Coldcard Hack: Is Your Bitcoin at Risk?
Last reviewed by The Bitcoin Adviser: 1 August 2026, 14:00 AEST
Bitcoin has been stolen from wallets protected by Coldcard-generated seeds after attackers exploited a weakness in the seed-generation process.
Coinkite has acknowledged the issue, released corrected firmware and advised affected users to migrate their Bitcoin.
Updating your device does not repair a seed generated under affected firmware.
Do not ignore the warning. Do not panic into an unsafe move either.
The quick answer
Single-signature
If an affected Coldcard generated the seed protecting your single-signature wallet, treat that wallet as potentially compromised and plan a careful migration.
Multisig
If the affected Coldcard holds one key in a properly constructed multisig vault, that key cannot move the Bitcoin alone. It should still be replaced deliberately.
Do not enter your seed into a website, computer, phone or unsolicited recovery tool.
What happened in the Coldcard hack?
Affected devices generated seeds with less randomness than users expected. That narrowed the number of possible seeds and made affected wallets easier for attackers to crack.
The term “Coldcard hack” is appropriate because the weakness was exploited and Bitcoin was stolen. More precisely, attackers exploited weak seed generation rather than remotely controlling every Coldcard device.
Entropy is the randomness used to create a seed. More independent randomness means a seed is harder to guess or calculate.
Which Coldcard devices are affected?
Critical: The relevant firmware version is the version installed when the seed was generated, not simply the firmware running on the device today.
| Device | Affected seed generation | Fixed firmware |
|---|---|---|
| Mk3 | 4.0.1 through 4.1.9 | 4.2.0 or later |
| Mk4 / Mk5 standard | Before 5.6.0 | 5.6.0 or later |
| Mk4 / Mk5 Edge | Before 6.6.0X | 6.6.0X or later |
| Q standard | Before 1.5.0Q | 1.5.0Q or later |
| Q Edge | Before 6.6.0QX | 6.6.0QX or later |
Coinkite states that affected Mk4, Mk5 and Q seeds contained approximately 72 bits of entropy rather than the expected 128 bits. It describes the impact on those models as less severe than the Mk3 issue, but still serious.
Read Coinkite’s official notice: Coldcard seed-generation warning.
Does updating the firmware fix my existing wallet?
No.
Fixed firmware corrects the generation of new seeds. It does not retroactively add randomness to a seed generated under affected firmware.
An affected existing seed must still be treated according to Coinkite’s migration guidance.
What if I used dice rolls?
Coinkite says that at least 50 fair, private and independent dice rolls added enough independent entropy to address this specific RNG weakness.
Fewer than 50 rolls, uncertain recollection, recorded rolls or rolls that may have been exposed do not meet that exception.
“I think I did some dice rolls” is not sufficient. Do not rely on a vague memory of having entered some dice rolls. If uncertain, migrate.
What if I used a passphrase?
A strong and unique BIP-39 passphrase creates an additional barrier, but Coinkite still recommends migration as soon as practical.
A short, common, patterned, quoted or reused passphrase should not be assumed to provide meaningful protection.
The BIP-39 passphrase is not the device PIN.
What single-signature users should do
- Confirm that the seed was generated on affected firmware.
- Install fixed firmware before generating a replacement seed.
- Create a new independently secured wallet.
- Record and verify the new backup.
- Verify the destination address on the signing device.
- Send a small test transaction.
- Confirm the test arrived in the correct wallet.
- Move the remaining Bitcoin.
- Keep the previous backup until the migration is fully confirmed.
Do not make the first transaction the full balance.
What multisig users should do
An affected key inside multisig should not be ignored.
In a properly constructed 2-of-3 vault, however, one compromised key does not provide enough signatures to move the Bitcoin.
That gives the holder time and structure to replace the affected key or migrate the vault without one device failure automatically becoming a total-loss event.
For TBA clients: Contact your adviser before changing a key or moving funds. Only you can initiate a transaction through your vault platform. TBA will help coordinate the appropriate key replacement or vault migration.
Do not make the situation worse
- Do not enter the seed into a computer, phone or website.
- Do not respond to unsolicited direct messages.
- Do not send seed words to anyone offering support.
- Do not attempt an unfamiliar recovery process under stress.
- Do not destroy the existing backup before the migration is confirmed.
- Do not assume new firmware repaired the old seed.
- Do not treat a passphrase or remembered dice rolls as conclusive without checking the official criteria.
How TBA can help
Moving meaningful Bitcoin after a security incident is not the time to improvise.
The Bitcoin Adviser can help you understand the warning, prepare a safe destination, verify the new structure and move into collaborative security where no single key, device or party can move the Bitcoin alone.
Secure your Bitcoin first. Decide about TBA later.
In response to this incident, the first three months of TBA’s collaborative-security service are free of charge, with no commitment and no early termination fee. This offer is available through August 2026.
Once the Bitcoin is secure, you can decide whether the ongoing service is right for you. If it is not, you can move at any time during the first three months and owe us nothing.
This is not the only safe migration route, and not everyone using Coldcard needs to become a TBA client. See also our hardware wallet security guide, Bitcoin Emergency Kit, and Scope & Risks.
Educational and operational guidance only. Not financial, legal or tax advice. Scope & Risks.
Coldcard hack FAQs
Was Coldcard actually hacked?
Bitcoin has been stolen after attackers exploited weak Coldcard-generated seeds. Coinkite has acknowledged the issue. This was not a remote compromise of every Coldcard device. The weakness reduced the randomness protecting affected seeds, making some wallets materially easier to crack.
Has Bitcoin been stolen?
Yes. Bitcoin has been stolen from wallets protected by Coldcard-generated seeds after the weakness was exploited. Do not treat this as only a theoretical concern.
Is every Coldcard compromised?
No. Impact depends on model, the firmware present when the seed was generated, and whether exceptions such as sufficient independent dice entropy apply. Check the affected ranges above and Coinkite’s official notice.
Is Coldcard Mk4 affected?
Yes, for seeds generated before standard firmware 5.6.0 or Edge firmware 6.6.0X. Updating firmware does not repair those existing seeds.
Is Coldcard Q affected?
Yes, for seeds generated before standard firmware 1.5.0Q or Edge firmware 6.6.0QX. Updating firmware does not repair those existing seeds.
Does updating firmware fix my old seed?
No. Fixed firmware corrects new seed generation. An affected existing seed still requires migration under Coinkite’s guidance unless a stated exception clearly applies.
Am I safe if I used dice?
Only if you clearly meet Coinkite’s criteria of at least 50 fair, private and independent dice rolls. Vague recollection is not enough. If uncertain, migrate.
Am I safe if I used a passphrase?
A strong unique BIP-39 passphrase adds a barrier, but Coinkite still recommends migration as soon as practical. Weak or reused passphrases should not be treated as meaningful protection. The passphrase is not the device PIN.
What should I do if Coldcard is my only device?
Treat an affected single-signature seed as potentially compromised. Prepare a verified replacement destination, test with a small amount, then migrate carefully. Do not enter the seed into unfamiliar tools.
Is my Bitcoin safe if Coldcard is one key in multisig?
One affected key cannot move the Bitcoin alone in a properly constructed multisig vault. The key should still be replaced. Contact your adviser before changing a key or moving funds.
Should I enter my seed into another wallet?
No. Do not enter the seed into a website, computer, phone or unsolicited recovery tool. Follow official vendor guidance and verify the new destination before moving funds.
Can TBA help me move the Bitcoin?
Yes. TBA can help you understand the warning, prepare a safe destination, verify structure and migrate into collaborative security. Only you can initiate a transaction through your vault platform.
Am I committed to staying with TBA?
No. During the August 2026 offer, the first three months of collaborative-security service are free of charge, with no commitment and no early termination fee. Once the Bitcoin is secure, you can decide whether to continue.