A Coldcard firmware flaw that first entered the hardware wallet’s code in 2021 is still being linked to stolen bitcoin, with Coinkite warning on August 2, 2026 that the threat remains real and ongoing and that patched firmware alone does not repair seeds already generated on vulnerable versions.
A Coldcard firmware flaw that first entered the hardware wallet’s code in 2021 is still being linked to stolen bitcoin, with Coinkite warning on August 2, 2026 that the threat remains real and ongoing and that patched firmware alone does not repair seeds already generated on vulnerable versions.
The issue has shifted from an old, quietly patched bug into an active drain on bitcoin holdings. Coinkite, the company behind Coldcard, has told affected users to generate a new seed and move their funds, a message echoed in reporting that Coldcard is urging users to move bitcoin while the exploit continues. For related coverage, see Subversive Bitcoin SPAC Files With SEC to Go Public.
What to Know
- A March 2021 code change made Coldcard seed generation predictable on affected firmware, and patching the firmware does not fix seeds already created on it.
- Coinkite says the theft is ongoing and that exposed users must generate a new seed and move funds rather than rely on an update.
What happened with the 2021 Coldcard firmware flaw
Block’s security team traced the regression to a March 1, 2021 commit that first shipped in released firmware v4.0.0 on March 17, 2021, which caused the ngu.random function to fall back to MicroPython’s deterministic Yasmarang generator instead of the STM32 hardware RNG, according to Block’s engineering analysis. For related coverage, see When Will the Bitcoin Bull Run Start? Analyst Markers to Watch.
That fallback path is what made the flaw dangerous. When a device generates a seed from a predictable random source, the resulting private keys can be reconstructed by an attacker, meaning the bitcoin secured by that seed was never truly private from the start. For related coverage, see Boltz Disables Bitcoin Swaps: What It Means for Users.
Coinkite’s advisory defines exactly who is exposed. Mk2 and Mk3 seeds generated on firmware versions 4.0.1 through 4.1.9 inclusive are at risk, and Mk4, Mk5, and Q seeds generated before their respective fixed releases are also affected, per the company’s July 30, 2026 warning.
Users who generated their seed on unaffected firmware, or who imported a seed created elsewhere, fall outside the exposed set. The risk is tied specifically to seeds produced on the vulnerable code, not to owning a Coldcard device in general.
Why the old Coldcard bug is still draining wallets
The reason a 2021 flaw is still causing losses in 2026 is that a patch cannot undo a weak seed. Coinkite said patched firmware prevents the issue from affecting newly generated seeds but does not repair seeds already created on vulnerable firmware, in its August 2, 2026 update.
Those pre-existing weak seeds are exactly what attackers are now sweeping. CoinDesk reported that the initial July 30, 2026 sweep took 1,083 bitcoin from 1,196 addresses in just 41 minutes, the opening move in a series of coordinated drains.
The drains did not stop there. Across three attack waves, CoinDesk counted 1,367 bitcoin drained from 4,585 addresses, a scale of theft consistent with an attacker who can regenerate keys at will rather than one breaking into devices one at a time.
Losses may have climbed further. A possible fourth sweep lifted cumulative losses to about 1,816 BTC, roughly $114 million, from more than 5,200 addresses by August 3-4, according to unconfirmed Galaxy Research counts reported by CoinDesk, though Coinkite had not published a final official loss total or postmortem.
The theft is measurably reshaping holder behavior. CryptoQuant data showed daily exchange deposits of bitcoin transfers under 10 BTC spiked to 7.3K BTC on August 1 as holders moved coins for safety, a pattern CoinDesk contrasted with the FTX collapse.
Even so, the broader market has held. Bitcoin was trading near $63,800 on August 4 despite the warning, as the exploit remained active, and stood at roughly $63,888 with a 1.86% daily gain in spot market data.
Sentiment, though, has soured. The Fear & Greed Index sat at 25, or Extreme Fear, as the incident spread across thousands of addresses in what has been reported as a hack hitting more than 1,000 bitcoin addresses.
What Coldcard and bitcoin wallet users should do now
For exposed users, Coinkite’s guidance is direct: generate a new seed on fixed firmware and move funds off any wallet whose seed was created on a vulnerable version. A firmware update by itself leaves an already-weak seed just as exploitable as before.
- Check your firmware version against the affected ranges, including 4.0.1 through 4.1.9 for Mk2 and Mk3 devices.
- If your seed was generated on affected firmware, create a fresh seed on a patched release and transfer bitcoin to the new wallet.
- Do not reuse or trust the old seed even after updating; the update does not retroactively secure it.
- Retain the physical device rather than discarding it, as Coinkite said its legal team may coordinate with law enforcement and asked affected users not to dispose of their hardware.
Coinkite has also said it halted shipments and destroyed remaining vulnerable inventory, steps that address new devices but do nothing for seeds already in circulation. That gap is why verifying how and when a seed was generated, not just which firmware a device now runs, is the decisive check for any current Coldcard holder.
Coinkite had not published its promised formal technical postmortem by August 4, so final loss attribution and the full official timeline may still change.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
