Coldcard Entropy Disclosure Explains Which Bitcoin Seeds Need Review
Coinkite says a firmware-related random-number path exposed some Coldcard seed-generation cases. TRM reports a major theft investigation, but exposure depends on how and when a seed was created.
WHY THIS MATTERS
Two technical and incident reports describe a firmware-related weak-randomness issue in some Coldcard seed-generation paths and a large Bitcoin theft investigation. The important distinction is that exposure depends on the firmware and method used when a seed was generated. Owning a Coldcard today does not, by itself, prove that a reader's seed was exposed.
Coinkite's technical disclosure explains the software path and its mitigation guidance. TRM Labs describes theft waves and preliminary loss estimates. Together, the reports give readers a way to understand the issue without turning one affected path into a claim that all hardware wallets are unsafe.
WHO, WHAT, WHEN, WHERE
Coinkite says an integration and linking error caused a MicroPython software pseudo-random number generator path to be used in affected seed-generation paths after the libNgU migration in March 2021. The company says this was not a failure of the hardware true random-number generator and not an intentional runtime fallback. [1]
Coinkite identifies Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 as affected for new seed generation, with version 4.2.0 or later correcting that generation path. It also lists fixed tracks for later models: Standard 5.6.0 or later for Mk4 and Mk5, Standard 1.5.0Q or later for Q, Edge 6.6.0X or later for Mk4 and Mk5, and Edge 6.6.0QX or later for Q. Readers should use the vendor's current instructions because firmware guidance can change. [1]
WHAT THE TECHNICAL DISCLOSURE CONFIRMS
The disclosure makes seed-generation history central to the question. A seed created through an affected path may need review. Coinkite also describes a different case for people who supplied at least 50 independent private dice rolls. The exact method, firmware version, model, and date therefore matter more than a simple label such as “Coldcard user.”
Coinkite says a strong, unique BIP-39 passphrase may reduce immediate exposure in some circumstances, but a passphrase does not repair an affected seed. Updating firmware also does not repair a seed that was already generated. The vendor's guidance is to generate a new seed on fixed firmware and migrate funds according to its current instructions. [1]
That distinction matters for incident response. A device update can correct future seed creation while leaving an old seed unchanged. Readers should not improvise a migration from a general social-media post or assume that moving a device to a new firmware version settles the status of every wallet it has created.
WHAT TRM REPORTS, AND WHAT THE NUMBERS MEAN
TRM Labs reports that theft waves began on July 30, 2026. Its article cites a preliminary Galaxy Research running tally near 1,816 BTC, valued at approximately $116 million in the report, across more than 5,200 addresses and four waves. These are estimates from an active investigation, not a final audited loss total. Bitcoin prices and address attribution can change the dollar value and the count. [2]
TRM discusses transaction construction that could point to multiple attackers, but it does not establish a confirmed actor attribution. The incident report describes a major theft investigation. It does not prove that every affected seed was created by the same method or that every Coldcard user was exposed. [2]
WHAT READERS SHOULD DO WITH THE GUIDANCE
Readers who may have generated a seed during an affected period should compare their model, firmware history, and seed-generation method with Coinkite's current technical guidance. Use the vendor's latest instructions for creating a replacement seed and moving funds. Do not publish seed words, private keys, dice results, or passphrases while asking for help.
Readers should also treat a passphrase as a wallet-design detail, not as a guarantee that an old seed is safe. A passphrase may change which derived wallet is visible, but it does not make a weakly generated base seed strong. When in doubt, pause and obtain qualified, current guidance through the vendor's official support process.
WHAT REMAINS UNKNOWN
The reports do not provide a public list that maps every address to a particular device, firmware version, or seed-generation method. TRM's loss figures are preliminary, and the source does not identify a confirmed thief. The public reports also do not establish that every device of a named model was used to create an exposed seed.
The incident is specific to a described seed-generation path. It is not evidence that hardware wallets as a class are generally unsafe. Hardware security still depends on firmware, generation method, backup handling, passphrase choices, and how a user responds to a vendor notice.
WHAT READERS SHOULD WATCH NEXT
Watch Coinkite's technical and support pages for updated affected-version guidance and migration instructions. Watch TRM's investigation for revisions to the estimated loss, address set, or attribution language. Keep any response private, verify links before entering wallet information, and do not treat preliminary numbers as a complete incident record.
SOURCES AND DISCLOSURES
[1] Coinkite, “Coldcard Entropy Technical Backgrounder,” including the affected generation path, firmware ranges, and mitigation guidance:
https://blog.coinkite.com/entropy-technical-backgrounder/
[2] TRM Labs, “The Largest Hardware Wallet Exploit of 2026: Inside the $116 Million Coldcard Hack,” including the preliminary theft estimates and investigation observations:
https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack
Disclosure: This is a sourced security report, not financial, legal, or technical advice and not a recommendation to buy, sell, hold, or move any asset. Exposure depends on seed-generation circumstances, and not every Coldcard user is affected. Use the vendor's current instructions rather than relying on this article to decide a wallet migration. Loss figures are preliminary estimates, not verified final totals. No paid placement, sponsorship, or affiliate relationship with Coinkite, TRM Labs, or any wallet provider was used. The featured illustration was generated for CryptoWorkPro and is not a documentary image of a device, seed, or theft.


