- What Broke Coldcard's Bitcoin Security?
- When Hardware Wallets Fail at Their Most Important Job
- Understanding Seed Entropy
- What Went Wrong Inside Coldcard?
- How the Vulnerability Went Undetected for Years
- Why This Wasn't a Traditional Hack
- How the Attack Unfolded
- Why Air-Gapped Wallets Didn't Help
- Open Source Wasn't Enough
- A Wake-Up Call for the Hardware Wallet Industry
- What Should Coldcard Users Do?
- Final Thoughts
- More Blog Posts
- Subscribe to newsletter
Written by Maheswaran
What Broke Coldcard's Bitcoin Security?
A firmware bug in Coldcard hardware wallets reduced seed entropy, allowing attackers to recreate wallet seeds and steal over $89 million in Bitcoin. Here's what happened, why it matters, and what the entire crypto industry should learn.
When Hardware Wallets Fail at Their Most Important Job
For years, hardware wallets have been considered the gold standard for Bitcoin security, promising to keep your private keys offline, protect your recovery phrase, and ensure your seed never touches the internet.
The recent Coldcard incident proved that following all of these rules still isn't enough if the wallet generates a weak seed in the first place.
Over 4,585 Bitcoin addresses have already been compromised across three attack waves, with approximately 1,367 BTC (around $89 million) stolen. The wallets weren't hacked through malware, phishing, or internet connectivity. Instead, the vulnerability existed from the moment the recovery phrase was created.
This incident isn't just a Coldcard story - it's a reminder that cryptographic randomness is the foundation of digital asset security.
Understanding Seed Entropy
Every Bitcoin wallet begins with a recovery phrase.
Those familiar 12 or 24 words are simply a human-readable representation of a randomly generated cryptographic number.
For a standard 12-word wallet, that randomness equals 128 bits of entropy, creating approximately:
2¹²⁸ possible combinations
That's roughly 340 undecillion possible seeds which is far beyond anything that can realistically be brute-forced.
Everything about Bitcoin security depends on achieving that level of randomness.
If entropy decreases, so does security.
What Went Wrong Inside Coldcard?
The vulnerability originated in firmware released during March 2021.
Coldcard devices include a hardware True Random Number Generator (TRNG) specifically designed to generate unpredictable randomness.
However, during a cryptographic library migration, a build configuration mistake caused firmware to reference a software pseudo-random number generator instead of the intended hardware entropy source.
The hardware randomness still existed.
It simply wasn't being used.
Because of this, recovery seeds generated on affected firmware contained substantially less randomness than intended.
Instead of producing fully unpredictable 128-bit seeds, researchers estimate:
Device | Intended Entropy | Estimated Effective Entropy |
Mk2 / Mk3 | 128 bits | ~40 bits |
Mk4 / Mk5 / Q | 128 bits | ~72 bits (Coinkite estimate, though some researchers estimate lower) |
The exact entropy for later devices remains debated, but all parties agree affected firmware produced weaker randomness than designed.
How the Vulnerability Went Undetected for Years
The bug wasn't discovered overnight. It remained hidden for more than five years before attackers began exploiting vulnerable wallets. The sequence below shows how a small firmware mistake evolved into one of the largest hardware wallet security incidents in Bitcoin's history.
Why This Wasn't a Traditional Hack
Many headlines described the incident as hackers "brute-forcing" wallet seeds.
That isn't technically accurate.
Brute-forcing a genuine 128-bit seed is practically impossible.
Instead, attackers exploited predictable randomness.
Rather than searching through an unimaginably large keyspace, they recreated the same deterministic process used by vulnerable firmware.
In other words:
- They didn't guess the keys.
- They regenerated them.
That distinction explains why offline storage offered no protection.
How the Attack Unfolded
Galaxy Research tracked the exploit across three coordinated waves.
The first wave drained more than 1,082 BTC from 1,195 wallets within roughly 41 minutes.
Additional waves increased the total losses to:
- 4,585 compromised wallets
- 1,367 BTC stolen
- Approximately $89 million
- Funds remaining largely unspent during initial investigations
Researchers also observed that higher-value wallets were targeted first, suggesting attackers had already generated a database of vulnerable addresses before broadcasting transactions.
Why Air-Gapped Wallets Didn't Help
One of the biggest misconceptions in crypto security is that offline equals secure.
Air-gapped devices prevent remote compromise.
They do not protect against weak cryptographic keys.
If the seed phrase itself lacks sufficient entropy, every private key derived from it becomes vulnerable, regardless of whether the wallet ever connects to the internet.
This incident demonstrates an important security principle: A wallet is only as secure as the randomness used to create its keys.
Open Source Wasn't Enough
Coldcard firmware is publicly available, yet this issue remained unnoticed for more than five years.
Open source offers transparency. It does not guarantee review.
Complex firmware often contains thousands of lines of code, build configurations, compiler directives, and cryptographic dependencies that few people thoroughly audit.
Security comes from independent verification, not simply public availability.
A Wake-Up Call for the Hardware Wallet Industry
The broader lesson extends far beyond one manufacturer.
Modern hardware wallets increasingly advertise:
- Secure elements
- Air-gapped signing
- Tamper resistance
- Open-source firmware
But none of those features matter if entropy generation isn't independently validated.
Security practitioners have pointed to standards like NIST SP 800-90B, which defines rigorous methods for validating entropy sources used in cryptographic systems. While hardware wallets aren't required to follow these standards today, the incident has sparked renewed discussion around adopting stronger entropy validation practices across the industry.
Future hardware wallet assurance should include:
- Independent entropy validation
- Verification of the actual firmware execution path
- Firmware-specific certification
- Public transparency around audited firmware versions
Randomness should become a first-class security requirement.
What Should Coldcard Users Do?
If your wallet was created using affected firmware, updating the device alone is not enough.
The existing seed remains weak.
Users should:
- Update to the latest firmware.
- Generate a brand-new recovery phrase.
- Move all funds to addresses derived from the new seed.
- Never reuse the compromised recovery phrase.
- Consider supplementing hardware-generated entropy with manual dice rolls where supported.
Once a weak seed exists, the only permanent solution is migration.
Final Thoughts
The Coldcard exploit wasn't caused by a failure in Bitcoin. It wasn't caused by cryptographic weakness and by users making poor security decisions.
It was caused by one of the most fundamental assumptions in cryptography breaking silently: randomness.
The incident should serve as a turning point for hardware wallet manufacturers and the wider self-custody ecosystem. As digital assets continue to grow in value, secure key generation deserves the same level of scrutiny as secure key storage.
At Encapsulate, we believe self-custody security depends not only on protecting private keys after they're created, but also on ensuring they're generated with truly unpredictable entropy from the very beginning.
More Blog Posts




.png&w=1920&q=75)
.png&w=1920&q=75)
.png&w=1920&q=75)
.png&w=1920&q=75)
.png&w=1920&q=75)













.png&w=1920&q=75)
.png&w=1920&q=75)
.png&w=1920&q=75)
.png&w=1920&q=75)
.png&w=1920&q=75)









