top of page
Token Trace Logo
Search

Coldcard Wallet Vulnerability Reportedly Linked to $70 Million Bitcoin Theft

  • Writer: Token Trace
    Token Trace
  • Aug 2
  • 6 min read

A recently disclosed vulnerability affecting certain Coldcard hardware wallets has been linked to the rapid movement of more than $70 million in Bitcoin.


According to reporting published by The Hacker News, an unidentified operator moved approximately 1,082.65 BTC from 1,196 Bitcoin addresses in a period of just 41 minutes on July 30, 2026. Researchers have connected the unusual transaction pattern to a flaw in how certain Coldcard devices generated cryptocurrency wallet seed phrases.


While the incident remains under investigation, it highlights an important reality for cryptocurrency users: a hardware wallet can protect private keys from many common threats, but it still depends on the security of the software used to create those keys.


What Was the Coldcard Vulnerability?

When a cryptocurrency wallet is created, the device generates a seed phrase—typically a sequence of 12 or 24 words.


That phrase is used to derive the wallet’s private keys. Anyone who obtains or successfully reconstructs the seed phrase can control the associated cryptocurrency.

Seed phrases are therefore supposed to be generated using highly unpredictable, cryptographically secure random numbers.


In the affected Coldcard firmware, a software integration error reportedly caused the wallet-generation process to rely on a deterministic pseudorandom number generator rather than the device’s intended hardware random-number generator.

The flaw was introduced in firmware released around March 2021.

In simple terms, some Coldcard devices may have created seed phrases that looked random to the user but were generated from a substantially narrower and more predictable range of possibilities.


How Could an Attacker Exploit This?

An attacker would not necessarily need to possess the hardware wallet, infect the victim’s computer or obtain a photograph of the seed phrase.

Instead, the attacker could attempt to reproduce the wallet’s seed-generation process on their own systems.

Researchers indicated that the vulnerable process relied on information including:

  • A unique identifier associated with the device

  • The device’s timer state

  • The number and sequence of previous random-number requests

If an attacker could determine or sufficiently narrow those variables, they could generate possible seed phrases offline.


They could then derive the Bitcoin addresses associated with each possible seed and compare them with addresses visible on the public Bitcoin blockchain.

Once a candidate seed produced a matching address, the attacker could derive the corresponding private keys and transfer the Bitcoin.

This is effectively a highly targeted form of seed-phrase guessing made possible by weak randomness.


The Reported $70 Million Bitcoin Sweep

Researchers identified a coordinated sweep on July 30 in which approximately:

  • 1,196 Bitcoin addresses were emptied

  • 1,082.65 BTC was transferred

  • Approximately $70.2 million in Bitcoin was moved

  • The activity occurred within roughly 41 minutes


Bitcoin being swept from multiple wallet addresses into a single destination address.

The transactions reportedly shared distinctive characteristics, including the same transaction fee rate and a pattern in which the entire available balance was moved without creating a change output. These characteristics suggest that the transfers may have been coordinated by a single operator. However, an important distinction remains.


No publicly available report has yet demonstrated the reconstruction of a specific victim’s Coldcard seed phrase and conclusively matched it to one of the affected addresses. Researchers have therefore linked the activity to the vulnerability based on timing and transaction patterns, but the connection has not been publicly proven for every affected wallet.


On the blockchain, an unauthorized wallet sweep may look identical to a legitimate owner consolidating or transferring their own Bitcoin.


Which Coldcard Devices May Be Affected?

The relevant question is not simply which firmware is installed on the device today.

Exposure depends on which firmware was installed when the seed phrase was originally generated.

The reported affected versions include:

  • Coldcard Mk2 and Mk3 devices running certain 4.0.x and 4.1.x firmware versions

  • Coldcard Mk4 and Mk5 seeds created before standard firmware version 5.6.0

  • Coldcard Q seeds created before standard firmware version 1.5.0Q

  • Certain older Edge firmware releases

Coinkite released emergency firmware updates for the affected Coldcard models on July 31, 2026.


Updating the Firmware Is Not Enough

Installing corrected firmware should prevent a device from generating another seed through the vulnerable process.


It does not, however, make an existing seed phrase more secure.

If a seed was generated using affected firmware, restoring that same seed on an updated Coldcard, or importing it into a different hardware or software wallet, does not remove the underlying weakness. The seed itself may still be reproducible.


Affected users should therefore consider generating an entirely new seed phrase using corrected firmware and moving their Bitcoin to addresses controlled by the new seed.

A cautious migration process may include:

  1. Updating the Coldcard to the corrected firmware.

  2. Generating a completely new seed phrase.

  3. Recording and securely backing up the new phrase.

  4. Confirming the new receiving address directly on the hardware wallet screen.

  5. Sending a small test transaction.

  6. Moving the remaining Bitcoin after confirming the test transaction.

Users should carefully follow official manufacturer guidance before taking action.


What About Dice-Generated Seeds and Passphrases?

Coldcard allows users to contribute their own randomness by rolling physical dice during wallet creation.

Coinkite has stated that a seed generated with at least 50 fair, independent and privately conducted dice rolls should not be exposed to this specific vulnerability. Users who are unsure how many rolls they completed—or whether the process was performed securely—have been advised to migrate to a new seed.


A strong and unique BIP-39 passphrase may also provide an additional layer of protection because it creates a separate wallet that cannot be accessed using the seed words alone. Nevertheless, the manufacturer reportedly still recommends replacing a potentially affected seed rather than relying solely on the passphrase.


Why This Incident Matters

Hardware wallets are generally designed to isolate cryptocurrency private keys from internet-connected devices. They can provide meaningful protection against malware, phishing and unauthorized computer access. However, hardware wallets are not immune from software defects.


A wallet can remain completely offline and still be vulnerable if the original seed phrase was created using insufficient randomness. This incident also illustrates why cryptocurrency theft investigations can be difficult. Blockchain records may clearly show when and where funds moved, but they do not automatically reveal:

  • Whether the transaction was authorized

  • How the private keys were obtained

  • Whether the seed phrase was stolen or reconstructed

  • Who controlled the receiving wallet

  • Whether the funds eventually reached an identifiable exchange or service


Those questions often require a combination of blockchain analysis, device examination, cybersecurity review and information obtained from cryptocurrency service providers.


What Should Potentially Affected Users Do?

Anyone who generated a seed phrase using an affected Coldcard firmware version should review the official Coldcard security notice and firmware guidance.

Users should also:

  • Avoid sharing their seed phrase with anyone offering assistance

  • Be cautious of unsolicited “recovery” services

  • Never enter the seed phrase into an unfamiliar website or application

  • Preserve transaction records if funds have already moved

  • Record relevant wallet addresses, transaction hashes and device information

  • Report unauthorized transactions to appropriate law-enforcement agencies


Victims of cryptocurrency theft are frequently targeted again by individuals claiming they can recover stolen assets for an upfront payment. No legitimate blockchain investigator can guarantee that cryptocurrency will be frozen or recovered.


Final Takeaway

The Coldcard vulnerability was not a weakness in Bitcoin’s blockchain or cryptographic protocol.


It was reportedly a failure in the process used by certain wallet firmware to create the secret information controlling the Bitcoin.


The device was intended to generate a seed phrase from an extraordinarily large number of unpredictable possibilities. Because of the software error, some seeds may have been drawn from a much smaller and more reproducible set.


For affected users, simply updating the hardware wallet may not be sufficient. A new seed generated through corrected firmware—and a transfer of the assets to that new wallet—may be necessary.

The incident serves as a reminder that cryptocurrency security depends not only on protecting a seed phrase after it is created, but also on whether that seed was generated securely in the first place.


About Token Trace

Token Trace is a forensics and investigations firm that helps individuals, law firms, investigators, businesses, and compliance teams understand complex cryptocurrency activity.


Our work includes tracing stolen or disputed digital assets, identifying exposure to exchanges and other virtual asset services, monitoring wallet activity, and converting technical blockchain data into clear, practical reporting.


Token Trace supports matters involving cryptocurrency theft, fraud, disputes, asset recovery efforts, litigation, and compliance reviews.

 
 
bottom of page