Coinkite issued a security update for COLDCARD hardware wallets after a seed-generation flaw made some recovery phrases predictable and enabled attackers to reconstruct wallet keys and steal funds. Reporting on the incident said the weakness affected the devices' random-number generation process, including a fallback tied to deterministic data such as serial numbers, and may have exposed more than 4,500 wallets. The thefts reportedly totaled about 1,367 BTC, valued at roughly $86 million, and law enforcement is investigating.
Coinkite urged COLDCARD Mk4, Mk5, and Q users to upgrade to firmware 5.6.1 for Mk4/Mk5 and 1.5.1Q for Q, but warned that upgrading alone does not secure wallets created with vulnerable firmware. Users with potentially affected seeds were told to generate a new seed on fixed firmware and move funds immediately. The company said a July 31 hotfix corrected seed generation for newly created wallets, while the latest release adds broader hardening across seed generation, transaction signing, USB handling, firmware-update validation, Delta Mode, backups, and TRNG self-tests.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
Coinkite disclosed that hackers exploited a seed-generation failure in COLDCARD firmware, causing severe financial losses for some customers. It warned that seeds generated on affected firmware from 2021 through July 2026 may be unsafe and advised users to generate a new seed on fixed firmware and move funds.
Coinkite published a broader security update for COLDCARD Mk4, Mk5, and Q devices, recommending users upgrade to firmware 5.6.1 or 1.5.1Q. The company said the release added defense-in-depth changes across seed generation, transaction signing, USB handling, firmware validation, Delta Mode, backups, and TRNG self-tests.
By August 3, reported losses had climbed to about 1,367 BTC, valued at roughly US$86 million, affecting more than 4,500 wallets. The article says the reported loss amount more than doubled from the initial July 31 figure.
Initial reporting on the exploitation of the Coldcard flaw said losses were approximately US$38 million. This figure was later reported to have more than doubled within days.
Coinkite said a July 31 firmware hotfix corrected the seed-generation failure for newly generated seeds. The company later emphasized that this did not make already vulnerable seeds safe.
Jonathan Goodman later discovered that all three of his Coldcard wallets had been emptied within minutes of one another. The article anchors these thefts to July 29.
Coinkite said law enforcement authorities are investigating the thefts and working to identify those responsible. No specific start date for the investigation is provided in the references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourceblog.coinkite.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.