OTHER

Important Update on Seed Migration for Coldcard Users

On August 1, Mishaboar, a key member of the Dogecoin community, advised Coldcard users to move their Bitcoin to wallets set up with new seed phrases.

Overview

  • In three documented events, 1,367.05 BTC—around $88.6 million—was withdrawn from 4,585 wallets.
  • Coinkite mentioned that while firmware updates can enhance the security of new seed phrases, they do not rectify vulnerabilities tied to seed phrases generated with older firmware.
  • Mishaboar warned against reusing compromised seeds or entering recovery phrases on internet-connected devices.

This warning followed an analysis by Galaxy Research that found 1,367.05 BTC—approximately $88.6 million—was taken from 4,585 wallets during three suspected attack incidents.

Mishaboar emphasized, “If you’ve ever used any COLDCARD device, transfer your funds to a new wallet immediately.” He highlighted the importance of not reusing any compromised Coldcard seed phrases or entering recovery phrases on connected devices. His alerts extended beyond Coinkite’s official security bulletin, which specifies affected firmware versions and particular exceptions.

Increasing Coldcard losses as smaller wallets become targets

Recent blockchain analysis from Galaxy Research revealed that 1,367.05 BTC was lost across three suspected attack waves. The company described these losses as an “estimated observed size,” indicating the total amount has yet to be confirmed by Coinkite, law enforcement, or affected users.

The initial wave resulted in the loss of 1,082.65 BTC from 1,196 addresses within around 41 minutes on July 30. In the last wave, about 208 BTC was withdrawn from 1,912 addresses, with the average balance per address dropping to just over 0.1 BTC. This trend indicates that attackers are shifting their focus from larger amounts to smaller wallets.

Galaxy found a link between each wave and a single operator; however, it could not determine if the same attacker was behind all three incidents. In the third wave, different destination addresses were employed, merging multiple victims into individual transactions while strictly following the standard derivation path, which differed from the earlier waves.

The research team pointed out that the identified transaction patterns may not capture every instance of theft. Other attackers could be conducting legitimate transactions without mimicking the fees, destination formats, or collection methods seen in the initial three waves.

Targeted firmware advisories from Coldcard

Coinkite confirmed that the vulnerability affects seeds generated on Mk2 and Mk3 devices with firmware versions 4.0.1 to 4.1.9. Additionally, seeds created on Mk4 and Mk5 devices prior to standard version 5.6.0 or Edge version 6.6.0X are at risk. For Coldcard Q, the updated releases are standard version 1.5.0Q and Edge version 6.6.0QX.

Researchers from Block determined that Coldcard Mk1 devices are not affected by the identified firmware issue. Coinkite also confirmed that TAPSIGNER, OPENDIME, and SATSCARD remain secure due to differing codebases, indicating that not all Coinkite products are vulnerable.

Block’s Bitcoin engineering and security team traced the vulnerability to a firmware integration error. The flawed software employed a deterministic MicroPython fallback instead of the correct STM32 hardware random-number generator during wallet secret creation, leading to insufficient cryptographic entropy on Mk2 and Mk3 firmware v4 paths. Newer models included limited secure-element reseeding.

Block noted that its analysis offers a technical overview but does not encompass comprehensive empirical testing across all devices. Coinkite has indicated that its investigation is ongoing, with a formal technical report anticipated soon.

Firmware updates do not rectify existing seeds

Coinkite has released updated firmware for all affected models and branch versions. While these updates enhance the seed-generation process for new wallets, they do not improve the randomness of previously generated seed phrases. Continuing to use the same vulnerable phrase across different hardware or software wallets poses a significant risk.

Affected users are encouraged to install the relevant updated firmware before generating a new seed. Coinkite advises documenting and verifying the new backup, ensuring that the receiving address accurately displays on the device screen, and conducting a small test transaction prior to transferring the entire balance.

Users should retain the old backup until the entire migration process is confirmed. Mishaboar further cautioned against entering seed phrases on a computer, recommending the secure offline storage of copies in multiple locations to reduce risks from phishing, malware, and cloud synchronization during a critical migration.

Coinkite mentioned a narrow exemption for users who completed at least 50 fair, independent, and private dice rolls before finalizing the seed words, contributing at least 128 bits of independent entropy. Users with fewer than 50 rolls, those uncertain of the count, or those who exposed the roll sequence should migrate.

A strong, unique BIP-39 passphrase boosts security; however, Coinkite highlighted that it does not rectify a compromised seed. Short, reused, or predictable passphrases can be easily guessed. Even users with strong passphrases should prioritize changing the underlying seed promptly.

The Coldcard incident reignites debates on self-custody

Bitcoin investor Anthony Pompliano noted that the losses underscore the technical challenges linked to self-custody, despite individuals maintaining direct control over their assets. He pointed out that the Bitcoin protocol remains intact; the issues arose from third-party wallet firmware.

This distinction is crucial, as attackers allegedly replicated weak wallet keys offline. The incident did not entail altering Bitcoin transactions, compromising its cryptography, or disrupting the network’s consensus mechanisms. Once an attacker possesses a valid private key, any resulting transaction appears on-chain as if it originated from the legitimate owner.

Reported losses rose from an initial estimate of 594.48 BTC to 1,367.05 BTC as researchers identified additional address groups. A related report from crypto.news highlighted how the firmware build error affected seed generation for over five years.

The incident has sparked renewed discussions about institutional custody in the U.S. According to crypto.news, Bloomberg ETF analyst Eric Balchunas noted that the losses bolster the case for spot Bitcoin ETFs among investors seeking price exposure without the complexities of managing private keys. While ETFs simplify personal seed management, they introduce new risks related to institutional custody and counterparty exposure.

Future updates will include Coinkite’s forthcoming technical review and additional Galaxy address evaluations. For now, the current on-chain loss estimate of $88.6 million remains preliminary and not definitively confirmed. Affected users now face the urgent task of installing the updated firmware and migrating their funds to completely new seed phrases.