes wallets to be generated with insufficient entropy. As of this writing, estimated losses exceed 1,000 BTC, a figure that may continue to rise as the situation develops.
A security advisory by Coinkite identified wallets generated by COLDCARD Mk3 using firmware version 4.0.1 (March 2021) or later, including the latest released version, as vulnerable to theft, unless the seed was created with sufficient externally generated entropy (such as 50 or more private dice rolls) or the wallet was additionally encumbered with a strong passphrase. The advisory also identifies seeds generated by Mk4 and Mk5 firmware before version 5.6.0 and Q firmware before version 1.5.0Q as affected.
In a follow-up technical backgrounder, Coinkite attributes the bug to a 2021 code change that unintentionally routed seed generation to a software PRNG, initialized from predictable device-unique values, instead of the device’s hardware RNG. Seeds generated by an affected Mk3 without supplemental dice rolls have roughly 40 bits of effective entropy instead of the intended 128. Seeds from affected Mk4, Mk5, and Q devices are harder to attack because output from a secure element is also mixed in, although an analysis by Block, performed with anonymous researchers and disclosed in coordination with Coinkite, found that only 32 bits of that entropy reach the PRNG state, leaving those seeds still well below the intended security level.
Several developers were able to immediately reproduce the attack with the assistance of frontier AI models, so the vulnerability should be assumed to be under active exploitation. Block’s analysis additionally identifies the older COLDCARD Mk2 running 4.x firmware as affected to the same degree as the Mk3, and notes that other randomly generated secrets, such as paper-wallet private keys and ephemeral seeds, are also affected.
This is an evolving situation, and additional information is likely to emerge after this newsletter’s publication. Readers should monitor Coinkite’s blog and other sources for updates. Bitcoin Optech recommends that COLDCARD users whose wallets may be affected move their funds carefully to an unaffected wallet as soon as possible. Seeds generated on an affected device without supplemental dice rolls should be treated as compromised. Users of Mk4, Mk5, and Q devices should upgrade to fixed firmware before generating any new wallets. Upgrading alone does not make an existing seed safe.
Source
https://bitcoinops.org/en/newsletters/2026/07/31/