Bitcoin
Bitcoin (BTC)
$63,241.00 0.91965
Bitcoin price
Ethereum
Ethereum (ETH)
$1,867.61 0.37255
Ethereum price
XRP
XRP (XRP)
$1.08 2.20325
XRP price
BNB
BNB (BNB)
$587.40 1.83304
BNB price
Solana
Solana (SOL)
$73.27 2.12493
Solana price
Hyperliquid
Hyperliquid (HYPE)
$52.34 0.48952
Hyperliquid price
Cardano
Cardano (ADA)
$0.188662 9.03789
Cardano price
Chainlink
Chainlink (LINK)
$8.33 3.63901
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.072931 0.8026
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.42 1.94155
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000657 -0.5997
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$63,241.00 0.91965
Bitcoin price
Ethereum
Ethereum (ETH)
$1,867.61 0.37255
Ethereum price
XRP
XRP (XRP)
$1.08 2.20325
XRP price
BNB
BNB (BNB)
$587.40 1.83304
BNB price
Solana
Solana (SOL)
$73.27 2.12493
Solana price
Hyperliquid
Hyperliquid (HYPE)
$52.34 0.48952
Hyperliquid price
Cardano
Cardano (ADA)
$0.188662 9.03789
Cardano price
Chainlink
Chainlink (LINK)
$8.33 3.63901
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.072931 0.8026
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.42 1.94155
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000657 -0.5997
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$63,241.00 0.91965
Bitcoin price
Ethereum
Ethereum (ETH)
$1,867.61 0.37255
Ethereum price
XRP
XRP (XRP)
$1.08 2.20325
XRP price
BNB
BNB (BNB)
$587.40 1.83304
BNB price
Solana
Solana (SOL)
$73.27 2.12493
Solana price
Hyperliquid
Hyperliquid (HYPE)
$52.34 0.48952
Hyperliquid price
Cardano
Cardano (ADA)
$0.188662 9.03789
Cardano price
Chainlink
Chainlink (LINK)
$8.33 3.63901
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.072931 0.8026
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.42 1.94155
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000657 -0.5997
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$63,241.00 0.91965
Bitcoin price
Ethereum
Ethereum (ETH)
$1,867.61 0.37255
Ethereum price
XRP
XRP (XRP)
$1.08 2.20325
XRP price
BNB
BNB (BNB)
$587.40 1.83304
BNB price
Solana
Solana (SOL)
$73.27 2.12493
Solana price
Hyperliquid
Hyperliquid (HYPE)
$52.34 0.48952
Hyperliquid price
Cardano
Cardano (ADA)
$0.188662 9.03789
Cardano price
Chainlink
Chainlink (LINK)
$8.33 3.63901
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.072931 0.8026
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.42 1.94155
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000657 -0.5997
Asteroid Shiba price

Coldcard users face urgent seed migration warning

Olivia Stephanie
Edited by
News
Coldcard users face urgent seed migration warning

Dogecoin community contributor Mishaboar urged Coldcard users on Aug. 1 to move their Bitcoin to wallets controlled by newly generated seed phrases. 

Summary
  • 1,367.05 BTC worth $88.6 million was drained from 4,585 addresses across three suspected attack waves.
  • Coinkite says firmware updates protect new seeds but cannot repair seed phrases from vulnerable versions.
  • Mishaboar advised users never to reuse affected seeds or enter recovery phrases into computers online.

The warning followed Galaxy Research’s estimate that three suspected attack waves drained 1,367.05 BTC, worth about $88.6 million, from 4,585 addresses.

Mishaboar wrote, “If you have ever used a COLDCARD device of any kind, migrate your funds to a new wallet immediately.” He also warned users not to reuse their existing Coldcard seed phrase or enter recovery words into an internet-connected computer. However, his reference to every Coldcard device is broader than Coinkite’s official security advisory, which identifies specific firmware versions and several exceptions.

Coldcard losses rise as attackers target smaller wallets

Galaxy Research’s latest on-chain estimate identified 1,367.05 BTC across three suspected attack waves. The research firm described $88.6 million as its “estimated observed size,” meaning the total has not been confirmed by Coinkite, law enforcement or every affected user.

The first wave removed 1,082.65 BTC from 1,196 addresses in about 41 minutes on July 30. A later third wave drained roughly 208 BTC from 1,912 addresses, with the average balance falling to slightly more than 0.1 BTC per address. The changing pattern suggests attackers moved from larger holdings toward smaller wallets.

Galaxy said each wave appeared internally consistent with one operator. However, it could not determine whether one attacker controlled all three waves. The third group used separate destination addresses, batched several victims into individual transactions and checked only the default derivation path, making it different from the earlier sweeps.

The research firm also warned that its known transaction patterns cannot identify every theft. A different attacker could generate valid transactions without repeating the fees, destination formats or collection methods seen in the first three waves.

Official Coldcard warning covers specific firmware

Coinkite said the problem affects seeds generated on Mk2 and Mk3 devices running firmware versions 4.0.1 through 4.1.9. Seeds created on Mk4 and Mk5 devices before standard version 5.6.0 or Edge version 6.6.0X are also covered. For Coldcard Q, the fixed releases are standard version 1.5.0Q and Edge version 6.6.0QX.

Coldcard Mk1 devices are outside the firmware regression identified by Block’s researchers. Coinkite also said TAPSIGNER, OPENDIME and SATSCARD are unaffected because they use different codebases. Therefore, the available technical evidence does not establish that every product ever made by Coinkite is vulnerable.

Block’s Bitcoin engineering and security team traced the flaw to a firmware integration error. The affected software used a deterministic MicroPython fallback instead of the intended STM32 hardware random-number generator when creating wallet secrets. On Mk2 and Mk3 v4 firmware, the affected path added no cryptographic entropy. Later models received a limited secure-element reseed.

Block cautioned that its analysis represented its current technical view and did not include complete empirical testing of every device. Coinkite has also said its investigation remains open and promised a formal technical report.

Firmware updates cannot repair existing seeds

Coinkite has released fixed firmware for every affected model and release track. The patches correct the seed-generation process for new wallets, but they cannot add randomness to a seed phrase created earlier. Moving the same vulnerable phrase into another hardware or software wallet also carries the weakness into the new device.

Affected users should install the correct fixed firmware before generating a replacement seed. Coinkite advises recording and verifying the new backup, checking a receiving address on the device screen and sending a small test transaction. Users should move the remaining balance only after confirming that the test funds reached the new wallet.

The company advises users to keep the old backup until the entire migration is confirmed. Mishaboar separately warned users never to type a seed phrase into a computer and recommended keeping offline copies in separate secure locations. That advice can reduce exposure to phishing, malware and cloud synchronization during a rushed migration.

Coinkite identified a limited exception for users who added at least 50 fair, independent and private dice rolls before the final seed words were produced. The company said those rolls contributed at least 128 bits of independent entropy. Users who entered fewer than 50 rolls, cannot remember the number or exposed the roll sequence should migrate.

A strong, unique BIP-39 passphrase creates an additional barrier, but Coinkite said it does not repair an affected seed. Short, reused or predictable passphrases may be guessable. Even users with strong passphrases are advised to replace the underlying seed as soon as practical.

Coldcard incident renews the self-custody debate

Bitcoin investor Anthony Pompliano said the losses showed how technically demanding self-custody can be, even though individuals retain the right to control their assets directly. He also stressed that Bitcoin itself was not hacked because the failure occurred in third-party wallet firmware rather than the Bitcoin protocol.

That distinction matters because an attacker reportedly reproduced weak wallet keys offline. The incident did not require changing Bitcoin transactions, breaking its cryptography or compromising the network’s consensus rules. Once an attacker obtains a valid private key, the resulting transaction appears on-chain like one authorized by the legitimate owner.

As previously reported, the observed loss estimate rose from an early 594.48 BTC calculation to 1,367.05 BTC as researchers found additional address groups. In related coverage, crypto.news examined how the firmware build error weakened seed generation for more than five years.

The case has also entered the U.S. institutional-custody debate.As crypto.news reported, Bloomberg ETF analyst Eric Balchunas argued that the losses strengthen the case for spot Bitcoin ETFs among investors seeking price exposure without managing private keys. ETFs remove personal seed-management duties, although they replace those risks with institutional custody and counterparty exposure.

Coinkite’s promised technical review and further Galaxy address analysis are the next expected updates. Until then, $88.6 million remains the latest public on-chain estimate rather than a final confirmed loss. Users covered by the official advisory face the more immediate task of installing fixed firmware and moving funds to a completely new seed.