Full story
Coldcard seed flaw exploited
A software bug in Coldcard hardware wallets allowed attackers to recreate wallet recovery phrases and steal bitcoin from users who believed their funds were securely self-custodied.
“"If you generated a seed using a Coldcard wallet, move your funds now"”
Coinkite CEO NVK urged affected customers to act immediately, writing, "If you generated a seed using a Coldcard wallet, move your funds now," and he said the fix protects new seeds going forward but does not fix seeds already generated on vulnerable firmware.

AMBCrypto said an attacker drained about 594 BTC worth over $38 million from 500 Coldcard wallets within about 15–25 minutes, exploiting a Coldcard Mk3 seed generation flaw that made some Mk3 recovery phrases predictable due to weak entropy.
The incident has been described as a key-generation stage compromise, with Blockaid co-founder and CEO Ido Ben-Natan saying, "Coldcard fits that pattern, with the exposure originating at the key generation stage."
Calls to migrate, blame
In the wake of the exploit, Coinkite’s guidance emphasized that updating firmware alone does not eliminate the risk for seeds already generated on vulnerable devices, and it advised users to create entirely new wallets and move funds onchain.
Bitcoin Magazine reported that Coinkite’s updated advisory said, "Fixed firmware is now available," and it specified that Mk4 and Mk5 users must update to version 5.6.0 or later while Mk3 users must update to version 4.2.0 or later.

Taproot developer Udi Wertheimer argued that security is not something holders can set up once and forget, writing on X, "The idea of your bitcoin resting easy in some secret location while you enjoy life not worrying about it is currently unrealistic."
Galaxy Research’s analysis, as summarized by Forbes, said it identified 1,596 bitcoin valued at about $102 million as of Tuesday that had been stolen from more than 7,300 crypto wallets across three confirmed waves and 14 smaller incidents.
Losses mount, legal risk
As investigators continued to compile victim addresses, multiple outlets put different totals on the theft, with Fox Business citing roughly $70 million in less than an hour and saying researchers at Galaxy Research drained more than 1,000 bitcoin from 1,196 digital wallets in just 41 minutes on July 30.
“drained more than 1,000 bitcoin from 1,196 digital wallets in just 41 minutes”
Cointribune said losses estimated at more than $88 million in Bitcoin prompted victims to prepare a legal response, adding that Coinkite could face a class action after the loss of more than 1,300 BTC attributed to the vulnerability.
The same Cointribune report quoted Thomas Braziel, founder and managing partner of 117 Partners, coordinating the collection of information from victims across several countries to assess legal options including a product liability action or a class action against Coinkite.
For affected users, the immediate consequence described across coverage was the need to migrate funds to newly generated wallets, because Coinkite warned that "Updating the firmware does not repair a seed that was generated by affected firmware" and that "A new seed must be generated and the funds migrated to the new wallet."
