Weak randomness in a hardware wallet meets an automated sweep
Coinkite warned that Coldcard devices generated seeds with too little entropy; within a day, onchain observers were attributing the draining of hundreds of bitcoin to keys an attacker could simply recompute.
What happened
Coinkite published a security advisory on 30 July, updated on 1 August, saying that Coldcard devices had produced seeds with insufficient entropy. Mk2 and Mk3 units on firmware 4.0.1 to 4.1.9 inclusive are affected unless the seed was generated with at least fifty independent private dice rolls, and Mk4, Mk5 and Q units before the fixed firmware versions produced about 72 bits of entropy rather than the expected 128. Users are told to update firmware, generate replacement seeds, verify backups and wallet fingerprints, make a test transaction and then migrate the remainder. The advisory confirms no thefts. Reporting the following day tied large automated sweeps to the flaw: CoinDesk counted about 594 BTC, roughly $38m, taken from around 500 single-signature wallets in twenty-five minutes, while Bitcoin Magazine put the running total at 1,082.65 BTC across 1,196 affected addresses, more than $70m.
Why it matters
Self-custody rests on the assumption that a properly generated seed cannot be guessed. Weak entropy converts that assumption into a race between users who patch and an attacker who can enumerate a keyspace, and the second party is faster. The speed of the sweeps, hundreds of wallets in minutes, shows an industrialised exploiting side, and the cost falls where self-custody always puts it. A custodian's failure is absorbed by its balance sheet and its insurers; this one is absorbed by whoever owned the coins.
What is not settled
The totals disagree and the desk records the disagreement rather than resolving it: CoinDesk reports 594 BTC and about $38m in the initial sweep, Bitcoin Magazine 1,082.65 BTC and more than $70m across all affected addresses. Coinkite has not confirmed that any theft is attributable to the flaw. How many vulnerable seeds remain unswept is unknown, and cannot be known from outside, which is the uncomfortable part: the exposure ends only when every affected holder acts.
Institutions in this story
-
Coinkite Inc.
Custodian
Published the advisory on 30 July, updated 1 August, and confirms no thefts itself; the attribution of the sweeps to the flaw rests on outside onchain analysts rather than on the manufacturer.
On the record
Coinkite warns of a Coldcard seed-generation flaw as wallets are drained
Coinkite published a security advisory on 30 July 2026, updated on 1 August, saying Coldcard devices had generated seeds with insufficient entropy: about 72 bits rather than 128 on later models, and weak seeds on Mk2 and Mk3 firmware 4.0.1 to 4.1.9 unless dice rolls were used. The advisory confirms no thefts; outside analysts attributed large automated sweeps of bitcoin to the flaw the following day.