- A Coldcard firmware flaw allowed attackers to predict some seed phrases and steal millions of dollars in Bitcoin from affected wallets.
- Coinkite released a fix and urged impacted users to create new wallets and transfer their funds immediately.
Hardware wallets offer one of the safest ways to store Bitcoin because they keep private keys offline. However, a recently discovered security flaw in some Coldcard wallets allowed attackers to steal millions of dollars in Bitcoin.
Coldcard maker Coinkite confirmed that vulnerable firmware generated predictable seed phrases. Attackers reportedly used those weak seed phrases to gain access to users’ wallets and drain their funds.
Weak Seed Phrase Generation Exposed Bitcoin Wallets
A seed phrase is the backup that gives users access to their Bitcoin wallet. If someone obtains that phrase, they can control the wallet and move the funds.
Coinkite said certain firmware versions used an insufficient source of randomness when creating seed phrases. As a result, some private keys became more predictable than they should have been.
Attackers exploited the weakness, reconstructed vulnerable seed phrases, and transferred Bitcoin from affected wallets into their own addresses.
The company described the incident as one of the most difficult moments in its history. It acknowledged both the financial losses suffered by customers and the damage to user trust.
Coinkite Takes Immediate Action
After discovering the flaw, Coinkite stopped shipping devices that contained the affected firmware. The company also destroyed its remaining inventory with the vulnerable software to prevent additional users from receiving compromised devices.
Coinkite released a firmware update that fixes the seed phrase generation issue for newly created wallets.
However, the company stressed that installing the update alone will not protect users who already created wallets with the affected firmware. Users should create a completely new wallet with a fresh seed phrase and transfer all their Bitcoin because compromised seed phrases remain vulnerable.
The company also asked customers to keep their affected devices instead of discarding them, as investigators may need them during the ongoing investigation.
Investigation Remains Underway
Coinkite is working with cybersecurity researchers, members of the Bitcoin community, and authorities in several countries to investigate the attack and identify those responsible.
The manufacturer added that its legal team is coordinating efforts to support future recovery attempts, although it cannot guarantee the recovery of the stolen Bitcoin.
Once the investigation ends, the company plans to publish a detailed technical report explaining how the vulnerability occurred and outlining the steps it will take to prevent similar incidents.
Other Coinkite Products Remain Safe
Coinkite confirmed that the vulnerability only affected specific Coldcard firmware versions. The company said Satscard, Opendime, and Tapsigner were not affected by the flaw, meaning users of those products do not need to take the same recovery steps as affected Coldcard owners.
The company also recommended that anyone looking for a new hardware wallet consider alternatives such as Bitkey, Ledger, Trezor, Jade, or BitBox. These devices remain widely used in the Bitcoin ecosystem while Coinkite continues investigating the incident.
Coinkite added that it plans to publish a detailed technical report after completing its investigation. The report will explain how the vulnerability occurred and outline the measures the company will take to prevent similar incidents in the future.
What Bitcoin Users Should Do
The Coldcard incident shows that hardware wallets remain highly secure, but firmware quality plays a critical role in protecting digital assets.
Bitcoin holders should install firmware updates only from trusted sources and monitor security announcements from wallet manufacturers. Anyone who created a wallet with the affected firmware should generate a new seed phrase, create a new wallet, and move their Bitcoin as soon as possible.
As the investigation continues, the incident serves as a reminder that strong security practices and regular software updates remain essential for protecting Bitcoin holdings.
ALSO READ: BNB Trades Around $600 as Binance Expands Into Commodity Options
Disclaimer:
This article is for informational purposes only and should not be considered financial or investment advice. Cryptocurrency investments carry risk, and readers should conduct their own research before making any investment decisions.

