COLDCARD vulnerability what happened, and what to do
Informational only, and this site never asks for your recovery words. details

Informational only. This is independent analysis and an evidence-backed explainer, not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite, Block, or any other party named here. Published estimates are attributed, and differing scenarios are kept separate with their assumptions. Act on your own judgement. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it. Deliberate recovery on independently verified offline equipment is a separate operation. Seed-word safety.

Incident record · disclosed 30 July 2026

For more than five years, affected COLDCARD firmware created seeds without its hardware random number generator.

A COLDCARD is intended to create recovery words using the STM32 hardware random number generator on its main chip. In affected releases from March 2021 until fixes on 31 July 2026, a build-configuration error sent seed creation to a deterministic software generator instead. Seeds generated in that window can have far fewer possible values than intended.

How much fewer depends on the model. On Mk2 and Mk3 the software generator received no cryptographic entropy at all. On Mk4, Mk5 and Q a secure-element reseed carried at most 32 bits into it, one input among several rather than the whole of the remaining strength: Coinkite estimates about 72 bits of effective search space for those models, against the 128 bits intended.

About 594 BTC moved in the attributed 30 July sweep. After identifying a third wave on 1 August, Galaxy Research put the wider attributed total at 1,367.05 BTC across 4,585 addresses, and says it has not tested whether those addresses were in fact generated with low entropy. How much of that movement the flaw itself caused is not established from public evidence.

Start here

Are your coins affected?

Six questions at most. Your answers are processed by code running in your browser and are not transmitted. This site never asks for seed words, passphrases or extended private keys.

Explore the incident

Six paths cover exposure, migration, firmware mechanics, the evidence record, the wider response and seed hygiene.

How this is evidenced

This is an independent explainer and source archive. Material claims and claim groups state how they are known and link to their evidence. Advisories can change during an incident, so earlier versions are retained: 45 reviewed changes to published source content so far, across 59 sources, alongside 24 further detected differences reviewed as capture noise or collection corrections and preserved separately.