The Troubles with ColdCard
2026-08-01
This is a difficult moment for the Bitcoin community.
In short: If you generated a seed phrase on a Coldcard device, act now and move your bitcoin. A "seed" is, in practice, your 12 words, and in this case the problem is that they have been more predictable than usual, even though everything looks normal on the surface — read on for technical details.
A critical entropy failure in Coldcard hardware wallets has been disclosed. Unlike the collapses of Mt. Gox, Quadriga, or FTX, this incident did not involve an exchange or trading venue. It affected users who followed best practices by generating their own keys on a hardware device that many in the industry had long recommended as a secure option for self-custody. As of now, approximately 594 BTC has been stolen from roughly 500 affected wallets.
Bitcoin's underlying cryptography remains intact. The problem was in the seed-generation process on certain Coldcard firmwares, which in some cases produced seeds with far less entropy than intended — in some cases as low as 40–72 bits instead of the intended 128. Low-entropy seeds are not visually distinguishable from secure ones until they are exploited.
Our position
BTCX has never recommended or promoted Coldcard devices. We have exclusively directed customers toward Trezor hardware wallets. Security is a continuously moving target. For any meaningful amount of bitcoin we continue to recommend diversified setups — different hardware vendors, multisignature configurations, and strong external entropy or passphrases where appropriate. Note that a multisignature setup built entirely from affected Coldcard devices does not provide protection; at least one key must come from an unaffected source.
Immediate action required
If you are currently using an affected Coldcard wallet — specifically any seed generated on a Mk3 running firmware 4.0.1 through 4.1.9, or on Mk4/Mk5 before firmware 5.6.0 (standard) or 6.6.0X (Edge), or on Q before firmware 1.5.0Q (standard) or 6.6.0QX (Edge), without a strong passphrase or sufficient independent dice-roll entropy — do not wait.
Move your bitcoin now.
Use a high fee so your transaction is unlikely to be displaced by a replace-by-fee attempt from an attacker who may already be monitoring or racing the same UTXOs. Take a moment to carefully verify the receiving address before sending — in a time-sensitive situation, a rushed or mistyped transfer is itself a common cause of lost funds.
Updating your device's firmware does not repair an already-compromised seed. Funds must be actively moved to a new, securely generated wallet.
Once the funds are moved to a secure new setup, you can take the time to build a more robust long-term custody arrangement. Do not leave significant value on any single-signature seed that was generated under the vulnerable conditions.
Going forward
This event is a reminder that no single device or vendor is a permanent guarantee. Review your own setup. Prefer multisignature with keys generated on independent devices from different manufacturers. Verify entropy sources. Keep your recovery processes tested and private.
We are monitoring the situation closely and will issue further updates if new information becomes available. If you have questions about migrating from an affected device, verifying whether your setup is at risk, or strengthening your current setup, contact support through the usual channels — we're here to help, and it's always better to ask than to guess.
Stay safe, and Stay Sovereign.
— The BTCX Team
Ready to start your Bitcoin journey?
BTCX is Sweden's first Bitcoin exchange. With us, you can buy bitcoin quickly and securely. Experience safety and simplicity when investing in the currency of the future!