Coldcard manufacturer Coinkite escalated its response to a hardware-wallet seed-generation failure on August 4, 2026, warning that the threat remained active and urging affected users to migrate their bitcoin to newly generated wallets.
The warning mattered because the incident challenged a core assumption behind hardware wallets: keeping signing keys offline does not protect funds when the device created those keys with inadequate randomness. Attackers did not need physical access to a Coldcard. Researchers said they could search a constrained set of possible seeds, identify those controlling funded Bitcoin addresses and transfer the coins.
An urgent escalation
Coinkite had issued its initial security advisory on July 30 and expanded the affected-device scope by August 1. On August 4, the company characterized migration as urgent, asked users to alert owners who might not have seen the warning and published an additional account of its investigation.
The vendor’s August 1 advisory identified seeds generated on Mk2 or Mk3 firmware versions 4.0.1 through 4.1.9 as exposed under specified conditions. It also said seeds created on Mk4, Mk5 and Q devices before their respective fixed releases were affected. Coinkite stressed that installing corrected firmware could protect future seed generation but could not repair a seed that already existed.
The advisory described two material qualifications. Seeds supplemented during creation with at least 50 independent, private dice rolls were not considered exposed by this random-number-generation failure alone. A strong, unique BIP-39 passphrase added a separate barrier, although Coinkite still recommended eventual migration. Those were the manufacturer’s contemporaneous assessments, not guarantees established by an independent audit.
How the seed-generation path failed
Block’s Bitcoin engineering and security teams traced the defect to an integration error between Coldcard firmware components. Their July 30 technical report said a random-number call resolved to MicroPython’s deterministic Yasmarang generator instead of the hardware random-number generator intended for wallet creation.
For affected Mk2 and Mk3 firmware, Block reported that no cryptographic entropy entered that path. For newer models, it found a secure-element reseed but said only 32 bits reached the software generator. Block cautioned that it had not completed full empirical testing and did not claim that every wallet could be recovered immediately. Practical exploitation depended on device identifiers, timing state, prior generator calls and computational cost.
The vulnerable path entered released firmware in March 2021, according to Block’s repository analysis. That long exposure window made the incident institutionally significant: a device could remain physically isolated and operate as designed during signing while still relying on seed material that an attacker might reproduce elsewhere.
What was known about the losses
Galaxy Research’s accounting published at 22:51 UTC on August 3 identified 1,596 BTC across approximately 7,300 addresses in three confirmed waves and 14 smaller incidents. Galaxy described that confirmed set as exceeding $100 million. Its larger estimate of 2,055 BTC, approximately $130 million, included a suspected fourth wave that had not been confirmed through victim reports.
Those figures were attribution estimates, not a complete victim ledger. Galaxy had not published the underlying address and transaction lists, address counts were not equivalent to individual owners, and similar transaction patterns could not establish whether one or several attackers were responsible. Coinburn therefore does not promote the suspected fourth wave into the confirmed total.
A limited market signal
CoinDesk reported bitcoin near $63,800 during early U.S. trading on August 4, using its own market data. That was an intraday observation rather than a daily close or composite performance calculation, and it did not demonstrate that the warning caused—or failed to cause—any particular price movement.
The clearer event-day consequence was operational, not market-wide: Coldcard users faced an active race between migration and unauthorized transfers, while wallet developers confronted evidence that offline custody remained dependent on correctly implemented entropy generation. As of August 4, the investigation, loss accounting and affected population were still evolving.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

