Unbranded Bitcoin hardware wallet beside a die on a yellow-orange security workbench

Coldcard Forces Human Randomness Into Every New Seed After $130 Million Bitcoin Exploit

August 23, 2026 7:13 am Comments

Coldcard is changing how every new wallet seed is created after one of the most damaging hardware-wallet failures Bitcoin has seen.

The new rule is blunt: the device will no longer let its own hardware do all the work. Users must add physical randomness through at least 65 key presses, 50 dice rolls, or 128 coin flips before a new seed can be completed.

That is the centerpiece of a much broader security overhaul released after attackers exploited weak seed generation in older Coldcard firmware and stole an estimated $130 million in Bitcoin.

For holders, the most important detail is also the easiest to miss: installing the update does not repair an old vulnerable seed. Anyone whose seed may have been generated on affected firmware still has to create a fresh seed and move the Bitcoin.

Coldcard now requires human-supplied randomness.

Coinkite told Mk4 and Mk5 owners to install firmware 5.6.1 and Q owners to install 1.5.1Q. The company said the release followed three weeks of sustained review by outside researchers and AI systems.

The new seed process combines user input with several sources inside the device. Standard seed generation now mixes 32 bytes from a backup generator, 32 fresh bytes from one secure element, eight fresh bytes from another secure element, and fresh output from the device’s hardware random-number generator.

That material is then combined with the required key presses, dice rolls, or coin flips.

Coinkite also replaced its backup pseudo-random number generator with a SHA-256-based design and added boot-time checks intended to catch a failure in the hardware randomness path before the wallet enters normal operation.

A Bitcoin wallet seed is the root secret behind every private key in that wallet. If the seed comes from a much smaller pool of possibilities than the user expects, an attacker can search that pool offline and recreate the keys without stealing the physical device.

The migration warning matters more than the update button.

Decrypt reports that the vulnerability dated to 2021 and left some seeds with far less effective randomness than a normal 128-bit wallet seed should have, even though owners believed their private keys had been created securely on an air-gapped device.

Attackers could therefore guess affected keys with computation rather than malware, phishing, or physical access to the wallet, turning a flaw in the original setup process into a remote path to the Bitcoin years later.

The first documented wave drained 594 BTC from roughly 500 wallets in about 25 minutes, showing how quickly a prepared attacker could sweep a precomputed set of vulnerable keys. By early August, researchers had tracked approximately $88.6 million across 4,585 affected addresses.

On some devices, the effective security reportedly fell from the expected 128 bits of entropy to roughly 40 bits. That collapse transformed an impossibly large search problem into one attackers could tackle with ordinary computation.

Coinkite has said the attackers may have used AI to examine older versions of its open-source firmware and locate the weakness. The company then used outside researchers and AI tools during the three-week review that produced the latest fixes.

The review expanded beyond the original random-number failure. It examined transaction signing, USB connections, firmware validation, backup handling, and other wallet functions before the new release was issued.

Galaxy Research said on August 14 that it had very high confidence more than 1,778 BTC had been stolen, worth about $112 million at the time, and warned that the final figure would be higher.

Patched firmware and a safe wallet are two different things. Updated software can generate safer seeds going forward, but it cannot retroactively add entropy to a seed created years ago.

Coinkite says users covered by the 2021-through-July-2026 advisory must generate a new seed on fixed firmware and transfer their funds. The company recommends downloading firmware only from the official Coldcard page, verifying its hash and signature, confirming the installed version on the device, and then completing the separate seed migration.

The fix reaches beyond seed generation.

Coldcard now rechecks a partially signed Bitcoin transaction immediately before signing it. That closes a theoretical gap in which a compromised computer connected by USB could change a transaction after the user reviewed it but before the device signed it.

The firmware also tightens USB data access, adds checks around firmware validation, hardens Delta Mode, and changes backup behavior. The wider repair shows why the company inspected the full security boundary instead of patching one line and moving on.

A separate technical summary from Bitcoin News described research indicating that the attacker may have ranked vulnerable addresses by balance and swept them in batches. That supports the view that this was a systematic key-recovery operation, not random device theft.

What Bitcoin holders should take from this.

Cold storage removes many online attack paths, but it does not remove implementation risk. A wallet can stay air-gapped for years and still be vulnerable if the secret created during setup was predictable enough to reconstruct.

The strongest part of Coldcard’s response is that the new design no longer asks users to trust one hidden source of randomness. Physical input is mandatory, several device sources are mixed together, and the firmware checks whether the intended hardware path is actually being used.

The response also carries a hard lesson: security claims are only as good as the code that enforces them. For affected owners, current firmware is only the first step.

The job is finished only after the old seed is retired and the Bitcoin has moved to keys generated under the repaired process.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.