This is a security alert.

If you hold Bitcoin on a Coldcard hardware wallet, or you know somebody who does, please read this in full, then act on it TODAY.

Since Thursday, 1,367 bitcoin have been stolen from 4,585 addresses secured by Coldcard hardware wallets.

That’s close to $89 million, or around £64 million at today’s rate. Worse still, the sweeping hasn’t stopped. As I write, another wave of theft is under way.

None of the victims here were careless.

Nobody clicked a dodgy link and no device was stolen.

These were people who bought the most respected Bitcoin hardware wallet on the market, wrote down their 24-word seed phrase, locked it away safely, and left it alone for years.

The coins were stolen anyway.

There is a long technical explanation for how that’s possible. Honestly, you don’t need to hear it.

What you do need is to know which devices are affected, what to do today, and whether the rest of your setup is safe.

First, though, a bit of background, because it changes what you do next.

The only job that really matters

Your Bitcoin doesn’t live inside a hardware wallet. It lives on the blockchain, and the device holds the key that lets you move it.

That key is what your 24-word seed phrase represents.

The most important thing a hardware wallet ever does is generate those words at random from a pool so vast that neither a person nor a computer could ever guess or brute-force them.

If that step is unbreakably strong, everything else follows.

If it isn’t, nothing else the device does can save you.

For years, Coldcard, which Coinkite in Canada makes, was the wallet of choice for people who took this seriously.

Bitcoin only. Open source. Air-gapped. Built to be paranoid about exactly the right things.

I own Coinkite kit myself, including its Opendime devices.

In March 2021, a firmware update changed how the device generated its randomness. The chip dedicated to that job stopped being used.

Instead, the software fell back on a substitute built from the device’s serial number and a clock reading. Neither is a secret.

That’s the whole problem with this developing crisis.

Those 24 words were meant to come from a pool nobody could ever work through.

On older Coldcard devices, they instead came from a search space that a modern computer – with enough information – could work through in hours.

Nobody spotted it for five years.

It took engineers at Block (NYSE: XYZ), which builds a competing wallet, to find the cause and hand it to Coinkite while the thefts were already underway.

Attackers didn’t break these wallets. They were vulnerable from the moment the affected firmware was installed.

The industry simply didn’t realise it until now.

What is affected, and what you do today

Coinkite’s first advisory named the Mk3. That has been overtaken.

Every Coldcard model in circulation is now in scope.

Mk2 and Mk3 running firmware 4.0.1 through 4.1.9 are the worst hit, with roughly 40 bits of protection instead of the 128 bits Coinkite intended to provide.

Mk4, Mk5, and Q are also affected if the seed was created before the fixed firmware was installed. Their effective entropy is around 72 bits. Less urgent, but still serious.

Opendime, Tapsigner, and Satscard run different code and are confirmed unaffected.

Here is what to do, in the order you need to do it…

#1. Work out where your seed words came from.

If a Coldcard generated them at any point since March 2021, treat them as affected. That still applies if you later moved those words onto a different wallet, because the words are the problem.

#2. Update the firmware from Coldcard’s official website and nowhere else.

Mk2 and Mk3 need 4.2.0 or later.

Mk4 and Mk5 need 5.6.0 standard or 6.6.0X Edge.

The Q needs 1.5.0Q standard or 6.6.0QX Edge.

Edge is a separate release track, so a higher version number on its own doesn’t mean you’re covered.

#3. Generate a brand-new seed and move your coins to it.

Updating the firmware fixes future seeds. It cannot repair one that already exists.

Verify the new backup, check a receiving address on the device screen. Send a small test amount, confirm it arrives, then move the rest.

Keep the old backup until the migration is complete. More money gets lost to a panicked migration than to the fault behind it.

#4. Check whether an exception applies to you.

If you entered at least 50 fair, private dice rolls when you set up the wallet, that randomness was yours and your seed remains secure.

If you entered fewer than 50, or you cannot remember, migrate.

A strong BIP-39 passphrase, which is not your PIN, adds a meaningful layer of protection, although Coinkite recommends that passphrase users should migrate anyway.

One more thing while everybody is panicking.

Nobody legitimate will ever ask for your seed words. Not Coinkite, not a checker website, not a helpful stranger who noticed you asking questions, not me.

Anything that wants those words typed into a screen is robbing you.

Your other wallets are fine…… Self-custody still wins.

As serious as this is for Coldcard users, it’s not a crisis for Bitcoin or crypto more broadly.

You can see that in the Bitcoin price, which barely moved as the story unfolded.

Also, every other major hardware-wallet manufacturer has now confirmed it is unaffected.

Ledger pointed to the certified randomness chip inside its secure element, producing the full 256 bits for every recovery phrase.

Trezor said the problem sits in Coinkite’s own firmware and that it doesn’t share that code.

Bitkey, Blockstream Jade, and Tangem said much the same within hours.

There is no evidence that BitBox, Foundation Passport, Cypherock, or KeepKey are affected either.

If you’re replacing a Coldcard, then those are all suitable alternatives.

Trezor, Ledger, BitBox02, Blockstream Jade, Foundation Passport, and Bitkey are all reasonable alternatives. None of them is immune to a future bug and, as we’ve said before, nothing is 100% safe.

But what they are is independent, written by different teams who do not share each other’s mistakes.

The broader lesson is one Binance founder CZ has been making for years, and repeated again over the weekend: diversify across wallet vendors.

If you hold a meaningful amount of Bitcoin, spread it across more than one vendor and get onto multisignature (multisig) devices. Not one multisig wallet was touched in the first sweep.

The market is drawing the wrong conclusion. Bitcoin sentiment has hit the lowest reading in Santiment’s history, worse than FTX and worse than Mt Gox. Small holders are sending coins back onto exchanges.

I understand the instinct. But I still believe self-custody is the best way to maintain control of your digital assets.

An exchange failure is not a bug that gets found, disclosed, and patched within 48 hours. It is a business failure you first hear about in a bankruptcy filing, after which you queue with the other creditors for years.

The people swept last Thursday had a horrible night. They could also act on it at four in the morning without asking anyone’s permission.

Self-custody is still the right answer.

It just is not something you do once in 2021 and never think about again. Firmware ages. What was best in class five years ago can turn into a liability sitting in a drawer.

So check your hardware wallet model and the firmware version today. Then message anyone you know using a Coldcard and ask them to do the same.

The attacker appears to be working down the balance list, and there is no reason to think they’ll stop just because a wallet holds a smaller amount of Bitcoin.

Have you been affected by the Coldcard security flaw?
Yes
No


Find out what your friends and family think as well. Share this email with them so they can answer today’s poll and subscribe as well.

Until next time,


Sam Volkering
Investment Director, Southbank Investment Research

PS Coinkite is still updating its advisory and the numbers have moved every day since Thursday. The blog is at blog.coinkite.com and the X feed is @COLDCARDwallet. Check both before you act.