Your COLDCARD seed was not random
Your seed words are supposed to come from pure chance, so that nobody could ever reproduce them. A software bug meant COLDCARDs were not doing that. From March 2021 onward the firmware quietly fell back to a general purpose random number generator instead of the dedicated hardware one, and that fallback seeds itself from the device's own state, things like a chip ID and an internal clock. Predictable inputs give predictable seeds.
At worst that narrows the range to about four billion possible seeds, and far fewer than that on the older models. Four billion sounds enormous, but a computer can work through the whole range. So thieves are not guessing at your wallet in particular. They are recreating every seed the flaw could produce, checking which ones hold coins, and emptying those. That is happening now.
Not affected? If you have never generated a seed on a COLDCARD Mk2, Mk3, Mk4, Mk5 or Q, this does not apply to you and you can stop reading. Seeds you generated somewhere else and merely imported into a COLDCARD are also fine. As for TAPSIGNER, OPENDIME and SATSCARD, Coinkite says they are not affected because they run different codebases. Nothing has contradicted that so far, but it is the vendor's own assessment rather than an independent finding.
Already updated the firmware? That protects seeds you generate from now on. It does nothing for a seed the old firmware already produced. If the seed you are using today came off an affected device, updating has not saved it and you still need to move.
My position#
If your seed was generated on a COLDCARD on firmware from March 2021 or later, move your bitcoin to a new wallet with a new seed. That applies whether or not you rolled dice and whether or not you use a passphrase.
Dice and passphrases change how fast you need to act, not whether you need to act. Enough dice entropy probably means your seed was fine. A strong passphrase means the passphrase is now the only thing protecting you, on a seed an attacker may be able to reconstruct. Neither is a reason to leave coins where they are indefinitely.
How fast do you need to move?#
Work down the list and stop at the first one that describes you. Adapted from Rob Hamilton's triage thread.
- 1A single-signature wallet with no dice and no passphrase.
- 2A multisig made only of affected COLDCARDs, where none of them had dice or a passphrase. Every key in the quorum can be recreated, so needing several of them protects you from nothing.
- 3Any of the above where you have reused a receive address. See the note below, this is worse than it sounds.
Find someone to help you if you need it, but do not wait.
- 1Single-sig where you rolled fewer than 50 dice, or where your passphrase is short, guessable, or something you invented rather than generated.
- 2Multisig where the affected COLDCARDs alone can move the funds, for example two COLDCARDs in a 2-of-3.
Assume the seed is known and that only your passphrase is holding. Use the table below to work out what your passphrase is actually worth.
- 1You rolled at least 50 dice (100 is a comfortable margin) and know it for a fact, or your passphrase genuinely carries 128 bits.
- 2A multisig where the affected devices are a minority and cannot move funds on their own. Your bitcoin is safe, but you are running with less redundancy than you think.
Rotate the affected keys out, or migrate to a fresh seed, on your own schedule.
Nobody legitimate will ask for your seed#
Incidents like this bring out people offering to help. Assume every unsolicited offer is a thief. No support agent, no recovery service, no migration tool and no wallet developer ever needs your seed words or your passphrase. Anyone who asks is stealing from you.
Do not type your words into a website. Do not install a tool someone sent you. Do not accept help over a direct message, and do not trust an email about this even if it looks like it came from the vendor. If you need a hand, ask someone you already knew before today.
Check the coins are still there#
Before you plan a migration, confirm you still have a balance. Look up your address or your wallet on a block explorer, or open a watch-only copy of the wallet. Do not enter your seed anywhere to do this, and use a public key or address only.
If the funds are already gone there is nothing to migrate, and nobody can reverse it. Save the transaction IDs and the addresses they went to, because that record is the only thing that is useful later. If the funds are still there, keep reading.
Reused an address? Move now#
If you have received to the same address more than once, treat yourself as the most urgent case whichever of the three groups above describes you. Address reuse hands an attacker a fixed target to watch and to test guessed keys against, and it removes the small amount of cover that fresh addresses give you.
What is your passphrase actually worth?#
Entropy in bits, by what your passphrase is built from and how many units long it is. 128 bits is the target. Green is at or above it, amber is close, grey is not enough.
| Built from | 8 | 12 | 16 | 20 | 25 | 30 | for 128 |
|---|---|---|---|---|---|---|---|
| Random BIP39 words (2,048 word list) | 88 | 132 | 176 | 220 | 275 | 330 | 12 |
| Random words from a 7,776 word list | 103 | 155 | 207 | 258 | 323 | 388 | 10 |
| Lowercase letters only | 38 | 56 | 75 | 94 | 118 | 141 | 28 |
| Lowercase letters + digits | 41 | 62 | 83 | 103 | 129 | 155 | 25 |
| Upper + lower + digits | 48 | 71 | 95 | 119 | 149 | 179 | 22 |
| Full printable ASCII | 52 | 79 | 105 | 131 | 164 | 197 | 20 |
Column headings are the number of words or characters in your passphrase.
Every number above assumes each word or character was chosen at random. A long passphrase you thought up yourself is worth a small fraction of what the table says. A memorable sentence, a quote, a pattern on the keyboard, or a password you have used anywhere else carries almost no entropy at all.
And reaching 128 bits does not repair the seed. It means the passphrase is the only thing left protecting coins whose underlying key may already be known. That buys you time to migrate carefully. It is not a reason to stay.
What your dice rolls were worth#
A fair six-sided die contributes about 2.6 bits per roll, and dice entropy came from you rather than from the device.
If you are not certain how many rolls you entered, or whether anyone could have seen them, do not count them at all. Treat your wallet as one that needs moving urgently.
Moving funds without being front-run#
If an attacker may already hold your key, a normal broadcast is a race. They can see your transaction sitting in the mempool and try to replace it with one paying themselves.
Submitting the transaction straight to a miner avoids the race, because it is already in a block by the time anyone else sees it. MARA has now opened its Slipstream service to everyone, so this no longer needs an account or an introduction. If you are in the most urgent group and moving a meaningful amount, take the extra step.
Submit through MARA Slipstream →Where to move it right now#
If you need to move today, do not wait until you have decided on your permanent setup. Get the coins off the compromised key first. Any of these will generate a fresh wallet in a few minutes and none of them are affected by this flaw:
- Sparrow on desktop, if you are comfortable on a computer.
- Blue Wallet, Blockstream Green or Cove on a phone, if you want this done in the next ten minutes.
My Basic guides walk through Sparrow, Blue Wallet and Blockstream Green step by step, including writing the backup down properly. They are unaffected and still online.
Coinkite's own guidance is to update the firmware and generate a replacement seed on the same device. I would not. Updating fixes new seeds but the device has already lost the benefit of the doubt on the one job that matters most. Generate the new seed somewhere else.
A phone wallet is not where large savings belong, and I am not pretending otherwise. But a fresh seed on a phone is safer tonight than a compromised seed on a hardware wallet, and you can move again later once you have decided properly. If the amount is large enough that this makes you uneasy, parking it briefly with a custodian or exchange account you already have is also better than losing it. Neither is a permanent answer, and both beat waiting.
Where to keep it long term#
I am not naming a replacement device yet. The lesson of this failure is not that COLDCARD was the wrong brand, it is that trusting any single vendor to get entropy right leaves you with no margin when they do not. Other vendors are being reviewed and so far nothing comparable has turned up elsewhere, which is encouraging, but I would rather wait than send people rushing from one device to another.
What I would hold to instead:
- Spread the trust. For meaningful amounts, use multisig with devices from different manufacturers, so one vendor's bug cannot spend your coins.
- Bring your own entropy. Dice are the reason some people are unaffected today. Generating a seed yourself, away from the device, removes the vendor from the part that matters most.
- Verify before you fund. Write the backup down, restore it, confirm the fingerprint matches, and send a small test amount before moving the balance.
- Do not rush into a worse setup. A panicked migration into something you do not understand is its own way to lose coins.
For specific product opinions, read Rob Hamilton's thread and Michael Flaxman's multi-vendor multisig guide, which pioneered the idea and remains the clearest mental model for a rebuild. One caveat on that one: it recommends the COLDCARD, having been written years before this failure. Take its principles and put a different device in that slot. Weigh both authors' disclosures for yourself.
Why my hardware guides are offline#
My Intermediate and Advanced guides were built around the COLDCARD, so they are down rather than left up as advice I no longer stand behind. They will return rebuilt around multiple vendors and your own entropy. The Basic guides are unaffected and still available.
Sources#
- Block Engineering: the technical report that identified the flaw
- Coinkite's own advisory and firmware guidance
- Rob Hamilton: triage thread and personal recommendations
This page is my reading of a developing situation and is not advice. Verify against the sources above and make your own decisions.