On Thursday, July 30, 2026, Coinkite disclosed that its Coldcard hardware wallets had been generating seed phrases predictably since March 2021. Within hours, attackers began emptying wallets in waves. It's the kind of flaw that contradicts the entire premise of the product: a cold wallet exists precisely so your key never depends on trustworthy software.

This article gathers what is known as of August 4, 2026: what broke, who is exposed, what to do if you own a Coldcard, the phishing scam that followed, and a market read that may surprise you — Bitcoin's price barely moved through all of it.

What happened

A hardware wallet generates its seed phrase from entropy: genuinely random numbers produced by a dedicated chip. If that randomness is real, the space of possible keys is far too large for any computer to walk through. If it's weak, the space shrinks — and what was impossible becomes a matter of processing time.

That is exactly what happened. An integration change made in March 2021 started routing seed generation through a predictable software path instead of the hardware randomness generator. There was a safety check in the code, but it only verified that the setting existed — not that it was actually active. The bug went unnoticed for five years.

The effect, according to the technical analysis published by Blockhead: on the worst-hit devices, entropy dropped from 128 bits to roughly 40 bits. That isn't an incremental reduction, it's the difference between infeasible and feasible. An attacker with modest resources can sweep 40 bits and simply guess the keys.

In one sentence

The wallet still asked for 24 words, showed 24 words and worked normally. What changed was invisible to the user: the set of seeds it could draw from shrank until it fit inside a brute-force search.

The scale of the theft

The attacks came in waves, and the numbers climbed each day. An honest warning: sources disagree, because on-chain tracking kept running while the articles were being published. The figures below are what each outlet reported, with the date of each count.

  • Wave 1 (July 30): 1,196 addresses emptied in 41 minutes, roughly 1,083 BTC (~$70.2 million at the time).
  • Wave 2 (July 31): a 25-minute sweep drained approximately 594 BTC (~$38 million) from about 500 wallets.
  • Wave 3 (over the weekend): 208 BTC taken from 1,912 addresses.
  • Wave 4 (Monday, August 3): Fortune puts the total at roughly 1,816 BTC, nearly $116 million, across more than 5,200 addresses.

Other counts from the same period work with smaller numbers because they closed earlier: Blockhead reported 1,367 BTC (~$88.6 million) as of August 2, and outlets citing Galaxy Research data reported around $110 million. All point to the same order of magnitude. And at the time of writing, the case was not yet closed.

The flaw was identified by Block's engineering and security teams. Part of the press raised the possibility that AI tools helped find the bug — Coinkite itself said it had run a state-of-the-art model over its own code without it catching the problem. Treat that part as reporting, not established fact: the sources don't converge.

Who is exposed

Not every device carries the same risk, and it's worth checking yours before panicking or, worse, before relaxing.

High risk

Coldcard Mk2 and Mk3

These are the severely affected ones: entropy reduced to about 40 bits. The fix landed in firmware 4.2.0, but note the point that confuses everyone — updating the firmware does not repair a seed that was born weak. If your phrase was generated on the device during the bug window, it stays vulnerable forever.

Partial risk

Coldcard Mk4, Mk5 and Q

Partially affected, with partial mitigation: entropy fell to around 72 bits, and Block's analysis estimates something closer to 32 effective bits. Less exposed than the Mk3, far from comfortable.

Out of scope

Tapsigner, Opendime and Satscard

They run different software and are not hit by this flaw.

Two factors reduce or eliminate the risk, per the manufacturer's own guidance: seeds created with 50 or more physical dice rolls (Coldcard's manual entropy feature) and the use of a separate passphrase, the extra word that is never stored on the device. Anyone who did either is in better shape.

What to do now

If you own or have owned a Coldcard, Coinkite's open letter is blunt: move your funds as soon as possible. The practical playbook:

  1. Identify where the seed was born. The question isn't which device you use today, it's on which device and firmware those 24 words were first generated. A seed imported from elsewhere, or created before March 2021, never went through the broken path.
  2. Update the firmware to a fixed version (4.2.0 or later on affected models). This does not save the old seed — it ensures the next one is born with real randomness.
  3. Generate a new seed, preferably using physical dice rolls, and write the phrase down on paper before doing anything else.
  4. Test with a small amount. Send a token sum to the new address, confirm it arrives, and confirm you can restore the wallet from the phrase you wrote down. Only then move the rest.
  5. Transfer everything from the old wallet to the new one and consider the old one permanently burned. Don't reuse it, don't leave "just a little" in it.
Warning

Never type your seed phrase into any website, form, spreadsheet, chat or "affected wallet checker". No legitimate verification asks for your words. The only place the phrase may be typed is the device itself, during restoration.

The second wave is phishing

Whenever a case like this makes headlines, the next wave is scams — and here there's an aggravating factor. Coinkite has come under fire for retaining customer emails, which means a list of people who demonstrably own a hardware wallet — exactly the target a scammer wants.

Expect very convincing emails, with the right tone and urgency, offering "automatic migration", a "verification tool" or "victim reimbursement". Simple rules: never click an email link to handle this, type the manufacturer's address by hand, and distrust anything with a short deadline. Haste is the favorite tool of anyone after your seed. The same logic applies as in the beginner crypto mistakes that cost the most: the loss rarely comes from the market, it comes from the decision made with a racing heart.

And the market? Almost nothing

Here's the counterintuitive part. A nine-figure theft from Bitcoin's most respected hardware wallet looked like material for an ugly drop. It wasn't. Fortune recorded less than 1% movement in Bitcoin and Ethereum since the disclosure; some outlets pointed to around 3% over 24 hours, with BTC in the $62,000 range. Under either read, the conclusion is the same: price stayed essentially sideways, inside the range it was already in.

That teaches something worth more than the headline. A big story is not the same as a big move — and the reverse holds too: plenty of the moves that matter happen with no headline at all, overnight, unannounced. Trading the news means buying the scare and selling the relief. Working from levels defined in advance means deciding with a cool head and letting price tell you when it gets there.

Where price alerts fit (and where they don't)

Let's be honest about the tool's limits, because in a security story that matters: Alarm Crypto monitors price, not your wallet. No price alarm would have prevented this theft, warned about a weak seed, or detected a transaction leaving your address. Anyone promising that is selling something else.

What an alarm solves is the neighboring problem, and it showed up plenty in these days. If you had to move funds in a hurry, wanted to track how the market reacted while you dealt with the rest, or simply want to know if Bitcoin leaves its current range without spending the day refreshing a chart — that's what it's for. Monitoring runs on the server, across 6 exchanges in parallel, and the alert arrives with a loud sound even with the app closed and the phone locked. That's the difference between knowing now and knowing later, which is the subject of why five minutes of delay costs money.

To set this up properly, start with how to set Bitcoin price alerts — and if your read is that the scare opened a window, it's worth understanding how to tell when a crypto has fallen enough to become an opportunity.

Frequently asked questions

My Coldcard firmware is up to date. Am I safe?

Not necessarily. Fixed firmware guarantees that new seeds are born with real randomness, but it does not repair a seed already generated. If your 24 words were born on the device between March 2021 and the fix, the path forward is to generate a new seed and migrate the funds.

How do I know whether my seed is one of the weak ones?

There is no reliable home test, and any service offering to "check" by asking for your words is a scam. The practical criterion is history: device model, when the phrase was created, and whether you used dice rolls or a passphrase. When in doubt, treat it as compromised and migrate — migrating as a precaution costs you an afternoon; being wrong the other way costs the whole balance.

I used a passphrase. Am I still exposed?

A passphrase adds a secret that was never stored on the device, so it puts you in a much better position than someone who skipped it. Even so, the manufacturer's recommendation is to migrate. Layered security is no reason to keep a broken layer underneath.

Are hardware wallets still worth it after this?

Yes. This episode doesn't show that hardware wallets are a bad idea; it shows they're a software product like any other, and that code auditing is indispensable. The practical lesson is to diversify: don't concentrate everything with a single manufacturer, use your own entropy when the device offers it, and keep a copy of the phrase off any device.

Does Alarm Crypto alert me if my wallet is moved?

No. The app tracks quotes and fires price and percentage-change alarms across 6 exchanges — it does not watch addresses, balances or on-chain transactions. For wallet surveillance you need a blockchain monitoring tool, which is a different category of product.

Conclusion

The Coldcard case is an uncomfortable reminder that "vault" is a metaphor: underneath, there is code written by people, and code carries errors that can sleep for five years. If you own an affected device, the action is simple and shouldn't wait — check where the seed was born, generate a new one on fixed firmware, test with a small amount and migrate everything. After that, distrust every email on the subject for the next few weeks.

And there's the market read the episode threw in for good measure: Bitcoin's price barely moved on an enormous story. Headlines and moves are different things. That's why it makes more sense to mark the levels that matter to you and let an alarm tell you when price gets there — preferably with a loud sound, because the market doesn't pick convenient hours. This article is informational and does not constitute investment advice.