Skip to content
BTC $62,930.00 0.10%ETH $1,855.17 -0.50%SOL $72.5800 -0.50%BNB $576.95 -1.90%XRP $1.0660 0.30%ADA $0.1763 4.30%DOGE $0.0696 -0.50%TRX $0.3280 0.50%LINK $8.1500 -0.30%ZEC $467.37 1.80%XMR $364.15 1.10%XLM $0.1719 -0.20%
as of 02:04 UTCData provided by CoinGecko
Bitcoin News

Coldcard weak seeds: Bitcoin cold storage under fire

Comic illustration of hardware wallet, blank coin, glowing shield, and broken key

Coinkite’s Coldcard hardware wallets are in an active weak-seed event. Maker advisories plus independent engineering analysis say some device-generated seeds used a software randomiser instead of the intended hardware path, and on-chain sweeps tied to those keys have kept moving after the first disclosure.

Bitcoin itself is quiet on the tape. Our CoinGecko market snapshot fetched at 2026-08-02T02:04:45+00:00 shows BTC near $62,930, up about 0.1% over 24 hours. The story that matters for self-custody this weekend is not that range. It is whether “air-gapped” still means what traders thought it meant.

This is a Bitcoin custody story first. Price is context. The seed is the asset.

What happened

Coinkite published a Coldcard security advisory and a matching technical backgrounder, both updated on August 1, 2026. The core claim is blunt: on affected firmware, wallet seed generation could fall through to a MicroPython software random path instead of Coldcard’s hardware RNG wrapper.

Coinkite’s current scope is broader than the first Mk2/Mk3 headlines. The advisory says funds controlled by seeds generated on Mk2 or Mk3 firmware 4.0.1 through 4.1.9 are at risk when the seed lacked at least 50 independent private dice rolls and the wallet lacks a strong unique BIP-39 passphrase. It also says seeds generated on Mk4, Q, and Mk5 before fixed releases are affected, with roughly 72 bits of entropy rather than the expected 128, and it lists fixed firmware for every affected track (including Edge builds).

Important practical line from the maker: updating firmware does not repair an existing seed. Users who generated on vulnerable builds still need a new seed on fixed firmware and a careful migration, unless the dice-entropy exception applies.

Block’s Bitcoin Engineering and Security team published a separate analysis, Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware, and says it is publishing early because exploitation is underway. Block describes the same integration failure: libngu checks whether MICROPY_HW_ENABLE_RNG is defined rather than whether it is enabled, then binds to MicroPython’s deterministic fallback seeded from device and timing state. Block’s table treats Mk2/Mk3 v4.0.0–v4.1.9 as a confirmed vulnerable path with no secure reseed, and flags Mk4/Q/Mk5 constructions where secure-element mixing still leaves a sharply reduced search space.

On the loss side, CoinDesk reported Galaxy Research’s third-wave tracking on August 1: about 208 BTC from 1,912 addresses between Friday midday and Saturday morning UTC, bringing observed totals across three waves to roughly 1,367 BTC (near $89 million at recent prices) from 4,585 addresses. Wave three, per that report, uses harder-to-map destinations and smaller average hauls. Those figures are Galaxy’s chain analysis as relayed by CoinDesk, not an on-chain census we ran ourselves.

Context

Cold storage sells a simple promise: the private key never touches an internet-connected machine, so remote malware cannot steal it. That promise still matters. What this incident attacks is the quieter assumption underneath it: that the device’s seed generation was cryptographically unpredictable in the first place.

If a seed’s search space collapses, an attacker does not need your living room. They need enough constraint on device state, enough compute, and an address or xpub oracle to test candidates. Coinkite estimates about 40 bits of effective search space for affected Mk2/Mk3 paths under current assumptions, and about 72 bits for later models with partial secure-element mixing. Block’s write-up frames Mk4-class devices around a 2^32 ceiling once fallback state and call history are fixed. Different labs are using different models. The shared point is that “hardware wallet” is not a magic noun.

Dice rolls and BIP-39 passphrases sit in the middle of the advisory. Coinkite says at least 50 fair independent private dice rolls hashed into seed creation can put a wallet outside this RNG-only risk. A strong unique passphrase adds another barrier, but Coinkite still tells passphrase users to migrate as soon as practical because the underlying seed remains weak. That nuance matters for anyone reading headlines and freezing.

It also matters for how traders talk about cold wallets and seed phrases. The seed is the wallet. Firmware versions, dice entropy, and passphrase strength are part of the custody stack, not optional folklore. Our wallet safety guide starts from that same premise: verify backups, verify receive addresses on-device, and treat migration as a process you can fail by rushing.

Bitcoin’s broader market is not pricing a systemic chain failure. Spot is still a range story in Bitcoin news terms, and the long cycle still lives on our Bitcoin history page. This is a self-custody stress test layered on top of a calm BTC print.

Our read

My stance: treat every Coldcard seed generated on the advisory’s affected firmware windows as compromised until proven otherwise by Coinkite’s dice exception or a completed migration to a new seed on fixed firmware. Do not wait for a perfect consensus between Coinkite and Block on bit counts. Wait for your funds to sit on a seed that was generated after the hotfix.

I am not reading this as “self-custody failed.” Exchange custody has its own failure modes, and this bug does not make hot wallets safer by comparison. I am reading it as proof that hardware brand trust is not a substitute for entropy provenance. Open-source firmware helped researchers reconstruct the path. It did not stop the bug from shipping for years.

Falsifiable claim: by 2026-08-16T00:00:00Z, the cumulative Bitcoin total attributed by Galaxy Research (as reported by CoinDesk or a later Galaxy primary note) to the Coldcard weak-key sweep waves will remain under 2,000 BTC. If a later wave pushes that running total to 2,000 BTC or more before that timestamp, we will update and treat the remaining vulnerable keyspace as still economically open rather than mostly picked over.

What would change my mind sooner: a Coinkite correction that sharply narrows the Mk4/Q/Mk5 scope with reproducible measurements, or chain evidence that the third-wave pattern is mostly unrelated noise. Until then, I am biased toward migration over debate.

What to watch next

First, Coinkite’s next formal technical review and any change to the affected version tables. The August 1 updates already expanded the practical message. Another revision could still move the edges.

Second, whether Galaxy or another desk publishes a primary dashboard with reproducible address sets. Secondary wave totals are useful, but a cited methodology is better for desk tracking.

Third, firmware adoption and migration mistakes. Rushed seed moves create their own losses. Watch for phishing sites that clone “urgent Coldcard update” language.

Fourth, Bitcoin spot only as a secondary signal. A calm tape near $63,000 does not mean the custody story is priced. It means traders can still ignore it until the next wave prints.

If you hold BTC on a Coldcard seed from the affected windows, the actionable path is already public: install the fixed firmware for your model and release track, generate a new seed, verify backups and addresses, test with a small send, then move the rest. The market can stay quiet. Your seed should not.