EMERGENCY PSA: Coldcard Firmware Flaw Has Drained $38M: Here's What To Do

03 Aug 2026 11:56 AM By Stormrake

To receive the Morning Note in your inbox, subscribe here: https://stormrake.substack.com/

A critical firmware vulnerability in Coldcard hardware wallets has come to light, and it is serious. Roughly 594 BTC, worth around $38 million, was swept from approximately 500 single-signature wallets in a 25 minute window on 30 July. The root cause was a firmware error dating back to March 2021 that caused affected devices to bypass proper hardware randomness during key generation, leaving predictable, crackable seeds.

We know a meaningful number of our clients hold Coldcard devices for self-custody. This is not a minor bug. If your seed was generated on a vulnerable firmware version without additional entropy, your keys may already be compromised, even if your coins have not moved yet.

Who is at risk?

Mk3 devices running firmware 4.0.1 or later are the worst affected. Mk4, Q and Mk5 devices were subject to a separate, less severe flaw. Coinkite has released fixed firmware (Mk4 and Mk5 to version 5.6.0 or later, Q to version 1.5.0Q or later), but a firmware update does not retroactively fix a seed that was already generated insecurely. Coinkite has indicated that a meaningful amount of additional entropy, at least 50 dice rolls, is needed to be confident your seed sits outside the vulnerable range. If you did not add that level of entropy or a passphrase when you set up your device, you should treat your existing seed as potentially exposed.

Be on High Alert for Scams

No legitimate party will ever ask for your seed phrase. Not a manufacturer, not a custody provider, not us. A request for your seed words is by itself proof that the request is fraudulent, however it is branded. Do not enter your seed phrase into any website offering to check whether you are affected. That is a scam.

Events like this always attract opportunists within hours. Treat any unsolicited message, tool or “checker” site asking for your seed as hostile by default.

What this means practically

This is not a Bitcoin problem. It is a self-custody execution problem, and it is exactly the kind of tail risk that sits quietly under the surface of “not your keys, not your coins” until it does not. Firmware, chip design and randomness generation are layers most holders never interact with directly, and this event is a reminder of how much trust that requires.

This is not the first breach of a self-custody solution, and it will not be the last. Stormrake custody takes that risk off the table.

Stormrake’s Custody Solution

Whether you are running an affected device or simply want somewhere safe to move your coins while you figure out your next step, Stormrake’s custody solution is a top tier way to store your Bitcoin. It takes the whole question of seed generation, firmware risk and device security off your plate, no drawer, no single point of failure, no guessing whether your setup was done right.

If you want to talk through moving your holdings across, reach out to the team directly. We are moving through client queries on this today.

To receive the Morning Note in your inbox, subscribe here: https://stormrake.substack.com/

*All prices are denominated in USD unless stated otherwise*

Written by Alexandar Artis

Create a brokerage account today

No Advice Warning 

The information in this newsletter is general only. It should not be taken as constituting professional advice from the author - Stormrake PTY LTD.
Stormrake is not a financial adviser and does not provide financial product advice. You should consider seeking independent legal, financial, taxation or other advice to check how the information relates to your unique circumstances. Stormrake is not liable for any loss caused, whether due to negligence or otherwise arising from the use of, or reliance on, the information provided directly or indirectly, by this newsletter.
 

Disclaimer 

All statements made in this newsletter are made in good faith and we believe they are accurate and reliable. Stormrake does not give any warranty as to the accuracy, reliability or completeness of information that is contained here, except insofar as any liability under statute cannot be excluded. Stormrake, its directors, employees and their representatives do not accept any liability for any error or omission in this newsletter or for any resulting loss or damage suffered by the recipient or any other person. Unless otherwise specified, copyright of information provided in this newsletter is owned by Stormrake. You may not alter or modify this information in any way, including the removal of this copyright notice.

Copyright © 2024 Stormrake Pty Ltd, All rights reserved

Stormrake