Back to home
Coldcard / Coinkite Security Incident

Coldcard Firmware Scandal: Coinkite Failed. Self-Custody Did Not.

A five-year firmware error weakened seed generation across Coldcard devices and exposed Bitcoin holders to theft. Custodians are exploiting the fear. The answer is not to hand your keys to another company. The answer is to rebuild self-custody properly.

By Joe TurnerPublished 6 August 2026Last updated 6 August 2026Approximately 10 minute read

Need help working through this?

Arise Bitcoin is providing one complimentary hour of Bitcoin self-custody operational guidance to people affected or concerned by the Coldcard incident. The session can be used to understand the exposure, plan the next steps and begin getting the custody arrangement back on track. After that hour, the client can decide for themselves whether they need any further support.

Arise Bitcoin provides operational guidance only. Arise never requests or accesses seed phrases, private keys or passphrases and never signs or broadcasts transactions for clients.

Jump to immediate steps

Coinkite failed at the one job a hardware wallet must get right.

A signing device must generate private keys that nobody else can reproduce.

For years, affected Coldcard firmware did not reliably do that.

A firmware integration error caused wallet generation to use a predictable software random-number generator instead of the hardware randomness the device was supposed to rely upon. On later models, additional secure-element input was reduced to a limited reseed that still fell far below the intended security target.

Bitcoin was taken from wallets whose owners believed their keys had been generated securely and kept offline.

That is a catastrophic failure by Coinkite. It deserves direct language, full transparency and serious scrutiny from every Bitcoin holder who relied on these devices.

But a second bad conclusion is already spreading.

Custodians and exchanges are using the incident to argue that the solution to a failed hardware wallet is to surrender control of your Bitcoin to them.

That is not the antidote. The correct response is better self-custody.

What happened?

In March 2021, Coldcard firmware changed the path used to generate wallet entropy.

Entropy is the unpredictable information from which a Bitcoin wallet creates its seed and private keys. Strong entropy produces a search space so large that guessing the seed is practically impossible.

According to independent technical analysis published by Block's Bitcoin Engineering and Security teams, Coldcard's firmware contained an integration error. A configuration value disabled MicroPython's hardware random-number implementation because Coinkite had supplied a separate hardware-randomness wrapper. A supporting library checked only whether that configuration value existed, rather than whether it was enabled.

The code therefore fell back to a deterministic software generator seeded with information such as chip identifiers and timing state. The output could look random while still coming from a dangerously restricted and potentially reproducible set of possibilities.

For Mk2 and Mk3 devices running affected firmware, Block found that no cryptographically generated secret input was being added through that path. Mk4, Q and Mk5 devices added secure-element input, but only four bytes of the resulting hash reached the reseed function. That limited the securely distinguished output streams to no more than 2^32 once other state was constrained.

Hashing the output afterwards could make it look uniform. It could not create entropy that was never there.

Your master seed should not be generated by a device

The deeper lesson is bigger than Coldcard.

A Bitcoiner should generate the entropy behind their master seed themselves. That responsibility should not be delegated entirely to a hardware wallet, regardless of the manufacturer, reputation, secure element or marketing claims.

The device can assist with the process. It should not be the sole source of the secret controlling the Bitcoin.

Arise Bitcoin favours properly performed physical dice-roll entropy.

One hundred fair, independent and privately performed dice rolls provides the level of entropy required for a strong master seed.

The rolls must be genuinely random, performed privately and never photographed, recorded, entered into an online tool or retained after the seed-generation process is complete.

The point is not to create complexity for its own sake.

The point is to ensure that the Bitcoiner, rather than a manufacturer's hidden implementation, is the original source of the entropy controlling the wallet.

Arise Bitcoin teaches this process hands-on. The client generates and controls the master seed. Arise never sees, records, requests or handles the resulting seed words.

Your device should help you operate your keys. It should not be trusted to secretly invent the complete foundation of them.

How much Bitcoin was stolen?

Early reporting documented approximately 594 BTC being swept from around 500 wallets in roughly 25 minutes. Later investigations reported substantially larger numbers across further addresses and attack waves.

The important established fact is that weak Coldcard-generated seeds were exploited and real Bitcoin was taken. The total continues to evolve as on-chain investigation proceeds.

Which Coldcard devices are affected?

The following is based on Coinkite's current advisory and available independent technical research. Coinkite's claims should be weighed against the significant reputational damage caused by the incident and independently checked against external technical research where possible.

DeviceAffected firmwareAction required
Mk2 / Mk3Version 4 firmware (4.0.0 through 4.1.9 per Block; 4.0.1 through 4.1.9 per Coinkite)Update the device before creating a replacement seed. Existing affected seeds must still be replaced.
Mk4 / Mk5Earlier firmware before the identified fixed releaseUpdate before creating a replacement seed. Existing affected seeds must still be replaced.
Coldcard QEarlier firmware before the identified fixed releaseUpdate before creating a replacement seed. Existing affected seeds must still be replaced.

The dominant instruction

The firmware version that matters is the one running when the seed was originally generated. Installing new firmware today does not strengthen an old seed. Restoring the same affected seed onto a different device does not strengthen it either.

Why Arise Bitcoin favours 100 dice rolls

Coinkite has published statements about the number of dice rolls it considers sufficient for users affected by its firmware failure.

Those statements come from the manufacturer responsible for the failure.

Readers should evaluate them in light of the severe reputational damage Coinkite has suffered and the fact that trust in its seed-generation assurances is the very issue now under examination.

Arise Bitcoin does not base its custody model on the minimum number now proposed by Coinkite.

Arise favours 100 fair, independent and private dice rolls when generating master-seed entropy.

This gives the Bitcoiner a strong independently generated entropy source rather than depending on the internal randomness of any one device.

This process must be performed properly

  • use a fair physical six-sided die
  • roll it privately
  • do not photograph or record the sequence
  • do not enter the rolls into a website
  • do not allow another person to observe or retain them
  • use a trusted offline process
  • destroy any temporary written sequence after the seed has been generated and verified
  • understand recovery before funding the wallet

Adding dice rolls to an already compromised seed does not repair that seed. An affected wallet must be replaced with a newly generated seed and the Bitcoin must be migrated.

What affected Coldcard users should do now

These steps are technically demanding when meaningful Bitcoin value is involved. Stop when something is unclear.

A person who does not confidently understand seed generation, wallet fingerprints, recovery verification, address verification and controlled migration should seek help before moving funds.

Need help working through this?

Arise Bitcoin is providing one complimentary hour of Bitcoin self-custody operational guidance to people affected or concerned by the Coldcard incident. The session can be used to understand the exposure, plan the next steps and begin getting the custody arrangement back on track. After that hour, the client can decide for themselves whether they need any further support.

Arise Bitcoin provides operational guidance only. Arise never requests or accesses seed phrases, private keys or passphrases and never signs or broadcasts transactions for clients.

1

Do not use a seed-checking website

No legitimate test requires you to type your seed words into a website, form, app, chatbot or support service. Anyone requesting your seed phrase, private key or passphrase should be treated as hostile.

2

Establish how the wallet was created

Record the Coldcard model, the approximate wallet-creation date and the firmware version running when the seed was generated. Do not publish this information together with wallet balances, addresses or personal details.

3

Install fixed firmware before creating anything new

Download firmware only from the official Coldcard website. Verify the firmware file and its signature before installing it. Where practical, check it against independent sources.

4

Generate a completely new master seed

Create a new seed only after the device has been updated, or use another appropriately assessed signing device. Use 100 properly performed private dice rolls so the Bitcoiner, not the device, is the original source of the entropy. Never reuse or modify the compromised seed. Verify recovery before funding the replacement wallet.

5

Verify the new wallet before relying on it

Record and verify the new backup. Confirm the wallet fingerprint. Verify a receiving address on the signing device itself. Confirm that the wallet can be fully recovered independently.

6

Send a small test transaction

Send a small amount to the new wallet. Confirm that the correct wallet receives it and that you can access and understand the new setup.

7

Move the remaining Bitcoin

Return to the affected wallet and move the remaining balance to the verified address controlled by the new seed. Check the destination address on the signing device before proceeding.

8

Confirm the migration

Confirm the complete intended balance has arrived and received the required confirmations. Keep the old backup until the migration is fully verified. Only then retire the old arrangement in a controlled manner.

Service boundary

Arise Bitcoin provides process guidance and operational support only. Clients remain responsible for their devices, keys, backups, addresses, amounts, transactions and outcomes. Arise Bitcoin does not request or access seed phrases, private keys or passphrases and does not sign or broadcast transactions for clients.

Custodians and exchanges are trying to exploit this tragedy

The Coldcard failure has created fear, confusion and urgency.

Custodians and exchanges are already using that fear to encourage Bitcoin holders to hand over their keys.

That is completely wrong.

A company should not exploit losses caused by one failed custody product to sell a different form of dependency.

Moving Bitcoin to a custodian does not eliminate risk. It transfers key control to the custodian and introduces:

  • counterparty risk
  • withdrawal risk
  • solvency risk
  • internal fraud risk
  • regulatory risk
  • operational risk
  • identity and account risk
  • concentration of control

The holder exchanges a technical self-custody problem for reliance on another company. That may feel easier in the moment, but it moves the person further away from the direct ownership Bitcoin was designed to make possible.

The answer to failed self-custody implementation is not custodial surrender. The answer is to rebuild the self-custody arrangement properly.

Do not allow Coinkite's failure to become a sales funnel for companies that want control of your keys.

A hardware wallet is not a complete custody plan

Buying a respected device is not the same as building a sound self-custody operating model. A hardware wallet is one component.

A complete arrangement also includes how the seed is generated, which sources of entropy are trusted, whether a passphrase is used, how backups are created, whether recovery has been tested, how firmware is maintained, how transactions are verified and how changes are documented.

The Coldcard incident exposed a dangerous assumption: that because a device was air-gapped and seed words had never touched the internet, the seed itself must have been securely generated.

Offline does not automatically mean unpredictable. A device can remain completely disconnected from the internet and still generate weak private keys.

The durable lessons from the Coinkite failure

Lesson 1

Generate the master seed yourself

A Bitcoiner should not delegate the full creation of their master seed to any device. Arise Bitcoin favours 100 private physical dice rolls so the wallet's foundation originates with the Bitcoiner rather than a manufacturer's internal implementation.

Lesson 2

Manufacturer trust is not a security model

Documentation, reputation and a long history in the market do not replace independently generated entropy, tested recovery and a custody process the owner actually understands.

Lesson 3

Seed generation is the foundation

An air gap, secure element and strong enclosure cannot compensate for a seed generated from inadequate entropy. The key-generation step is the most important step in the entire custody process.

Lesson 4

A passphrase can create separation

A strong, unique and recoverable BIP-39 passphrase can prevent a weak base seed from immediately revealing the funded wallet. A forgotten passphrase can also permanently prevent recovery.

Lesson 5

Multisig needs genuine diversity

A multisig arrangement built entirely from affected devices made by one manufacturer may preserve the same common failure across every key. Multiple devices are not meaningful redundancy when they share the same defect.

Lesson 6

Firmware maintenance is custody maintenance

Self-custody is not set and forget. Firmware, wallet software, documentation, backups and recovery procedures must be reviewed over time.

Lesson 7

Operational competence beats brand loyalty

The goal is not to defend or attack a manufacturer. The goal is to understand the complete custody system well enough to detect assumptions, contain failures and recover safely.

Did self-custody fail?

No. Coinkite failed.

Self-custody does not mean blindly trusting a hardware-wallet company. It means taking direct responsibility for the system controlling your keys, including recognising that every device, manufacturer, software package and human procedure introduces assumptions.

Good self-custody reduces those assumptions, separates critical secrets, creates recovery paths and avoids allowing one company to become the entire security model.

The Coldcard failure should make self-custody more mature. It should not make Bitcoin holders run back into the arms of custodians.

The Arise Bitcoin position

Coinkite failed. The failure affected the most important part of a hardware wallet's job: the creation of the secret controlling the Bitcoin.

Affected users should act carefully and promptly.

Coinkite's current claims should be treated as claims from a manufacturer whose credibility has been severely damaged, not as the final independent authority on the incident.

Custodians and exchanges should not exploit the losses to pull more Bitcoin under corporate control.

Arise Bitcoin's position is clear:

  • the Bitcoiner should generate the master-seed entropy
  • 100 properly performed private dice rolls should be used
  • the device should not be the sole source of the master secret
  • recovery must be verified before the wallet is funded
  • compromised seeds must be replaced, not patched
  • migrations should be controlled and tested
  • documentation should explain the process without exposing secrets
  • the client must remain in control

Arise Bitcoin teaches this process hands-on without seeing, storing or accessing the client's seed phrase, private keys or passphrase.

Hold Your Own.

Coldcard firmware scandal FAQ

No. Fixed firmware corrects future seed generation. It does not add entropy to a seed that was previously created on affected firmware. An affected seed must be replaced and the Bitcoin migrated to addresses controlled by the new seed.

According to Coinkite's current advisory, seeds generated on Mk4 and Mk5 before the identified fixed standard firmware, and Q before its corresponding fixed release, are affected. Their estimated entropy was higher than the worst affected Mk2 and Mk3 releases, but still below the intended security target. These claims come from the manufacturer responsible for the failure and should be assessed alongside independent technical research.

Arise Bitcoin's position is no. The Bitcoiner should generate the entropy controlling the master seed rather than relying entirely on the internal randomness of a device. Arise teaches a client-operated process using 100 private physical dice rolls. The client alone generates and controls the resulting seed.

Arise Bitcoin favours 100 fair, independent and private physical dice rolls when generating a new master seed. Coinkite has published a lower figure, but that statement comes from the manufacturer responsible for the affected implementation and should be evaluated accordingly. Dice rolls do not repair an existing compromised seed. A new seed and controlled migration are required.

A strong and unique BIP-39 passphrase adds an independent secret an attacker must also discover. It reduces immediate exposure but does not repair the base seed. A strong, memorable and properly backed-up passphrase reduces risk in the interim; migration to a newly generated seed remains the correct long-term step.

That replaces self-custody execution risk with counterparty risk. A custodian controls the keys and ultimately controls withdrawal access. Custodians and exchanges using the Coldcard incident as a sales opportunity are exploiting a tragedy for commercial gain. The correct response is to rebuild self-custody properly, not to surrender key control to another company.

No. Bitcoin's consensus system and underlying signature cryptography were not broken. The failure occurred in Coinkite's implementation of seed generation within its Coldcard firmware.

Arise Bitcoin provides Bitcoin-only self-custody operational guidance. A complimentary one-hour session is available to help affected or concerned holders understand the issue and establish a controlled path forward. Arise never requests or accesses seed phrases, private keys or passphrases and never signs or broadcasts transactions for clients.

JT

Joe Turner

Founder, Arise Bitcoin

Joe provides Bitcoin-only self-custody operational guidance for individuals, families and SMSF trustees. Arise Bitcoin helps clients understand, implement, document, review and strengthen practical self-custody arrangements without taking custody of keys or providing financial advice.

Get your custody arrangement back on track

The Coldcard remediation process is technical, but you do not need to improvise it alone.

Arise Bitcoin is providing one complimentary hour of Bitcoin self-custody operational guidance to affected or concerned Bitcoin holders. Use the session to understand the exposure, review the required steps and begin building a controlled migration plan. After that hour, you decide whether you need anything further.

Arise Bitcoin never requests or accesses seed phrases, private keys or passphrases. The client remains the sole operator and custodian of their Bitcoin.

Hold Your Own.

Primary sources and further reading

Coinkite publications are included because they contain the manufacturer's current firmware and remediation statements. Their inclusion does not constitute independent verification, and readers should assess them in the context of the company's significant loss of credibility following this incident.
  1. 1.Block Engineering, Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware (independent technical analysis)
  2. 2.CoinDesk, initial 594 BTC sweep report
  3. 3.The Hacker News, later technical and on-chain reporting
  4. 4.Coinkite, Coldcard Security Advisory (manufacturer publication)
  5. 5.Official Coldcard firmware downloads (manufacturer publication)
  6. 6.Official Coldcard firmware upgrade instructions (manufacturer publication)

Sources accessed 6 August 2026. Incident figures and official guidance may change as investigations continue.