mt logoMyToken
ETH Gas
EN

A five-year-old Coldcard bug let hackers guess bitcoin wallet keys, Coinkite confirms

Favoritecollect
Shareshare
A five-year-old Coldcard bug let hackers guess bitcoin wallet keys, Coinkite confirms

Coinkite disclosed on July 30 that a coding error dating to March 2021 caused its Coldcard hardware wallets, physical devices that store the keys to a person's bitcoin offline, to generate wallet seed phrases using a predictable software program instead of the device's dedicated chip for generating true randomness. The flaw has already been linked to the theft of more than 1,300 bitcoin from affected wallets.

The problem traces back to a 2021 software update. Coldcard's wallets are supposed to create a new seed phrase, the string of words that functions as the master key to a person's funds, using a hardware chip built to produce genuine randomness. During that update, a coding error caused the device to quietly draw from a software program that only mimics randomness instead, based mostly on predictable information like the device's internal clock rather than anything truly unpredictable. A safeguard meant to catch this kind of error only checked that a setting existed, not that it was switched on, so the mistake passed through testing undetected for years.

Bitcoin wallets depend on that seed phrase to secure funds. A properly generated 12-word seed is supposed to carry 128 bits of randomness, meaning the number of possible combinations is so large that guessing the right one is practically impossible. Coinkite's technical explanation of the bug says seeds generated on its Mk2 and Mk3 models with the flawed software carried only about 40 bits of real randomness, a small enough set of possibilities that a well-resourced attacker could work through them. Its newer Mk4, Mk5, and Q models mix in some genuine randomness from a separate security chip, which Coinkite says raises the effective strength to about 72 bits, still far short of the target. Block's security team , which reached the same conclusion independently, found that only a sliver of that extra randomness, equal to about 32 bits, actually made it into the final seed.

Coinkite has released fixed software for every affected model, including version 4.2.0 for the Mk2 and Mk3, but installing the update does not fix a seed that was already generated on the flawed software. Anyone whose wallet was set up without adding at least 50 rolls of a physical die during setup, or without a separate secret passphrase on top of the seed phrase, is advised to generate a brand new seed on the updated software and move their funds over, testing with a small transaction first before moving everything. Coldcard's Tapsigner, Opendime, and Satscard products run on different software and are not affected.

By August 2, Galaxy Research had tracked roughly 1,367 bitcoin, worth about $88.6 million at the time, drained from more than 4,500 addresses tied to the bug, a figure that has climbed steadily since the first reports of an exploit on July 30. Coinkite says its code has always been publicly viewable and suggests an attacker likely used an automated tool to review it and find the flaw before the company did.

A hardware wallet is supposed to be safer than storing bitcoin on an exchange or a phone because it keeps the keys offline, but this incident is a reminder that the software running inside the device matters as much as the physical box itself. Rival hardware wallet makers moved quickly to tell their own customers that their devices were not affected. Ledger said its wallets use a certified hardware random number generator built into a secure chip that produces the full 256 bits of randomness a 24-word recovery phrase needs.

Ledger is not affected by the recently published Coldcard Mk3 advisory.

Ledger devices use a certified True Random Number Generator (TRNG) built directly into our Secure Element chip, generating full 256 bits of entropy for every 24-word Secret Recovery Phrase. Please refer to…

— Ledger (@Ledger) July 31, 2026

Trezor users: your funds are safe.

The recent Coldcard issue is limited to their own custom firmware and how some of their devices generated randomness. Trezor does not share that code.

We have always mixed multiple independent sources of randomness together (device hardware +…

— Trezor (@Trezor) July 31, 2026

Trezor told its users that the Coldcard problem is specific to Coldcard's own firmware and that Trezor does not share that code, adding that it mixes randomness from multiple independent sources instead.

Coldcard's code has been publicly viewable for years, which is usually considered a security advantage because outside researchers can review it. In this case, that same openness likely helped an outsider find the flaw first. Coinkite says it does not know for certain who found it or how, but suspects an attacker used an automated tool to comb through old versions of the code, something Coinkite itself had tried a few weeks earlier without catching the bug.

Coinkite's investigation is ongoing, and it has said a fuller technical review is still coming, so some of the details here, including the final theft total, could still change.

➢ Stay ahead of the curve. Join Blockhead on Telegram today for all the latest in crypto.
+ Follow Blockhead on Google News
Disclaimer: This article is copyrighted by the original author and does not represent MyToken’s views and positions. If you have any questions regarding content or copyright, please contact us.(www.mytokencap.com)contact
More exciting content is available on
X(https://x.com/MyTokencap)
or join the community to learn more:MyToken-English Telegram Group
https://t.me/mytokenGroup