Security Centre · Hardware Wallet Security

What To Do When a Hardware Wallet May Be Compromised

Current hardware-wallet warning: Coldcard seed-generation hack

Bitcoin has been stolen from wallets protected by Coldcard-generated seeds after attackers exploited weak seed generation. Fixed firmware is available, but existing affected seeds still require migration. Status: Active · Fixed firmware available · Migration still required.

Read the Coldcard hack guide →

A hardware wallet is an important signing device. It is not, by itself, a complete security architecture.

This page is a durable guide for interpreting hardware-wallet, seed, firmware, supply-chain and coordinator warnings when they appear. It is not a list of vendor scandals.

Doctrine

A hardware wallet is one part of the system

A hardware wallet isolates and signs with a private key. It does not eliminate every risk attached to seed generation, backups, firmware, recovery, inheritance or human error.

A device may appear to operate normally while the seed it generated is later found to be weak. Hardware risk can therefore be physical, procedural, supply-chain related, firmware related, seed-generation related or retrospective.

Response

Different flaws require different responses

Device theft or loss

Secure remaining keys and backups. Use documented recovery. Do not improvise seed entry on unfamiliar software.

Exposed seed

Treat the path as compromised. Do not re-enter the seed. Escalate before unfamiliar migration.

Weak seed generation

Firmware updates do not repair historical seeds. Plan migration if the vendor says existing keys are affected.

Malicious or flawed firmware

Use official vendor notices. Updating may fix future behaviour without repairing prior key material.

Supply-chain compromise

Prefer official purchase channels and device provenance records. Review before admitting a key into a vault.

Coordinator or software wallet issue

The signing device is only one layer. Coordinator compromise can still create operational risk.

Outdated firmware

Keep firmware current, then check whether historical keys also need replacement.

Backup or passphrase failure

Protect existing secrets. Do not destroy old backups until a verified migration is complete.

Firmware

Updating software may not fix historical key material

A firmware update may correct future behaviour without repairing a seed, backup or key created previously.

Read the vendor’s official notice to determine whether key replacement or wallet migration is also required.

Structure

The custody structure determines the consequence

In single signature, one compromised seed can provide control of the entire wallet.

In multisig, one compromised key may still require urgent replacement, but it does not necessarily provide enough signatures to move the Bitcoin. One affected key cannot move the Bitcoin alone.

Migration

Calm migration principles

  1. Establish what is affected.
  2. Use official vendor information.
  3. Protect existing secrets.
  4. Prepare the replacement destination first.
  5. Verify the new backup and address.
  6. Test with a small amount.
  7. Move the remainder only after verification.
  8. Retain the old backup until completion.
  9. Update documentation after migration.

Educational and operational guidance only. Not financial, legal or tax advice. Scope & Risks. Archived warnings can be listed here when an incident is resolved without rewriting this guide.