Coldcard’s Five-Year Entropy Failure Put an Estimated $116m in Bitcoin Within Reach

For years, the hardware-wallet pitch has been simple: keep the keys offline and the internet cannot get them. Coldcard built much of its reputation on that premise. This week, a flaw in the way some Coldcard devices generated wallet seeds exposed the uncomfortable limit of the slogan: an offline device is not much help if the secret it creates was never sufficiently random.

By 3 August, researchers were linking four waves of Bitcoin theft to the vulnerability. The current estimate is about 1,816 BTC — roughly $114m to $116m at the time of reporting — taken from more than 5,200 addresses since 30 July. The figure is still evolving, and the latest wave was identified through on-chain pattern matching rather than confirmed victim reports. But the underlying defect is no longer speculative. Coldcard maker Coinkite has published an emergency advisory, released fixed firmware and told users with affected seeds to migrate.

Not a stolen device, not a phishing page

The notable part of the incident is what apparently did not happen. There was no requirement to steal a Coldcard device, coerce its owner into revealing a recovery phrase, or compromise a computer connected to it.

According to Coinkite, certain firmware versions generated seeds with materially weaker randomness than intended. A seed phrase is the master secret from which a wallet’s keys are derived. Its security depends on there being too many possible combinations for an attacker to search. Reduce that uncertainty enough, however, and an attacker can recreate likely seeds offline, derive their addresses and look for wallets containing Bitcoin.

That is why this is more serious than a conventional wallet-drain story. In many crypto thefts, the attacker first has to reach the victim: a malicious approval, a fake support agent, a poisoned browser extension. Here, the weakness sat at the beginning of the custody chain. The device could remain in a drawer, never plugged into a computer, while an attacker worked externally against the quality of the seed it had created years earlier.

A 2021 error with a 2026 bill

Coinkite says the issue affects Mk2 and Mk3 devices running firmware versions 4.0.1 through 4.1.9, a range beginning in March 2021. It also affects seeds generated on Mk4, Mk5 and Q devices before the company’s fixed firmware releases. For those later models, Coinkite says the affected seeds contained about 72 bits of entropy rather than the expected 128 bits.

That distinction matters. The company does not say every Coldcard user is exposed in the same way. Users who added at least 50 fair, independent and private dice rolls when creating a seed are outside this particular exposure, according to its advisory. A strong, unique BIP-39 passphrase adds another barrier too, though Coinkite still recommends migration. TAPSIGNER, OPENDIME and SATSCARD are not affected, it says, because they use different codebases.

But the most important operational point is brutally simple: a firmware update cannot repair a seed generated under flawed conditions. The software can be fixed for future wallets; the old secret remains the old secret. Coinkite’s guidance is therefore to update, generate a fresh seed and migrate funds carefully after verifying the new wallet.

The first sweep was alarmingly efficient

The initial on-chain episode supplied the scale. Galaxy Research linked a 30 July sweep of 1,196 addresses to the flaw, with 1,082.65 BTC — approximately $70.2m at the time — drained in 41 minutes. CoinDesk reported that two further waves lifted observed losses to about 1,367 BTC across 4,585 addresses before a possible fourth wave emerged.

That fourth wave is where precision matters. CoinDesk reported that the transactions appeared to use Bitcoin’s replace-by-fee mechanism. In theory, an owner who spotted a still-unconfirmed theft transaction could broadcast a replacement transaction with a higher fee and move the coins first. That narrow window is not a remedy for the design failure, nor proof that every suspected transaction belongs to the same attacker. It is an illustration of how little time affected holders may have once a wallet has been found.

Attribution is also unresolved. No public evidence currently identifies the person or group responsible. The on-chain behaviour may strongly connect the sweeps to a vulnerable seed-generation population; it does not establish who ran the operation.

Self-custody is not a product category

The instinctive reaction will be to recast this as an argument against self-custody. That is too neat. The real lesson is harsher and more useful: self-custody is a chain of engineering assumptions, not a purchase made at checkout.

Secure hardware, air-gapped signing and open-source scrutiny are valuable. Yet none can compensate for a foundational failure in entropy generation. The wallet screen may show a recovery phrase, but the relevant question is whether that phrase was created from enough unpredictable information to make it irrecoverable by anyone else.

Coldcard’s response deserves attention precisely because it is concrete. The company has identified affected firmware ranges, published replacement versions, explained the limits of updating and set out migration guidance. What remains unresolved is the human aftermath: how many holders generated vulnerable seeds, how many still hold funds, and how quickly attackers can identify them.

A cold wallet can protect a key from the internet. It cannot protect a key from being insufficiently random at birth.

Sources: Coinkite security advisory; CoinDesk; Fortune; The Hacker News.

This article is for information purposes only and should not be considered trading or investment advice. Nothing herein shall be construed as financial, legal, or tax advice. Bullish Times is a marketing agency committed to providing corporate-grade press coverage and shall not be liable for any loss or damage arising from reliance on this information. Readers should perform their own research and due diligence before engaging in any financial activities.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top