04/08/2026
TL;DR: A Coldcard firmware bug caused some devices to generate wallet seeds with far less randomness than intended. An attacker recreated likely seed combinations, found funded wallets on the blockchain, and stole more than 1,500 BTC, roughly $100 million, without ever touching the physical devices.
A major Coldcard security incident is unfolding.
A firmware bug caused some Coldcard devices to generate wallet seeds with far less randomness than they were supposed to have. An attacker was able to recreate possible seeds, find wallets holding Bitcoin, and sweep more than 1,500 BTC without ever touching the physical devices.
This is a good reminder that “cold storage” is only as secure as the randomness used to create the seed.
One way to protect against this type of failure is to generate your seed independently. Entropia v2 Seed Tablets use physical random draws from the full BIP-39 word list. When used correctly, the randomness comes from the tablet draws, not from software inside the hardware wallet.
https://btc-hardware-solutions.square.site/product/entropia-v2-seed-tablets/11
That does not eliminate every possible risk, but it avoids relying entirely on one company’s random-number generator.
It may also be worth asking yourself another uncomfortable question:
Should all of your generational wealth depend on one seed phrase, one device, and one hiding place?
You do not have to become a security expert overnight, but it is worth investing the time to learn about multisignature wallets. A properly designed multisig setup can require keys stored on different devices and in different locations before Bitcoin can be moved.
Do not panic. Do not rush. Learn how your wallet was created, update your firmware, verify your backups, and understand your recovery process before moving significant funds.
Bitcoin gives us the ability to hold our own wealth. It also gives us the responsibility to protect it.
Functional art that can help secure your bitcoin! Entropia is a BIP39 lottery system that you can use to trustlessly create secure bitcoin private keys. Choose 11 or 23 words at random, and then use a bitcoin signing device like SeedSigner to calculate the final checksum word that completes your see...