Mishaboar, a member of the Dogecoin community, urged Coldcard users on August 1 to migrate their Bitcoin to wallets created with new seed phrases.
Summary
- 1,367.05 BTC, worth $88.6 million, was taken from 4,585 addresses over three suspected attack incidents.
- Coinkite mentioned that firmware updates can secure new seeds but cannot protect against vulnerable seed phrases from older versions.
- Mishaboar warned users against reusing compromised seeds or inputting recovery phrases on online devices.
This alert followed Galaxy Research’s estimates that 1,367.05 BTC—approximately $88.6 million—was siphoned from 4,585 addresses across three suspected attack waves.
Mishaboar emphasized, “If you have ever used any COLDCARD device, move your funds to a new wallet promptly.” He also advised against reusing any compromised Coldcard seed phrases or entering recovery phrases on internet-connected devices. His warning goes beyond Coinkite’s official security advisory, which lists affected firmware versions and certain exceptions.
Rising Coldcard losses as attackers target smaller wallets
Galaxy Research’s latest on-chain analysis revealed that 1,367.05 BTC was lost across three suspected attack waves. The firm described the losses as an “estimated observed size,” indicating that the total amount hasn’t been validated by Coinkite, law enforcement, or all affected users.
The first wave extracted 1,082.65 BTC from 1,196 addresses in around 41 minutes on July 30. A subsequent third wave drained about 208 BTC from 1,912 addresses, with the average balance per address dropping to just over 0.1 BTC. This trend indicates a shift in focus from larger amounts to smaller wallets.
Galaxy noted that each wave appeared to be consistent with a single operator; however, it could not confirm if one attacker was behind all three incidents. The third group utilized different destination addresses, consolidating multiple victims into separate transactions while only inspecting the default derivation path, differing from previous waves.
The research firm also pointed out that its known transaction patterns may not capture all thefts. Other attackers might generate legitimate transactions without mirroring the fees, destination formats, or collection methods noted in the first three waves.
Specific firmware alert from Coldcard
Coinkite specified that the vulnerability impacts seeds generated on Mk2 and Mk3 devices using firmware versions 4.0.1 to 4.1.9. Seeds created on Mk4 and Mk5 devices before standard version 5.6.0 or Edge version 6.6.0X are also included. For Coldcard Q, the applicable releases are standard version 1.5.0Q and Edge version 6.6.0QX.
Coldcard Mk1 devices are not part of the firmware issue identified by Block’s researchers. Coinkite further clarified that TAPSIGNER, OPENDIME, and SATSCARD remain unaffected due to varying codebases. Hence, current technical evidence does not imply that all Coinkite products are vulnerable.
Block’s Bitcoin engineering and security team traced the flaw to an integration issue in the firmware. The affected software relied on a deterministic MicroPython fallback instead of the intended STM32 hardware random-number generator for wallet secret creation. On Mk2 and Mk3 version 4 firmware, this path provided no cryptographic entropy. Newer models received a limited secure-element reseed.
Block advised that its analysis reflects its current technical understanding and does not cover complete empirical testing of every device. Coinkite has stated that its investigation is ongoing, with a formal technical report to follow.
Firmware updates cannot remedy existing seeds
Coinkite has issued corrected firmware for all affected models and release tracks. While these updates fix the seed-generation process for new wallets, they cannot enhance randomness for previously created seed phrases. Transferring the same vulnerable phrases to different hardware or software wallets also perpetuates the issues.
Affected users should install the appropriate corrected firmware before generating a new seed. Coinkite suggests documenting and verifying the new backup, checking a receiving address on the device screen, and sending a small test transaction before transferring the remaining balance.
Users should keep the old backup until the full migration is confirmed. Mishaboar additionally advised against typing seed phrases into a computer and recommended maintaining offline copies in various secure locations to reduce exposure to phishing, malware, and cloud synchronization during a hurried transition.
Coinkite identified a limited exception for users who completed at least 50 fair, independent, and private dice rolls before generating the final seed words, contributing a minimum of 128 bits of independent entropy. Users with fewer than 50 rolls, uncertainties about the number, or those who exposed the roll sequence should migrate.
A strong, unique BIP-39 passphrase offers extra protection, yet Coinkite emphasized that it does not fix a compromised seed. Short, reused, or predictable passphrases can be guessed. Even users with strong passphrases are encouraged to replace the underlying seed as soon as possible.
Coldcard incident reignites discussions on self-custody
Bitcoin investor Anthony Pompliano noted that the losses highlight the technical challenges of self-custody, even as individuals maintain direct control over their assets. He emphasized that the Bitcoin protocol itself was not compromised; the issue arose within third-party wallet firmware.
This distinction matters because an attacker might have replicated weak wallet keys offline. The incident did not require modifying Bitcoin transactions, breaking its cryptography, or undermining the network’s consensus mechanisms. Once an attacker gains access to a valid private key, the resulting transaction appears on-chain as if it were authorized by the legitimate owner.
As reported earlier, estimated losses rose from an initial calculation of 594.48 BTC to 1,367.05 BTC as researchers identified additional address groups. In related coverage, crypto.news examined how the firmware build error compromised seed generation for over five years.
The incident has also ignited discussions within the sphere of U.S. institutional custody. As crypto.news highlighted, Bloomberg ETF analyst Eric Balchunas argued that the losses support the case for spot Bitcoin ETFs among investors seeking price exposure without the complexities of managing private keys. While ETFs simplify personal seed management challenges, they introduce new risks associated with institutional custody and counterparty exposure.
Coinkite’s forthcoming technical review and additional analysis from Galaxy are anticipated updates. In the meantime, the current on-chain loss estimate of $88.6 million is considered preliminary, rather than a final total. Users affected by the official advisory now face the urgent task of installing corrected firmware and migrating their funds to completely new seed phrases.




