Coinkite says 2021 COLDCARD firmware bug linked to theft of ~1,083–1,367 BTC; users must replace affected seeds

·

Coinkite says a firmware bug dating to 2021 weakened the way some COLDCARD hardware wallets generated recovery seeds, and independent on-chain investigators have linked the flaw to thefts of roughly 1,082.65 to 1,367.05 bitcoin. For users, the key point is practical and urgent: a software update by itself does not fix the problem if a wallet’s seed phrase was created on vulnerable firmware. Those seeds must be replaced and funds moved to a newly generated wallet.

The Canadian company, which makes the COLDCARD line of bitcoin hardware wallets, published an urgent “Coldcard Security Advisory” on July 30, with updates on Aug. 1 and Aug. 14. Coinkite said funds tied to seeds generated on affected firmware “may be at risk” and posted migration guidance. According to the company, Mk2 and Mk3 devices are specifically at risk if seeds were generated on firmware versions 4.0.1 through 4.1.9, unless the user added substantial dice entropy or used a strong BIP-39 passphrase, an optional extra secret layered on top of the seed phrase. Coinkite said Mk4, Mk5 and Q devices were also affected before fixed releases, though with less severe entropy reduction.

The root cause, according to independent analysis published July 30 by Block Engineering, was a random-number-generation integration error introduced during a code migration in March 2021. In plain terms, the devices relied on the wrong source of randomness when creating some wallet seeds. Instead of using the STM32 chip’s hardware true random number generator, the firmware used MicroPython’s Yasmarang software pseudo-random generator, which is weaker and deterministic. Block Engineering said, “COLDCARD firmware contains an RNG integration error that causes ngu.random to use MicroPython’s deterministic Yasmarang fallback instead of the STM32 hardware RNG.” The firm said the regression was first released in firmware v4.0.0 on March 17, 2021.

That matters because a hardware wallet’s seed phrase is the master secret controlling access to funds. Hardware wallets are designed to keep those keys offline, but that protection depends on strong randomness at the moment the seed is created. If the randomness is weak or predictable, an attacker can potentially reconstruct the seed offline and then use public blockchain records to identify and drain associated bitcoin. For COLDCARD, a product widely used by self-custody bitcoin holders and marketed around security-focused, air-gapped setups, the bug is especially significant.

Estimates of the losses grew as investigators traced more activity. Galaxy Research initially reported that 1,196 addresses were drained of 1,082.65 BTC during a 41-minute window on July 30, equal to about $70.2 million at bitcoin prices at the time. Galaxy later reported a broader total of 1,367.05 BTC across 4,585 addresses in three waves, or about $88.6 million based on the market price then. Some later media reports cited higher dollar figures, including totals above $100 million, but the most traceable on-chain estimates published in the research are in the 1,082.65 BTC to 1,367.05 BTC range. The first drains were observed around July 29 and 30.

Coinkite’s guidance is clear: users should not generate a new seed on affected models until fixed firmware is installed. But installing fixed firmware is only the first step for anyone who already created a seed under vulnerable conditions. Coinkite said in its advisory, “Updating firmware alone does not repair an existing affected seed.” Instead, affected users need to install the fixed release, generate a new seed on that corrected firmware, and migrate funds from any old seed created on vulnerable versions.

Coinkite published a separate technical backgrounder on July 30 stressing the same point: the flaw can be patched going forward, but seeds already created with reduced entropy remain weak. The company released fixed firmware updates on July 31 and Aug. 1, along with instructions for moving funds safely.

No public attribution has been made in authoritative technical reports about who carried out the thefts. In the days after the disclosure, security firms and news outlets also reported phishing and scam campaigns targeting COLDCARD users, including fake “security verification” tools. For affected customers, that creates a second risk alongside the firmware flaw itself: relying on unofficial help. Users should follow Coinkite’s published guidance directly and treat unsolicited messages, recovery offers and third-party tools with caution.

Tags: #bitcoin, #hardwarewallet, #security, #coinkite