OTHER

Important Seed Migration Update for Coldcard Users

On August 1, Mishaboar, a prominent figure in the Dogecoin community, urged users of Coldcard to transfer their Bitcoin to wallets established with fresh seed phrases.

Overview

  • Over three suspected attack occurrences, 1,367.05 BTC, valued at around $88.6 million, was withdrawn from 4,585 wallets.
  • Coinkite noted that although firmware updates can secure new seeds, they do not rectify vulnerable seed phrases from earlier firmware versions.
  • Mishaboar warned users against reusing compromised seeds or entering recovery phrases on devices connected to the internet.

This alert followed an analysis by Galaxy Research, which found that 1,367.05 BTC—approximately $88.6 million—was withdrawn from 4,585 wallets during three suspected attack incidents.

Mishaboar stated, “If you have ever used any COLDCARD device, transfer your funds to a new wallet immediately.” He stressed the importance of not reusing any compromised Coldcard seed phrases or inputting recovery phrases on online-connected devices. His warnings extended past Coinkite’s official security advisory, which outlines affected firmware versions and specific exceptions.

Rising Coldcard losses as attackers target smaller wallets

Galaxy Research’s latest on-chain analysis indicated that 1,367.05 BTC was lost across three suspected attack waves. The firm described these losses as an “estimated observed size,” meaning the total remains unverified by Coinkite, law enforcement, or affected users.

The first wave drained 1,082.65 BTC from 1,196 addresses in roughly 41 minutes on July 30. In the subsequent third wave, about 208 BTC was extracted from 1,912 addresses, with the average balance per address reducing to just over 0.1 BTC. This indicates that attackers shifted their focus from larger sums to smaller wallets.

Galaxy noted that each wave appeared to be linked to a single operator; however, it could not conclusively verify if the same attacker carried out all three incidents. The third group employed different destination addresses, merging multiple victims into single transactions while only checking the standard derivation path, which differed from earlier waves.

The research team remarked that its known transaction patterns might not represent every theft case. Other attackers could execute legitimate transactions without replicating the fees, destination formats, or collection methods observed in the initial three waves.

Specific firmware advisory from Coldcard

Coinkite disclosed that the vulnerability impacts seeds generated on Mk2 and Mk3 devices with firmware versions 4.0.1 to 4.1.9. Additionally, seeds created on Mk4 and Mk5 devices prior to standard version 5.6.0 or Edge version 6.6.0X are affected. For Coldcard Q, the updated releases are standard version 1.5.0Q and Edge version 6.6.0QX.

Coldcard Mk1 devices are not affected by the firmware issue highlighted by Block’s researchers. Coinkite clarified that TAPSIGNER, OPENDIME, and SATSCARD remain secure due to their different codebases. Thus, current technical evidence suggests that not all Coinkite products are compromised.

Block’s Bitcoin engineering and security team identified the flaw as stemming from a firmware integration error. The flawed software utilized a deterministic MicroPython fallback instead of the intended STM32 hardware random-number generator during wallet secret creation. This resulted in insufficient cryptographic entropy on Mk2 and Mk3 v4 firmware paths. Newer models received a limited secure-element reseed.

Block mentioned that its analysis represents its technical perspective but does not account for comprehensive empirical testing across all devices. Coinkite has announced that its investigation is ongoing and a formal technical report will be released soon.

Firmware updates cannot fix existing seeds

Coinkite has deployed updated firmware for all affected models and release tracks. While these updates correct the seed-generation process for newly created wallets, they cannot enhance randomness for previously generated seed phrases. Using the same vulnerable phrase on different hardware or software wallets continues to be risky.

Affected users are encouraged to install the relevant updated firmware before generating a new seed. Coinkite recommends documenting and verifying the new backup, ensuring the receiving address displays accurately on the device screen, and performing a small test transaction prior to transferring the full balance.

Users should retain the old backup until the entire migration process is confirmed. Mishaboar also advised against entering seed phrases on a computer, suggesting offline copies should be kept in multiple secure locations to reduce exposure to phishing, malware, and cloud synchronization during an urgent migration.

Coinkite indicated a narrow exception for users who completed at least 50 fair, independent, and private dice rolls before generating the final seed words, contributing a minimum of 128 bits of independent entropy. Users with fewer than 50 rolls, those uncertain of the number, or those who exposed the roll sequence should migrate.

A robust, unique BIP-39 passphrase adds extra security; however, Coinkite emphasized that it does not resolve a compromised seed. Short, reused, or predictable passphrases are susceptible to guessing. Even users with strong passphrases should change the underlying seed as soon as possible.

Coldcard incident sparks conversations about self-custody

Bitcoin investor Anthony Pompliano pointed out that the losses reveal the technical challenges of self-custody, despite individuals having direct control over their assets. He highlighted that the Bitcoin protocol itself remains intact, as the issue arose within third-party wallet firmware.

This distinction is important, as an attacker reportedly duplicated weak wallet keys offline. The incident did not involve tampering with Bitcoin transactions, jeopardizing its cryptography, or undermining the network’s consensus mechanisms. Once an attacker possesses a valid private key, the resulting transaction shows on-chain as if it came from the legitimate owner.

Reported losses grew from an initial estimate of 594.48 BTC to 1,367.05 BTC as researchers identified additional address groups. A related report from crypto.news discussed how the firmware build error compromised seed generation for over five years.

The incident has provoked discussions regarding U.S. institutional custody. According to crypto.news, Bloomberg ETF analyst Eric Balchunas stated that the losses reinforce the case for spot Bitcoin ETFs among investors seeking price exposure without the complexities tied to managing private keys. While ETFs simplify personal seed management, they also introduce new risks associated with institutional custody and counterparty exposure.

Future updates will include Coinkite’s upcoming technical review and further Galaxy address evaluations. Meanwhile, the current on-chain loss estimate of $88.6 million remains preliminary and not definitively finalized. Users affected by the official warning now face the urgent task of installing corrected firmware and transferring their funds to entirely new seed phrases.