COLDCARD Seed Vulnerability Puts Wallets at Risk as Funds Are Already Moving On-Chain

COLDCARD Seed Vulnerability Puts Wallets at Risk as Funds Are Already Moving On-Chain

N
News Editor
2026-07-31 15:22:26
Bitcoin Magazine, citing an official announcement posted by Coinkite, warned that a serious security flaw is affecting COLDCARD MK3, MK4, MK5, and Q devices. The report says some wallets generated on those devices are being drained because attackers can recover the seed phrase without any action from the user. According to the article, the only wallets considered safe are those created with the dice roll method, provided the user supplied at least 50 rolls of entropy. The piece says any word seed generated after the end of 2020 on a Coldcard is not secure if the user did not add the recommended 50-plus dice rolls. It also says the flaw extends to ephemeral keys and session keys used for Clone Coldcard or Key Teleport, as well as BIP 85 seeds derived from a compromised seed. The attack is described as active, with around 1,000 BTC seen moving on-chain in connection with the issue. For affected users, the article urges an immediate move of funds to a newly generated seed or to a wallet created on a different device. If another hardware wallet is available, the report says that is the fastest option. If not, it outlines a temporary passphrase-based workaround and also mentions Nunchuck, Blockstream Green, and Bluewallet as software wallet options. The article adds that a firmware patch has already been released and says Coldcard remains usable after the update if a new seed is generated securely.

Bitcoin Magazine issued an urgent warning over a serious security problem affecting COLDCARD devices, saying MK3, MK4, MK5, and Q models are impacted. The report pointed readers to an official announcement posted by Coinkite the previous day and urged them to read that notice directly and verify the issue there.

COLDCARD Seed Vulnerability Puts Wallets at Risk as Funds Are Already Moving On-Chain 2

The article’s bottom line was blunt: some Coldcard wallets are being drained, and a flaw allows attackers to recover a seed phrase without any action from the owner. It said the only wallets considered safe are those generated with the dice roll method, assuming the user supplied at least 50 dice rolls.

If a user does not know, does not remember, or cannot confirm whether that method was used, the article says funds should be moved immediately. It described the matter as a critical issue that requires immediate action.

Which seeds are affected

According to the report, any word seed generated on a Coldcard after the end of 2020 is not secure if the user did not add their own entropy through the recommended 50 or more dice rolls. The article said those seeds were created without enough randomness and can be brute forced by a malicious attacker.

The report also said the issue affects ephemeral keys and session keys tied to Clone Coldcard or Key Teleport features. BIP 85 seeds generated from a compromised seed are affected as well. Even with those details, the instruction in the article did not change: users still need to move their funds.

Bitcoin Magazine said the exploit is already active, adding that around 1,000 BTC has been seen moving on-chain in connection with the vulnerability.

Immediate steps outlined in the article

The article said affected users need to move funds to a new word seed, or to a word seed generated by a different device, in order to secure their holdings.

For anyone who already has another hardware wallet that is not a Coldcard, the report said sending funds there is the quickest and simplest route.

For users who only have a Coldcard, the article suggested generating a passphrase using at minimum six seed words from the BIP 39 word list. It specifically warned users not to choose the words themselves and instead to follow the guide referenced in the article. From there, it advised checking the wallet fingerprint or an address, powering down the device, restarting it, and entering the passphrase again. If the fingerprint or address matches, the user can send funds to the passphrase wallet.

The article stressed that this is not a permanent fix. It described the passphrase step as a way to buy time by raising security enough that an attacker would not be able to brute force the keys in a matter of days, giving the user room to create a new seed without rushing. It also said the passphrase should be written down and stored securely.

Software wallet options mentioned

If users have no other option, or are uncomfortable using the device at all, the report mentioned Nunchuck, which is available on mobile and desktop. It told users to slow down, avoid moving too quickly, and make sure all backups are properly completed before sending funds there.

For people managing significant sums, the article said Nunchuck supports multisig and allows one to create a setup using multiple devices.

It also named Blockstream Green and Bluewallet as other software wallet options.

Patch released, but older funds still need to be moved first

Once funds are secure, the article said users can pause. It also said Coldcards remain safe to use as long as the word seed is generated securely, and noted that a firmware patch has been released.

According to the report, any word seed generated after installing that firmware update should be secure, and the dice roll option can still be used. If a user temporarily moved funds to a hot wallet or another less secure destination, the article said the Coldcard can be used again after applying the firmware update and generating a new seed.

Warning others who may be exposed

The article ended by telling readers to check on others once their own funds are protected. It said anyone who knows a Coldcard user whose seed may have been created during the vulnerable period should reach out, explain the issue, and help with migration if they are able to do so.

It added that many people do not follow Bitcoin news regularly, so some affected users may not realize they are exposed.

The article first appeared in Bitcoin Magazine and was written by Shinobi.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1560

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.