Full story
Coldcard seed theft
A firmware bug in Coldcard hardware wallets let attackers recreate wallet recovery phrases and drain bitcoin from self-custody devices, with one report saying an attacker drained about 594 BTC worth over $38 million from 500 Coldcard wallets within about 15–25 minutes on July 30.
“an attacker drained about 594 BTC worth over $38 million from 500 Coldcard wallets within about 15–25 minutes”
Coinkite CEO NVK told users in an open letter, "Move your funds now," after the flaw was patched but the fallout continued because updating firmware alone did not eliminate the risk for seeds already generated on vulnerable firmware.

A separate account said the sweep ended at 21:56 ET on Thursday night and that the attacker drained roughly 594 bitcoin from around 500 Bitcoin wallets, with 562 BTC ultimately consolidated into a single address that had not moved as of the time of writing.
AMBCrypto described the mechanism as a Coldcard Mk3 seed generation flaw that made some Mk3 recovery phrases predictable due to weak entropy, shrinking the number of guesses from 340 undecillion combinations to a few billion.
The same AMBCrypto report said that seeds generated on Mk4, Q, and Mk5 before the fixed firmware release were affected too, while other Coinkite hardware signers such as TAPSIGNER, OPENDIME, and SATSCARD remained unaffected.
AI, entropy, and debate
Security and industry voices framed the Coldcard incident as more than a single product failure, with Taproot developer Udi Wertheimer writing on X that "The idea of your bitcoin resting easy in some secret location while you enjoy life not worrying about it is currently unrealistic."
Blockaid co-founder and CEO Ido Ben-Natan said the incident highlights that "A hardware wallet's security ultimately comes down to the firmware and systems users interact with but never see," pointing to upstream safeguards before users take control.

Bitcoin Magazine said Coldcard MK3 devices with firmware version 4.0.1 through 4.1.9 were the worst affected, and it warned that 12- or 24-word seeds generated without user-generated dice rolls or a BIP 39 extra passphrase were vulnerable.
The same Bitcoin Magazine account quoted Coinkite’s updated July 31, 2026 advisory timing, including that "Mk4 and Mk5 users must update to version 5.6.0 or later" and that "For Mk3, update to version 4.2.0 or later."
In a separate explanation, Decrypt said Coinkite suspected the issue was found by machine and wrote, "We have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue," while also stating that fixed firmware does not repair existing seeds.
Migration, losses, and lawsuits
As losses and totals expanded across multiple waves, Galaxy Research was cited as tracking "1,596 BTC stolen from roughly 7,300 addresses" across three confirmed waves, with a suspected fourth wave that could lift the total to roughly 2,055 BTC.
“"1,596 bitcoin stolen from roughly 7,300 addresses"”
CBC reported that Coinkite warned users to move funds after releasing firmware updates, and it quoted Coinkite’s Rodolfo Novak advising anyone who has generated a seed using a Coldcard wallet to "move your funds now."
Cointribune said Coinkite faces a sweeping class-action lawsuit after losses estimated at more than $88 million in Bitcoin, and it described Thomas Braziel as coordinating the collection of information from victims across several countries.
The same Cointribune account quoted Felipe Ojeda describing his experience as, "It was a 'spiritual guide' wallet, which only receives payments, and I kept it completely offline," before saying he filed a police report and planned to pursue legal action against Coinkite in his country.
Across the reporting, the practical consequence remained the same: Coinkite’s guidance required users to generate a new wallet and move funds onchain because updating firmware does not change or repair an existing seed, leaving affected holders to migrate even after patches.



