Coinkite has confirmed a seed-generation flaw in its Coldcard hardware-wallet line after attackers drained 594.48 BTC in about 25 minutes, according to on-chain analysis and the company’s own security notice. The transfers began at 9:31 a.m. Taipei time on July 31 and played out over a three-block window, with 1,324 UTXOs moved through 500 transactions. At a bitcoin price of roughly $64,000 at the time, the stolen amount was worth about $38.3 million.
The incident has shaken one of bitcoin self-custody’s best-known hardware-wallet brands. Attention quickly turned to a flaw in the way some Coldcard devices generated wallet seeds.
On-chain analysts traced a coordinated sweep of single-signature wallets
One of the earliest public warnings came from the on-chain monitoring community. Rob Hamilton, CEO of AnchorWatch, said in a post on X that all of the drained addresses were single-signature wallets and were concentrated in native SegWit format. He said the pattern looked like an entropy problem during wallet generation.
Hamilton said 1,324 UTXOs were swept across 500 transactions within a three-block window, totaling 594.48 BTC. He added that 562 BTC was later consolidated into a single new address and had not moved again at the time of his analysis.
Kevin Loaec, CEO of Wizardsardine, also pointed to a low-entropy random-number generator. In his view, the seed material did not carry the level of randomness it should have had, leaving room for attackers to derive private keys.
The affected addresses all held more than 0.15 BTC, and their creation dates stretched from 2021 to 2026. Some had been dormant for years. Victim accounts also began appearing on Reddit, adding to the view that the attacker may have completed large-scale private-key derivation before triggering the thefts in one coordinated wave.
The technical issue dates back to a 2021 firmware change
The engineering and security team at Block, the company behind the Bitkey wallet, laid out the technical details in a report. According to that report, Coldcard firmware version 4.0.0, released in March 2021, introduced a build setting that accidentally disabled the secure chip’s hardware random-number generator.
The failure slipped through because the library logic checked whether the setting existed, not whether it was actually enabled. As a result, key generation silently fell back to a predictable software path. The entropy source for that path came from the chip serial number and clock registers.
Those inputs are not secret. A serial number is fixed at manufacturing, and clock values can be measured by an attacker using their own device to narrow the possible range. What should have been an unguessable random seed became something that could be attacked through brute-force methods.
Coinkite said the affected devices produced only about 72 bits of entropy, well below the expected 128 bits. The impact was broader than wallet seeds alone. Paper-wallet private keys, seed-split masks, device clone keys and Key Teleport transfers all used the same generator.
The scope widened beyond the Mk3
Coinkite’s July 30 security notice first centered on the Mk3. The company said users who generated seeds on firmware versions from 4.0.1, released in March 2021, through 5.0.3 should move assets as soon as possible. At that stage, it said preliminary analysis suggested that the Mk4, Q and Mk5 were not affected.
That assessment was later challenged publicly. Max Guise, hardware lead for Bitkey, said on X that the flaw was not limited to the Mk3 and also affected the Mk2, Mk4, Q and Mk5, though the severity varied by model. He wrote that an active theft campaign was highly likely and said more wallets could still be at risk. He recommended that affected users move funds as soon as they could do so safely.
Coinkite later updated its notice and confirmed that the Mk4 and Mk5 were affected on firmware versions earlier than 5.6.0, while the Q was affected on versions earlier than 1.5.0Q. The company said TAPSIGNER, OPENDIME and SATSCARD were not impacted because they use a different codebase.
Users are being told not to wait for a firmware update
Coinkite broke its guidance into several categories. Users who never used dice input to create a seed were told to move to a new seed as quickly as possible.
For users who generated a seed with at least 50 fair and private dice rolls, the company said the risk was lower because that process contributes at least 128 bits of entropy. It said 99 or more rolls would be better.
Users who set a strong and unique BIP-39 passphrase were also described as facing lower risk, but Coinkite said they should still migrate to a new seed. The company added that short, common or reused passphrases should not be treated as secure.
Its broader advice was clear: do not wait for a firmware update. Users should generate a new seed on an unaffected device, verify the backup, send a small test transaction first and then move the full balance.
For those who need to avoid the built-in random-number generator on the Mk3, Coinkite said a new seed can be created by using “Import Existing → Dice Rolls” and entering at least 99 dice results.

