Coinkite published a Coldcard security advisory on 30 July 2026 after on-chain investigators reported roughly 594 bitcoin swept from about 500 single-signature addresses in a short run of blocks. The Canadian hardware maker says seeds generated on affected firmware may have far less randomness than users were told, and it shipped hotfix firmware 5.6.0 and 1.5.0Q on 31 July.
The Block and CoinDesk matched the same core sequence: a coordinated drain, then Coinkite’s public warning. Coinkite has not published a closed-form forensic proof that this sweep was caused solely by the entropy bug, and its investigation is ongoing. Security researchers examining the chains of spends have linked the pattern to weak seed generation on Coldcard devices.
What moved on-chain
According to Atlas 21’s reconstruction cited by The Block, about 594.5 BTC (near $38 million at then-prevailing prices) left roughly 500 single-signature wallets across Bitcoin blocks 960188 to 960191 on 30 July. Many of the source addresses had been dormant for years and held more than 0.15 BTC at the time of the spend. That is the public “known set” most outlets used for the first wave.
Clay Garrett of Block’s Bitcoin engineering and security team later flagged 695 earlier transactions that shared the same full fingerprint as the known set, moving another ~488 BTC. If those earlier spends are the same operation, the combined total approaches 1,083 BTC. That second tranche is still an investigator’s extension of the fingerprint cluster, not a court-verified total.
What Coinkite says is broken
Coldcard is an air-gapped, Bitcoin-only hardware signer from Coinkite: the private keys stay on the device, and you sign transactions without exposing the seed to a networked computer. The product’s security story has always depended on how the device builds that seed (the BIP-39 mnemonic) when you choose “new wallet.”
Coinkite’s advisory is blunt about the entropy shortfall:
- Mk3: seeds generated on firmware 4.0.1 (March 2021) through 5.0.3 (the last Mk3 release) may have only about ~40 bits of entropy. That is critically low. Coinkite says it is exploring one final Mk3 release but warns that updating the deprecated platform risks bricking units; either way it tells those users to migrate.
- Mk4, Mk5, and Q: seeds generated before fixed firmware may have as little as about ~72 bits, still well below the 128-bit target. Fixed builds are Mk4/Mk5 5.6.0+ and Q 1.5.0Q+, released 31 July 2026.
- Not affected: TAPSIGNER, OPENDIME, and SATSCARD use different codebases and are outside this bug.
Early media notes that said “only Mk3” tracked Coinkite’s first public framing. The live advisory and the upgrade page now put newer models in scope until they run the hotfix and you generate a new seed on that fixed firmware. An update cannot repair a weak seed that was already written down years ago.
Who is actually exposed
The risk is not “every Coldcard on a desk.” It is seeds whose randomness came from the broken device generator, used as single-signature wallets without extra entropy.
Coinkite says you are not treated as at risk from this RNG issue alone if, when creating the seed, you entered at least 50 fair, independent dice rolls through Add Dice Rolls (and those rolls stayed private). 99+ rolls push dice-only entropy near 256 bits. Fewer than 50 rolls, or any uncertainty about how the seed was made, means migrate.
A strong, unique BIP-39 passphrase (not the device PIN) adds an independent barrier. Short, quoted, or reused passphrases should not be treated as a fix. Coinkite still wants passphrase users to migrate to a fresh seed as soon as practical.
Multisig setups and wallets that never used a Coldcard-generated seed sit outside the core warning, though investigators have focused on single-sig spends that look like predictable keys.
What Coinkite wants you to do
The preferred path is calm migration, not a panic send:
- Upgrade first if you will generate a replacement seed on Mk4, Mk5, or Q: install 5.6.0 or 1.5.0Q (or later) from the official upgrade page, bless the firmware, then create a new seed.
- Verify the new backup and the receive address on the device screen. Send a small test amount and confirm receipt before moving the rest.
- Keep the old backup until the new wallet is proven. Rushing a migration is how people lose coins to typos and wrong-network mistakes.
- Mk3-only stopgap: apply a long, random BIP-39 passphrase on-device, verify the new fingerprint, test-send, then migrate off Mk3 hardware when you can. Advanced users can build a dice-only seed on empty Mk3 4.1.9 via Import Existing → Dice Rolls with 99+ rolls (that path does not use the device RNG).
Bitcoin developer James O’Beirne, cited by The Block, put the urgent cohort in plain language: single keys generated on a Coldcard Mk3 between 2021 and 2023, without dice, passphrase, or multisig, should move funds soon, carefully.
Takeaway
Self-custody still means you own the failure modes. Hardware wallets remove exchange counterparty risk; they do not remove firmware and entropy risk. The practical checklist for LatAm and global holders who treat a Coldcard as their long-term vault is the same: confirm which model and firmware generated each seed, treat weak-entropy seeds as compromised for planning purposes, upgrade before minting a replacement key, and prefer multisig or passphrase + verified migration over a single rushed transfer.
This is a security incident report, not investment advice. If your coins sit on an affected seed, follow Coinkite’s migration steps and verify every address on the device screen before you send.



