Logo
Home
Archives
Premium
Donate
Media Kit
Recommendations
Tags
Login
Subscribe
Logo
  • Home
  • Posts
  • 🚨 If your seed was born on a Coldcard, read this now

🚨 If your seed was born on a Coldcard, read this now

The firmware update does not fix your seed. This is what does.

We don't normally land in your inbox like this. Today earns the exception. This is a public service announcement; nobody paid for it.

Last Wednesday night (US time) an attacker began sweeping funds from wallets whose seeds were generated on Coldcard devices. Within four days the tally passed 1,700 BTC, well over $100 million, across four separate waves. The sweeps are still happening. This was no phishing wave or database leak. A firmware bug quietly weakened the random number generator behind seed creation, shipped in 2021, and sat unfixed for five years until someone chose to exploit it.

Coinkite has owned the failure, shipped emergency firmware, halted sales, and destroyed affected stock. But here is the part too many people are getting wrong, and the reason this email exists:

The firmware update protects seeds you create from now on. It does nothing for the seed you already have.

One more uncomfortable fact: Coinkite says it has now emailed every address it could still reach, but many buyers are years past any record, and a wave of fake "Coinkite" emails from lookalike domains is riding the same news. So treat this as your real notification, and treat any email that asks you to click or verify as an attack.

Are you affected? 60 seconds

  1. Was your seed generated on a Coldcard (any model) running firmware 4.0.0 or later, meaning any time since March 2021? If your seed was created elsewhere and merely imported to the device, this bug is not your bug. Stay for the anti-scam section anyway.

  2. Did you add your own entropy with 50 or more dice rolls, or protect the wallet with a long passphrase? You are in materially better shape. A short passphrase does not count: the first confirmed drain of a Mk3 protected by a two word passphrase was reported Sunday. Treat a short or guessable passphrase with the same urgency as none at all, and remember wallets with transaction history are being targeted first.

  3. Plain single-sig on a seed generated on a Coldcard, no dice, no passphrase? Treat the seed as compromised and plan to move today.

  4. Multisig users: check where each key was born. A 2-of-3 built entirely from keys generated on Coldcards inherits the full problem and deserves single-sig urgency. A quorum that mixes vendors with one Coldcard key means your funds are safe, but rotate that key this week.

The fix is rotation. Move first, update later

  1. Move your funds before you touch the firmware. Several users reported devices refusing to boot after the emergency update this weekend. Coinkite has not confirmed how widespread that is, and there are recovery paths, but Jameson Lopp's advice stands: migrate first, upgrade after.

  2. Do not wipe the old seed and generate a new one on the same device. Casa CEO Nick Neuman flagged this pattern directly: it stakes everything on one device that is already suspect. Move to a different wallet instead: another hardware device, a fresh software wallet as a temporary landing spot, or a multisig.

  3. Send a small test amount first. Confirm you can see it and, importantly, spend from it. Then sweep the rest. Watch the fee environment; a lot of bitcoin is on the move.

  4. Only then update the firmware on the emptied device, and only from coldcard.com/downloads. (Mk3: 4.2.0 or later, Mk4/Mk5: 5.6.0 or later, Q: 1.5.0Q or later.) If a device holding nothing gets bricked, that is an annoyance, not a catastrophe, and Coinkite's Bless Firmware option and SD card recovery can usually revive it.

  5. Update every place your old addresses live: exchange payout addresses, lending platforms, inheritance documents, your own muscle memory.

Need a clean device today? Coinkite's own Sunday update names Bitkey, Ledger, Trezor, Jade and Bitbox as reputable hardware alternatives. We would add SeedSigner, the open source signer you build yourself from cheap off the shelf parts.

Our pick if you want something in the mail today: Jade Plus draws its randomness from several independent sources at once (its hardware generator, the camera, your input, and the companion app), and both its hardware and firmware are public for review. Our link takes 10% off automatically, and code JADEPLUSEXPRESS at checkout adds free expedited shipping. Full disclosure: it is an affiliate link, so the newsletter earns a cut. The discounts are yours either way.

Away from your wallet right now? Don't wait until you get home. If someone you trust can reach the device or the safe, talk them through the move. That is exactly how 10 BTC got rescued this weekend: a bitcoiner stuck out of town had a friend run to his house, open the safe, and move the funds out of reach until he got back.

Already hit? Preserve the device, the seed backup, and every log as evidence. File a police report and document everything; Coinkite has said it will support victims with reports and insurance claims. As Samson Mow laid out this weekend, paper trails matter, and any "recovery service" that contacts you is a scam.

Jameson Lopp put it best: do not panic, and do not rush. Yes, the sweeps are ongoing, so this belongs at the top of your list today. But most disasters in self custody are of the victim's own making: fumbled sweeps, seed phrases typed into laptops, "support agents" sliding into your DMs.

Speaking of which:

  • No one legitimate will DM or email you asking to click, verify, or "check" anything. A confirmed phishing wave is impersonating Coinkite from lookalike domains right now. Real Coinkite mail comes from coinkite.com, and even then: don't click, type the address yourself.

  • Never type your seed into a website, an app, or a "checker" of any kind. No legitimate tool asks for your seed.

  • Download firmware only from coldcard.com. Bookmark it. Don't Google it.

The bigger lesson

Coldcard is a good device made by capable people, and this still happened. That is the real takeaway. Every vendor is fallible: every device, every supply chain, every review process. If your security depends on one company being perfect forever, you are one commit away from a very bad Wednesday.

The setup that survives the next bug is multivendor multisig: multiple keys, on hardware from different vendors, so no single company's mistake can touch your funds. People who held their bitcoin this way slept through this week. For them, this whole event amounts to one calm key rotation. No evacuation needed.

If you want that setup, these are the serious options right now. Even Coinkite's own Sunday update points people to most of them:

  • Casa: guided multivendor vaults where a human walks you through setup and key rotation, and they never hold your keys. CEO Nick Neuman published a free walkthrough on migrating from a Coldcard, and notes you can pair an existing Coldcard straight into a vault: the multisig becomes your new wallet, and the weak key rotates out on your schedule. Advisors are running free consults through the crisis.

  • Unchained: collaborative custody 2-of-3; they are telling clients to rotate any key born on a Coldcard, most urgently vaults holding two of them.

  • AnchorWatch: multisig custody with actual Lloyd's of London insurance on the vault, up to $100M. Their CEO Rob Hamilton has been one of the heroes of the weekend, publishing one of the clearest technical breakdowns of the bug and answering questions nonstop. Worth a follow.

  • Bitkey: Block's 2-of-3 that splits keys across your phone, the hardware, and Block's servers. There is no seed phrase anywhere in the flow, which makes it a clean break from the failure mode that caused this mess. Confirmed unaffected. And credit where due: when a researcher disclosed a separate Bitkey issue this weekend (no funds at risk), Bitkey engineering lead Clay Garrett handled it in the open: same day patch, live Q&A Space, reporter credited. That is what good incident response looks like. Also worth a follow.

  • Nunchuk: multisig-focused wallet for mobile and desktop with collaborative custody and inheritance features.

  • Liana: free, open source miniscript wallet from Wizardsardine with timelocked recovery paths; their team published its own migration advisory this weekend.

  • DIY: Sparrow plus devices from different vendors, if you would rather hold every key yourself.

Stay calm, verify everything, and rotate like it's routine. Because done right, it is. One last thing: check on your people. If you know someone running a Coldcard, forward them this email. Bitcoiners take care of bitcoiners.

Naiw
Bitcoin Breakdown

background

Bitcoin-only daily newsletter with the highest signal-to-noise ratio in the industry

© 2026 Proof of Press LLC.
beehiivPowered by beehiiv