Close Menu
Chain Tech Daily

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Bitcoin ETFs gain fresh case after $89M Coldcard drain

    August 2, 2026

    Bitcoin performed better under Biden than Trump

    August 2, 2026

    An Information-Theoretic Account of Secure Brainwallets

    August 2, 2026
    Facebook X (Twitter) Instagram
    Chain Tech Daily
    • Altcoins
      • Litecoin
      • Coinbase
      • Crypto
      • Blockchain
    • Bitcoin
    • Ethereum
    • Lithosphere News Releases
    Facebook X (Twitter) Instagram YouTube
    Chain Tech Daily
    Home » Coldcard users face urgent seed migration warning
    Crypto

    Coldcard users face urgent seed migration warning

    James WilsonBy James WilsonAugust 2, 20266 Mins Read
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Dogecoin community contributor Mishaboar urged Coldcard users on Aug. 1 to move their Bitcoin to wallets controlled by newly generated seed phrases. 

    Summary

    • 1,367.05 BTC worth $88.6 million was drained from 4,585 addresses across three suspected attack waves.
    • Coinkite says firmware updates protect new seeds but cannot repair seed phrases from vulnerable versions.
    • Mishaboar advised users never to reuse affected seeds or enter recovery phrases into computers online.

    The warning followed Galaxy Research’s estimate that three suspected attack waves drained 1,367.05 BTC, worth about $88.6 million, from 4,585 addresses.

    Mishaboar wrote, “If you have ever used a COLDCARD device of any kind, migrate your funds to a new wallet immediately.” He also warned users not to reuse their existing Coldcard seed phrase or enter recovery words into an internet-connected computer. However, his reference to every Coldcard device is broader than Coinkite’s official security advisory, which identifies specific firmware versions and several exceptions.

    If you have ever used a COLDCARD device of any kind, migrate your funds to a new wallet immediately.

    IMPORTANT: DO NOT reuse the COLDCARD seed phrase ever again – create a new one on the new wallet, and as I have been recommending for a while set also the 25th/13th password. https://t.co/NRnlV2eXkQ

    — Mishaboar (@mishaboar) August 1, 2026

    Coldcard losses rise as attackers target smaller wallets

    Galaxy Research’s latest on-chain estimate identified 1,367.05 BTC across three suspected attack waves. The research firm described $88.6 million as its “estimated observed size,” meaning the total has not been confirmed by Coinkite, law enforcement or every affected user.

    The first wave removed 1,082.65 BTC from 1,196 addresses in about 41 minutes on July 30. A later third wave drained roughly 208 BTC from 1,912 addresses, with the average balance falling to slightly more than 0.1 BTC per address. The changing pattern suggests attackers moved from larger holdings toward smaller wallets.

    Galaxy said each wave appeared internally consistent with one operator. However, it could not determine whether one attacker controlled all three waves. The third group used separate destination addresses, batched several victims into individual transactions and checked only the default derivation path, making it different from the earlier sweeps.

    The research firm also warned that its known transaction patterns cannot identify every theft. A different attacker could generate valid transactions without repeating the fees, destination formats or collection methods seen in the first three waves.

    Official Coldcard warning covers specific firmware

    Coinkite said the problem affects seeds generated on Mk2 and Mk3 devices running firmware versions 4.0.1 through 4.1.9. Seeds created on Mk4 and Mk5 devices before standard version 5.6.0 or Edge version 6.6.0X are also covered. For Coldcard Q, the fixed releases are standard version 1.5.0Q and Edge version 6.6.0QX.

    Coldcard Mk1 devices are outside the firmware regression identified by Block’s researchers. Coinkite also said TAPSIGNER, OPENDIME and SATSCARD are unaffected because they use different codebases. Therefore, the available technical evidence does not establish that every product ever made by Coinkite is vulnerable.

    Block’s Bitcoin engineering and security team traced the flaw to a firmware integration error. The affected software used a deterministic MicroPython fallback instead of the intended STM32 hardware random-number generator when creating wallet secrets. On Mk2 and Mk3 v4 firmware, the affected path added no cryptographic entropy. Later models received a limited secure-element reseed.

    Block cautioned that its analysis represented its current technical view and did not include complete empirical testing of every device. Coinkite has also said its investigation remains open and promised a formal technical report.

    Firmware updates cannot repair existing seeds

    Coinkite has released fixed firmware for every affected model and release track. The patches correct the seed-generation process for new wallets, but they cannot add randomness to a seed phrase created earlier. Moving the same vulnerable phrase into another hardware or software wallet also carries the weakness into the new device.

    Affected users should install the correct fixed firmware before generating a replacement seed. Coinkite advises recording and verifying the new backup, checking a receiving address on the device screen and sending a small test transaction. Users should move the remaining balance only after confirming that the test funds reached the new wallet.

    The company advises users to keep the old backup until the entire migration is confirmed. Mishaboar separately warned users never to type a seed phrase into a computer and recommended keeping offline copies in separate secure locations. That advice can reduce exposure to phishing, malware and cloud synchronization during a rushed migration.

    Coinkite identified a limited exception for users who added at least 50 fair, independent and private dice rolls before the final seed words were produced. The company said those rolls contributed at least 128 bits of independent entropy. Users who entered fewer than 50 rolls, cannot remember the number or exposed the roll sequence should migrate.

    A strong, unique BIP-39 passphrase creates an additional barrier, but Coinkite said it does not repair an affected seed. Short, reused or predictable passphrases may be guessable. Even users with strong passphrases are advised to replace the underlying seed as soon as practical.

    Coldcard incident renews the self-custody debate

    Bitcoin investor Anthony Pompliano said the losses showed how technically demanding self-custody can be, even though individuals retain the right to control their assets directly. He also stressed that Bitcoin itself was not hacked because the failure occurred in third-party wallet firmware rather than the Bitcoin protocol.

    A few thoughts on the Coldcard security incident (in no particular order):

    1. This is devastating for a lot of people. They lost their hard-earned economic value in a way most didn’t realize was possible. Not everyone is a technical genius, but almost all are merely looking to…

    — Anthony Pompliano 🌪 (@APompliano) August 2, 2026

    That distinction matters because an attacker reportedly reproduced weak wallet keys offline. The incident did not require changing Bitcoin transactions, breaking its cryptography or compromising the network’s consensus rules. Once an attacker obtains a valid private key, the resulting transaction appears on-chain like one authorized by the legitimate owner.

    As previously reported, the observed loss estimate rose from an early 594.48 BTC calculation to 1,367.05 BTC as researchers found additional address groups. In related coverage, crypto.news examined how the firmware build error weakened seed generation for more than five years.

    The case has also entered the U.S. institutional-custody debate.As crypto.news reported, Bloomberg ETF analyst Eric Balchunas argued that the losses strengthen the case for spot Bitcoin ETFs among investors seeking price exposure without managing private keys. ETFs remove personal seed-management duties, although they replace those risks with institutional custody and counterparty exposure.

    Coinkite’s promised technical review and further Galaxy address analysis are the next expected updates. Until then, $88.6 million remains the latest public on-chain estimate rather than a final confirmed loss. Users covered by the official advisory face the more immediate task of installing fixed firmware and moving funds to a completely new seed.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    James Wilson

    Related Posts

    Crypto August 2, 2026

    Bitcoin ETFs gain fresh case after $89M Coldcard drain

    Crypto August 2, 2026

    Strategy keeps STRC dividend at 12% below $90

    Crypto August 2, 2026

    Trump Media launches Truth API amid SEC scrutiny

    Crypto August 2, 2026

    XRP Ledger urges node upgrade after manifest flood

    Crypto August 2, 2026

    Michael Saylor says BIP-110 lacks miner consensus

    Crypto August 2, 2026

    Trump Media transfers 2,628 BTC as holdings shrink

    Leave A Reply Cancel Reply

    Don't Miss
    Crypto August 2, 2026

    Bitcoin ETFs gain fresh case after $89M Coldcard drain

    Bloomberg Intelligence senior ETF analyst Eric Balchunas said on Aug. 2 that the Coldcard security…

    Bitcoin performed better under Biden than Trump

    August 2, 2026

    An Information-Theoretic Account of Secure Brainwallets

    August 2, 2026

    Coldcard users face urgent seed migration warning

    August 2, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • YouTube
    • LinkedIn
    Our Picks

    Bitcoin ETFs gain fresh case after $89M Coldcard drain

    August 2, 2026

    Bitcoin performed better under Biden than Trump

    August 2, 2026

    An Information-Theoretic Account of Secure Brainwallets

    August 2, 2026

    Coldcard users face urgent seed migration warning

    August 2, 2026

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Don't Miss
    Crypto August 2, 2026

    Bitcoin ETFs gain fresh case after $89M Coldcard drain

    Bloomberg Intelligence senior ETF analyst Eric Balchunas said on Aug. 2 that the Coldcard security…

    Bitcoin performed better under Biden than Trump

    August 2, 2026

    An Information-Theoretic Account of Secure Brainwallets

    August 2, 2026

    Coldcard users face urgent seed migration warning

    August 2, 2026

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    About Us
    About Us

    ChainTechDaily.xyz delivers the latest updates and trends in the world of cryptocurrency. Stay informed with daily news, insights, and analysis tailored for crypto enthusiasts.

    Our Picks
    Lithosphere News Releases
    X (Twitter) Instagram YouTube LinkedIn
    © 2026 Copyright

    Type above and press Enter to search. Press Esc to cancel.