Coldcard mandates 65 key presses after record 1,816 BTC seed exploit

Share

Coldcard, one of the most respected Bitcoin hardware wallet manufacturers in the ecosystem, has confirmed that a firmware flaw dating back to March 2021 enabled the theft of roughly 1,816 BTC from more than 5,200 addresses. The 5.6.1 update published on August 20 only patches future seeds; exposed funds must still be migrated to new keys.

🔑 Key takeaways

  • Record theft of roughly 1,816 BTC (~116 M$) via a Coldcard seed flaw exploited since July 2026
  • Firmware 5.6.1 requires 65 key presses, 50 dice rolls, or 128 coin flips per new seed
  • Older Mk2/Mk3 devices delivered only ~40 bits of entropy instead of 128
  • Affected users must migrate funds to a seed generated on patched firmware
  • Only exception: seeds created with at least 50 private physical dice rolls

A five-year-old generation flaw

The regression introduced in March 2021 stemmed from an apparently harmless build configuration error. According to the technical analysis published by Block, a feature flag set to zero in the source code was treated as active at compile time. As a result, affected devices called a deterministic software generator written in MicroPython instead of the intended STM32 hardware generator.

This substitution drastically reduced the effective entropy of generated seeds. On older Mk2 and Mk3 devices, brute-forcing a key moved from roughly 2^128 to 2^40 possible combinations, a level trivially attackable with current computing resources. On Mk4, Mk5 and Q devices, residual entropy reached about 72 bits, insufficient but markedly less critical.

An attacker could generate a batch of candidate seeds, derive the corresponding Bitcoin addresses, then compare those addresses against publicly visible balances on the blockchain. Any match allowed reconstruction of the private key without access to the physical wallet, without knowledge of the PIN, and without attacking the Bitcoin network itself.

Theft scale: four coordinated waves

The first malicious transactions were spotted on July 30, 2026. Within 25 minutes, roughly 594 BTC, valued at 38 M$ at the time, were moved from some 500 wallets to a single consolidation address. Galaxy Research tracked the progression across four major waves and several secondary incidents, in a pattern that appears deliberately orchestrated and programmatic.

Source / DateBTC stolenValue (USD)Addresses hit
July 30, 2026 (1st wave)~594 BTC~38 M$~500
August 14, 2026 (Galaxy Research)>1,778 BTC~112 M$>4,585
August 14, 2026 (TRM Labs)~1,816 BTC~116 M$>5,200

By August 14, Galaxy Research’s tally exceeded 1,778 BTC drained from more than 4,585 addresses. TRM Labs put the total at roughly 1,816 BTC, valued near 116 M$, from over 5,200 addresses. A fourth wave of funds was still circulating in the mempool at the time of analysis. According to TRM Labs, about 90 % of the Bitcoin stolen in confirmed waves had not left the identified destination wallets by early August, with later activity limited to further consolidation rather than sophisticated laundering.

Coldcard hardens the seed creation process

Faced with the severity of the incident, Coinkite overhauled the seed creation process. Firmware 5.6.1 for Mk4 and Mk5, and version 1.5.1Q for Q, now require user-supplied entropy combined with the STM32 generator and the two secure elements SE1 and SE2. Users must pick one of three options: at least 65 key presses at unpredictable intervals, 50 rolls of a six-sided die, or 128 coin flips.

« Every newly generated seed now requires a user entropy source. »

Coinkite, release notes, August 20, 2026

Beyond human input, Coldcard replaced the Yasmarang pseudo-random generator with SHA-256 Hash_DRBG and added statistical tests designed to detect hardware generator failures. The company also introduced staged verification of PSBT (Partially Signed Bitcoin Transactions) immediately before signing, to block any modification injected by a compromised computer connected via USB. Firmware settings for SIGHASH (which determines which parts of a transaction are covered by the signature) were tightened, and backups involving the active wallet were corrected.

Affected versions and migration procedure

Coldcard explicitly warned that installing patched firmware does not repair existing seeds. Any seed generated on vulnerable firmware remains exposed regardless of the device’s current version. Affected users must follow a rigorous migration procedure:

  1. Update firmware to a patched version and verify its digital signature
  2. Generate a new seed on the updated device
  3. Confirm the backup and wallet fingerprint on the device screen
  4. Run a small test transfer to a validated receiving address
  5. Migrate the full balance to the new address
  6. Retain the old seed until migration is fully confirmed

Coinkite identifies one exception: users who added at least 50 unrecorded physical dice rolls at initial creation hold at least 128 bits of independent entropy and may keep their seed. Vulnerable versions cover seeds generated on Mk2 and Mk3 with firmware 4.0.1 to 4.1.9, on Mk4 and Mk5 with standard versions before 5.6.0 or Edge before 6.6.0X, and on Q before 1.5.0Q or Edge 6.6.0QX. Mk1 devices are not affected; TAPSIGNER, OPENDIME and SATSCARD rely on separate codebases.

Industry reactions: a self-custody credibility crisis?

The incident reignited debate over the trade-offs of Bitcoin self-custody. Jonathan Brockmeier, head of compliance at OKX, reported record inflows to centralized platforms after the attacks. Charles Guillemet, CTO of Ledger, reminded observers that the entire security model of a hardware wallet ultimately rests on the quality of the random number generator.

« This is the worst strike in Bitcoin history against the most informed and properly secured bitcoiners. This is not an exchange getting hacked because of hot keys. These are thousands of individuals whose personal private keys were recreated without their knowledge. »

Guy Swann, Bitcoin commentator

Lorenzo Valente, director of digital assets research at ARK Invest, called the self-custodial hardware space a « disaster » reputationally, noting that users trade counterparty risk for a bundle of software, hardware, supply-chain, phishing and backup risks. Nick Neuman, CEO of Casa, dismissed the dice-roll recommendation as unrealistic for 99 % of users. David Lawrence, co-founder of Amicus, argued the episode could accelerate adoption of regulated products like BlackRock’s IBIT ETF. Andrew Lazutkin, CTO of Tangem, cautioned that open-source firmware does not automatically equal better security without sound architecture and independent verification.


Conclusion: self-custody under stress

The attack timeline raises a question: why five years between the flaw’s introduction and its mass exploitation? Galaxy Research described the operation as « deliberate, programmatic and potentially assisted by a large language model. » Coinkite itself suggested attackers may have used AI to audit older open-source firmware versions and spot the regression.

As long as the majority of funds remains in identified destination wallets (~90 % per TRM Labs in early August), the probability of a large-scale sell-off stays limited. But the episode shows Bitcoin self-custody remains a delicate balance between usability and cryptographic rigor, and no manufacturer is immune to an apparently minor build error. What happens next will depend on how quickly affected users migrate their funds before a fifth wave is orchestrated.

Sources

This article is for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles