What To Do When a Hardware Wallet May Be Compromised
Current hardware-wallet warning: Coldcard seed-generation hack
Bitcoin has been stolen from wallets protected by Coldcard-generated seeds after attackers exploited weak seed generation. Fixed firmware is available, but existing affected seeds still require migration. Status: Active · Fixed firmware available · Migration still required.
A hardware wallet is an important signing device. It is not, by itself, a complete security architecture.
This page is a durable guide for interpreting hardware-wallet, seed, firmware, supply-chain and coordinator warnings when they appear. It is not a list of vendor scandals.
A hardware wallet is one part of the system
A hardware wallet isolates and signs with a private key. It does not eliminate every risk attached to seed generation, backups, firmware, recovery, inheritance or human error.
A device may appear to operate normally while the seed it generated is later found to be weak. Hardware risk can therefore be physical, procedural, supply-chain related, firmware related, seed-generation related or retrospective.
Different flaws require different responses
Device theft or loss
Secure remaining keys and backups. Use documented recovery. Do not improvise seed entry on unfamiliar software.
Exposed seed
Treat the path as compromised. Do not re-enter the seed. Escalate before unfamiliar migration.
Weak seed generation
Firmware updates do not repair historical seeds. Plan migration if the vendor says existing keys are affected.
Malicious or flawed firmware
Use official vendor notices. Updating may fix future behaviour without repairing prior key material.
Supply-chain compromise
Prefer official purchase channels and device provenance records. Review before admitting a key into a vault.
Coordinator or software wallet issue
The signing device is only one layer. Coordinator compromise can still create operational risk.
Outdated firmware
Keep firmware current, then check whether historical keys also need replacement.
Backup or passphrase failure
Protect existing secrets. Do not destroy old backups until a verified migration is complete.
Updating software may not fix historical key material
A firmware update may correct future behaviour without repairing a seed, backup or key created previously.
Read the vendor’s official notice to determine whether key replacement or wallet migration is also required.
The custody structure determines the consequence
In single signature, one compromised seed can provide control of the entire wallet.
In multisig, one compromised key may still require urgent replacement, but it does not necessarily provide enough signatures to move the Bitcoin. One affected key cannot move the Bitcoin alone.
Calm migration principles
- Establish what is affected.
- Use official vendor information.
- Protect existing secrets.
- Prepare the replacement destination first.
- Verify the new backup and address.
- Test with a small amount.
- Move the remainder only after verification.
- Retain the old backup until completion.
- Update documentation after migration.
Educational and operational guidance only. Not financial, legal or tax advice. Scope & Risks. Archived warnings can be listed here when an incident is resolved without rewriting this guide.