Understand custody · A documented incident

The Hardware Wallet That Generated Keys with Too Little Randomness

On July 30, 2026, COLDCARD disclosed a dangerous firmware defect affecting hardware-wallet seed generation. Some devices created new wallets with substantially less randomness than intended.

EDITORIAL OVERVIEW · Prepared by the project editors from the sources listed below.

The defect dated back to 2021

The problem followed a software change made in 2021. Seed generation was supposed to use a hardware source of random numbers, but part of the program instead called a software generator.

Seeds created by some affected devices consequently had insufficient entropy—the measure of how unpredictable they were.

COLDCARD estimated that affected Mk3 seeds had roughly 40 bits of effective security rather than the intended minimum of 128 bits. Some Mk4, Mk5, and Q seeds could have about 72 bits.

This did not mean that two owners would necessarily receive identical words. The danger was that the number of plausible seeds became narrow enough for an attacker to search computationally.

Theft without access to the device

On July 29, owners of several wallets discovered unexpected transactions. Researchers connected the activity to the seed-generation defect the following day.

Such an attack did not require stealing the COLDCARD, learning its PIN, or infecting the owner's computer. If a seed had been created from insufficiently random data, the corresponding private key could be searched for away from the device.

Bitcoin Optech's July 31 account placed the preliminary estimated losses above 1,000 BTC and cautioned that the figure could change as the investigation developed.

Affected devices and versions

COLDCARD's official guidance lists seeds generated on Mk2 and Mk3 firmware 4.0.1 through 4.1.9; Mk4 and Mk5 firmware before 5.6.0; Q firmware before 1.5.0Q; and certain Edge releases issued before their respective fixes.

A seed safely generated elsewhere did not become weak merely because it was later imported into a COLDCARD. The defect concerned the creation of new random data inside affected firmware.

Wallets whose owners added at least 50 independent, private dice rolls during original seed creation could be an exception. The manufacturer treats those rolls as a separate source of sufficient entropy.

Why an ordinary update is not enough

Fixed firmware corrects the generation of future seeds, but it cannot change one that already exists.

Restoring an affected seed on an updated device does not make its keys safe. Cloning the wallet or creating a new backup also preserves the same old seed.

The official migration guidance calls for installing fixed firmware, generating a completely new seed, verifying the new wallet, and only then transferring funds. Old addresses should not receive new deposits.

Owners using an additional passphrase, BIP85, or multisig need to account for every related wallet and determine which ones descend from the affected original seed.

The device could appear to work normally while the space of possible seed phrases was far smaller than intended.

Sources and verification

  1. COLDCARD: official firmware upgrade guidance
  2. COLDCARD: migration guide for an affected seed
  3. Coinkite: technical background on the entropy defect
  4. Bitcoin Optech Newsletter #416: incident account and preliminary loss estimate

Documented incident. The investigation continued after the initial disclosure; the loss estimate reflects Bitcoin Optech's account published on July 31, 2026.

Unless stated otherwise, the text, conclusions, structure and editorial arrangement were created by the project editors. Facts, quotations and source materials remain attributable to their authors and rights holders.

Back to the rubric