A black keypad device next to small tools on a
AI

Coldcard patches seed-randomness flaw tied to nearly 600 BTC in theft

Because vulnerable seeds can’t be repaired by an update, the incident is fueling fresh interest in custodians and spot BTC ETFs like IBIT.

By Elliot Marsh7 min read

A firmware flaw in Coinkite’s Coldcard hardware wallet has been linked to the theft of nearly 600 BTC worth roughly $38 million so far. The bug has been patched, but users who generated seeds on vulnerable firmware still need to migrate funds to entirely new wallets, keeping the self-custody risk debate in play.

Key Takeaways

  • A Coldcard firmware flaw has been linked to the theft of nearly 600 BTC, worth roughly $38 million so far.
  • Certain Coldcard firmware versions generated wallet seeds with far less randomness than intended, enabling brute-force recreation of recovery phrases.
  • Coinkite has patched the bug, but previously generated vulnerable seeds remain exposed and require a full wallet migration.
  • Industry voices are using the incident to argue that regulated custodians and spot bitcoin ETFs, including BlackRock’s IBIT, can be safer in practice for many holders.

Coldcard’s Seed-Randomness Bug: Nearly 600 BTC Stolen, Patch Isn’t a Full Fix

The failure mode here is not a signing exploit or a hot-wallet leak. It is key generation, the part hardware wallets are supposed to make boring and unbreakable.

Attackers were able to recreate wallet recovery phrases and steal bitcoin from wallets users believed were securely self-custodied, after researchers found that certain Coldcard firmware versions generated wallet seeds using far less randomness than intended. A seed, also called a recovery phrase, is the word list that deterministically recreates a wallet’s private keys. If the seed has low entropy, it stops being a secret and starts being a search space.

That is where the brute-force angle matters. With less randomness than intended, an attacker can try enough candidate seeds to eventually land on the right recovery phrase, then sweep funds as if they were the owner. The theft linked to this issue has been tallied at nearly 600 BTC, worth roughly $38 million so far.

What remains unclear from the available disclosures is the full blast radius. The reporting does not specify the exact vulnerable firmware versions, the patch release timing, or a verified victim count. The “so far” qualifier on the $38 million figure is doing real work, because it implies more cases could still be attributed.

Remediation Reality: Why Updating Firmware Doesn’t Save Vulnerable Seeds

Coinkite says the flaw has been patched, but the remediation is not the usual “update and move on.” Firmware is the device’s embedded software, and a patch can change how the wallet generates keys going forward. It cannot retroactively add randomness to a seed that was already generated.

Coinkite CEO NVK made that point explicitly in an open letter urging immediate action from affected users: “If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further,” he wrote. NVK added that while the fix protects new seeds going forward, it does not fix seeds already generated on vulnerable firmware.

Mechanically, that means the only clean exit is migration. Users who generated seeds on vulnerable firmware must create entirely new wallets and move funds, because updating firmware alone does not eliminate risk for already-generated seeds. For allocators, this is the operational gut punch: the “fix” is a forced key rotation event, and key rotation is exactly where people make mistakes under time pressure.

Even the recommended mitigation path has drawn criticism, because it raises the bar on user behavior. Casa CEO Nick Neuman criticized guidance that users supplement wallet-generated randomness with physical dice rolls, saying: “You just can't ask people to roll dice to be secure with your self custody,” calling it “a non-starter for 99% of people.” The point is less about dice specifically and more about who self-custody is realistically built for when best practice starts to look like a ritual.

Custody Narrative Shift: From ‘Not Your Keys’ to ‘Pay Someone to Worry’

Bitcoin’s self-custody pitch has always been a trade: remove exchange counterparty risk by holding your own keys, then accept the operational security burden that comes with it. This incident hits that bargain at its core, because it attacks the key-generation step rather than a downstream mistake like phishing or a compromised computer.

Some bitcoin advocates framed the damage as unusually severe because it targeted users who believed they were doing everything “right.” Bitcoin commentator Guy Swann called it “the worst hit in bitcoin history to the most knowledgeable and 'properly secured' bitcoiners,” adding: “This isn't an exchange getting hacked because of hot keys. This is thousands of individuals having their personal private keys recreated out from underneath them.” The “thousands” figure is not backed by an audited count in the packet, but the framing captures why this story sticks: it is a confidence shock, not just a loss report.

ARK Invest digital asset research director Lorenzo Valente pushed the argument that self-custody often just swaps one risk bucket for another. “In practice, consumers have traded counterparty risk for software risk, hardware risk, supply-chain risk, phishing risk, backup risk, and the possibility of losing everything through one mistake,” he said. “Frankly, you are better off today holding funds across several publicly-traded exchanges or ETFs.”

Taproot developer Udi Wertheimer made the same point in plainer terms, arguing that passive, set-and-forget security is “currently unrealistic” as threats evolve. His conclusion is the line traders will remember because it maps directly onto product choice: “If you don't want to worry yourself you need to pay someone else to be worried.”

That is where the ETF narrative enters. Amicus co-founder David Lawrence argued incidents like this may push new investors toward regulated products such as BlackRock’s iShares Bitcoin Trust (IBIT) rather than managing private keys, saying new investors may conclude: “I'm safer to just buy IBIT.'” There is no direct ETF flow evidence in this packet, but the explicit linkage matters because it can change the perceived custody risk premium at the margin.

The counter-framing is that this is an engineering failure, not an indictment of self-custody as a concept. Tangem CTO Andrew Lazutkin argued the lesson is rigor and verification, saying the incident shows “open-source firmware should not automatically be equated with better security,” and that security comes from “strong architecture, thorough testing and independent verification.” That is the cleanest way to separate category risk from implementation risk, even if markets rarely bother.

The Coldcard firmware flaw sparks ETF shift Milestones Ahead

The next signal is whether the stolen amount rises materially above the nearly 600 BTC, roughly $38 million so far, as additional cases are identified and attributed. The “so far” language keeps the headline risk asymmetric, because the story gets louder if the tally moves.

A second milestone is disclosure clarity. Publication of the specific vulnerable firmware versions and patch release timing would define the potential affected population and help distinguish a narrow window from a broader exposure.

Third is follow-on guidance from Coinkite and NVK on best practices for seed generation and migration, including whether additional mitigations are recommended beyond creating new wallets and moving funds. The remediation burden is part of the market impact, because it determines how long this stays a live operational problem.

Finally, the custody narrative spillover is measurable even if it starts as talk. Commentary explicitly tying this incident to spot bitcoin ETF adoption, with IBIT repeatedly cited, is the sentiment layer. Traders can then compare that narrative against subsequent ETF flow and positioning data to see whether “safer in practice” stays rhetorical or becomes allocation behavior.

My Take: This Is a Key-Generation Failure That Markets Will Still Price as ‘Self-Custody Risk’

The threshold that matters is whether this stays a one-vendor firmware incident or becomes a broader proxy for “hardware wallets can fail at the one job they have.” Because the exploit sits at seed generation, it attacks the root of the trust model, and that is why it is likely to be priced as category-level self-custody risk even if the bug is specific.

The real test is whether the forced-migration reality keeps producing new loss attributions and new user-error stories. If the tally remains near ~600 BTC and the vulnerable versions turn out to be narrowly scoped, the damage can be contained to engineering process. If the number climbs and the remediation drags, the setup starts to look structural, and the ETF and custodian bid becomes less about ideology and more about operational outsourcing.

Sources