Coldcard seed bug: what happened and how to check your funds
Based on verified official data as of 31.07.2026; hands-on update coming.
On 31 July 2026, Coinkite disclosed that Coldcard hardware wallets running firmware 4.0.1 (March 2021) or later on the Mk3 generated seeds using predictable, chip-data-seeded key generation instead of true randomness. Attackers drained roughly 500 wallets holding about 600 BTC (~$40 million) in minutes. If you created a seed on an affected device, updating firmware does not fix it - you must generate a brand new seed on a safe device and migrate funds. Any wallet that imported a vulnerable seed is also at risk.
TL;DR
- Coinkite warns all users who generated a seed on a Mk3 running firmware 4.0.1 (March 2021) or later that their funds may be at risk.
- Around 500 wallets holding ~600 BTC (~$40M) were drained in minutes; single-signature setups were most exposed.
- Firmware updates do NOT repair an affected seed - a new seed must be generated and funds migrated to a fresh wallet.
- The flaw spreads: any other wallet that imported a vulnerable Coldcard seed carries the same weakness (per Block researchers).
- The Bitcoin price stayed above its ~$60,000 support after the news, but some commentators fear a slide toward $58,000.
What actually broke in the Coldcard firmware
Coldcard is a bitcoin-only hardware wallet from Canada-based Coinkite. It keeps private keys offline, uses dual secure elements and supports air-gapped signing. The security model depends on one thing above all: the seed phrase must be generated from genuine randomness so nobody can guess it.
That is where the bug sits. According to Coinkite, Mk3 devices on firmware 4.0.1 (March 2021) and later used a predictable software-based key generation process seeded by chip data instead of a strong randomness generator. Predictable seeds mean an attacker who works out the pattern can reconstruct the private keys and move the coins without ever touching the device.
Coinkite says it was unaware of the bug until the day of disclosure. Attackers drained around 500 wallets, mostly single-signature setups, in a matter of minutes - roughly 600 BTC worth about $40 million at the time.

Am I affected? Quick decision table
The trigger is when and where your seed was generated, not which firmware you run today. If your seed came from an affected Coldcard, upgrading firmware afterwards does nothing to fix it. The same weak seed also poisons any other wallet you imported it into.
Use the table below as a first pass, then read Coinkite's own blog post before acting. Do not assume a multisig setup makes you safe if one of the keys was generated on an affected device.
| Your situation | At risk? | Action |
|---|---|---|
| Seed generated on Mk3, firmware 4.0.1+ (March 2021 or later) | Yes | Generate a new seed on a safe device, migrate funds |
| Seed generated before firmware 4.0.1 | Per Coinkite guidance, verify | Confirm generation source before assuming safe |
| Imported an affected Coldcard seed into another wallet | Yes | Same seed is still weak; migrate to a fresh seed |
| Multisig where one key came from an affected device | Partially | Rotate the affected key on a safe device |
| Seed generated on a different brand / unaffected device | No (from this bug) | No action needed for this issue |
How to migrate without making it worse
Coinkite's advice is blunt: proceed calmly and verify every step. Rushing a migration can create a more immediate risk than the bug itself - a typo in a new address or a bad backup can lose everything instantly.
The correct sequence is to generate a fresh seed on a device you trust, write down and verify the backup offline, confirm the receive address on the device screen, then move funds in a deliberate transaction. Send a small test amount first, confirm it arrives, then move the rest.
Do not simply update the firmware and stop. Updating does not repair a seed that was already generated by affected firmware. The compromised seed stays compromised until every coin has been moved to a wallet built from new, safe entropy.
The AI-assisted attack angle
Part of what alarmed the community was speed and timing. A pseudonymous onchain analyst using the handle @Pledditor wrote on X that the exploit is public, attention is on it, and everybody has access to frontier large language models, so dozens of teams could now be racing to exploit it.
Cobra, the pseudonymous co-owner of Bitcoin.org, posted that he had a bad feeling AI was involved in the drain and warned the price could fall toward $58,000 once mainstream media pick it up. These are opinions, not confirmed findings, and no attribution to any AI tool has been verified.
The wider lesson is about custody hygiene rather than any single brand. Self-custody removes counterparty risk but hands you full responsibility for entropy, backups and firmware. That trade-off is the same one we flag across our self-custody and no-KYC hub coverage: fewer intermediaries, more to get right yourself.
Did it move the Bitcoin price?
The Bitcoin price dropped in the hours after the attack was discovered but held above its key $60,000 support level, according to Forbes. Some commentators fear the news could push it toward the $58,000 level last seen at the end of June.
As of this writing, that lower move has not happened, and any forecast of a crash is speculation. A $40 million theft is severe for the affected holders but small against Bitcoin's total market. Price reaction depends far more on broader flows than on one wallet incident.
For anyone spending crypto through a card, this changes nothing about card mechanics but everything about where you park long-term holdings. Keep spending balances small and custody the bulk on hardware you have verified is unaffected.
Risk warning: derivatives and crypto-backed credit involve significant risk, including liquidation of your collateral. Never commit funds you cannot afford to lose. Nothing on this page is financial, investment or tax advice.
Who this is NOT for
- Coldcard owners who need a step-by-step firmware recovery walkthrough - always follow Coinkite's official post, not a third-party summary.
- Traders looking for a price prediction; the $58,000 figure here is a quoted opinion, not a forecast.
- People wanting confirmation that AI caused the exploit - that claim is unverified speculation.
- Exchange-only users with no hardware wallet - this specific bug does not affect you.
Frequently asked questions
Coinkite is warning users who generated a seed on a Mk3 running version 4.0.1 (March 2021) or any later version. The risk attaches to when and where the seed was created, not the firmware you happen to run now.
NomadCrypto Editor
Editorial Team, NomadCard
The NomadCrypto editorial team verifies every published fee across 59 crypto cards against issuer documentation, with the verification date shown on every figure.