===== SCHEMA: Article + Person author + HowTo + FAQPage + BreadcrumbList. JSON-LD is valid inside the body, so it ships with the pasted HTML. If Yoast already outputs BreadcrumbList for this page, remove that node here. =====
Digital Asset Recovery – Recoveris AG, Zug

Coldcard Hack: Was Your Bitcoin Wallet Affected, and Can It Be Recovered?

Sometimes, yes. If your Coldcard has not been drained yet, move your Bitcoin to a newly generated seed today, before the flaw is used against you. If it has already been drained, the theft is traceable on Bitcoin's public ledger, and Recoveris can assess whether the funds can still be intercepted.

Coinkite disclosed a firmware flaw on 1 August 2026 that let attackers reconstruct the private keys of certain Coldcard wallets without ever touching the device. Since 30 July, more than 1,500 BTC has been drained from thousands of addresses, and the theft is still active. If you own a Coldcard, this page shows how to check whether you are affected, what to do in the next few minutes, and what recovery realistically looks like if you were already hit.

EY technical partner  ·  Court-admissible reporting  ·  Led by former law enforcement & prosecutors Updated August 2026
The direct answer

Was my Coldcard wallet affected by the hack, and can stolen Bitcoin be recovered?

Your Coldcard may be affected if its seed phrase was generated on firmware released between March 2021 and 31 July 2026, without extra dice-roll entropy. A firmware update alone does not fix an already-generated seed. If funds are still in the wallet, move them to a freshly generated seed immediately. If they are already gone, the theft is traceable on Bitcoin's public blockchain, and recovery depends on where the funds are sent next.

Why this is different from a typical hack

  • The weakness was in the randomness, not your behaviour. A firmware bug bypassed the device's hardware randomness chip and used a predictable software substitute instead.
  • No phishing or physical theft was required. Attackers reconstruct private keys directly from the weak seed, without your seed phrase, device, or a single mistake on your part.
  • The exploit is still active. Public research has identified at least 15 separate attacker groups targeting the same flaw, so unmigrated wallets remain exposed.

What to do now

  1. Check whether your seed was generated on vulnerable firmware (before v4.2.0 Mk3 / v5.6.0 Mk4-Mk5 / v1.5.0Q).
  2. If funds remain, generate a brand-new seed with real entropy on a wallet the flaw never touched, and move everything now, not just an update.
  3. If funds are already gone, preserve the transaction IDs, receiving addresses, and your device's firmware history, then request a free case review.
Sources: Coinkite security advisory; CoinDesk; TechCrunch; Recoveris – Recover Stolen Bitcoin.

Is your Coldcard affected?

01

Start with your firmware version. Open Settings on your Coldcard and check which release it is running, then compare that against Coinkite's own security advisory. Broadly: any Mk3 running firmware from 4.0.1 to 4.1.9, and any Mk4, Mk5 or Q running firmware from the March 2021 release (v4.0.0) up to the 31 July 2026 fix, sits in the affected range. If your device predates that window, or you added significant extra randomness yourself during setup (Coinkite recommends at least 50 private dice rolls), your exposure is lower. If you are unsure, treat the wallet as exposed.

This matters even if your coins are still sitting untouched. The flaw does not require an attacker to see your device, your seed phrase or your transactions. It only requires enough computing time to reconstruct a weak key from public information. Updating the firmware protects any seed you generate from today onward. It does nothing for a seed that was already created before the fix.

Umberto Buonora, Head of Investigations at Recoveris
"This was not a scam you fell for. A cryptographic flaw meant thousands of Coldcard wallets never had a truly random seed. If yours is one of them, updating the firmware is not enough, you need a brand-new seed on a wallet the flaw never touched. If you already lost funds, the trace works exactly like any other Bitcoin theft: public, and time-sensitive."
Umberto BuonoraHead of Investigations, Recoveris AG · former Guardia di Finanza

How the Coldcard exploit works

02

Coldcard hardware wallets, made by the Canadian company Coinkite, are built to generate a Bitcoin wallet's seed phrase, the 12 or 24 words that control every coin in it, using a dedicated chip whose only job is producing unpredictable randomness. On 1 August 2026, Coinkite disclosed that a firmware bug, present since a March 2021 release (v4.0.0), had in some cases bypassed that chip and fallen back to a predictable, software-based substitute instead.

The practical effect is that some wallets never had a truly random seed. Coinkite's own technical review found that affected Mk4, Mk5 and Q devices produced roughly 72 bits of randomness instead of the intended 128, and Mk3 devices running firmware 4.0.1 through 4.1.9 fell to around 40 bits, low enough that a well-resourced attacker can reconstruct the exact same private key through computation alone.

That is what makes this different from a typical scam. Nobody phished the owner, nobody stole a device, and no seed phrase was ever typed into a fake website. The weakness lived inside the wallet's own key generation, waiting.

The first confirmed wave hit on 30 July 2026: an attacker drained 1,196 addresses in 41 minutes, worth roughly $70 million at the time. Coinkite widened its advisory on 1 August after finding the flaw reached beyond the Mk3 line. Since then, researchers have tracked at least 15 separate attacker groups running the same reconstruction technique against different corners of the vulnerable address space, and the theft is still active.

If you own a Coldcard, none of this required you to make a mistake. It required your seed to have been generated on the wrong firmware, at the wrong time. What matters now is whether that seed still holds any Bitcoin.

The scale of the theft so far

03

This is one of the largest hardware-wallet incidents on record, and the figures below are still moving as investigators identify more exposed addresses. Treat them as a floor, not a final count.

1,500+ BTC
Confirmed stolen across multiple attack waves since 30 July 2026
CoinDesk; TechCrunch, early Aug 2026
$100M+
Approximate value at time of theft, and still climbing
CoinDesk; TechCrunch
7,000+
Bitcoin addresses drained from vulnerable Coldcard seeds
Galaxy Research, via TechCrunch
15
Separate attacker groups identified running the same exploit
Galaxy Research

Coinkite has described the threat as ongoing. If you have not yet confirmed whether your own wallet was exposed, the numbers above are the reason not to wait for a firmer total before you act.

If your Coldcard has not been drained yet: act now

04

Do these four things before anything else. Updating the firmware is step two, not step one, because it cannot repair a seed that already exists.

1

Confirm your firmware and seed origin

Check the version in your device settings against Coinkite's advisory.

2

Generate a brand-new seed with real entropy

On the fixed firmware, adding at least 50 private dice rolls during setup.

3

Move every coin to the new wallet immediately

Transfer the full balance without delay, before checking anything else.

4

Retire the old seed completely

Treat it as burned even if it looks untouched. Never reuse it on any device.

If your Bitcoin was already stolen: can it be recovered?

05

If your Coldcard has already been drained, the situation is the same as any other Bitcoin theft: painful, but not automatically hopeless. Every satoshi that left your wallet moved to a new address, and Bitcoin's ledger records that movement permanently and publicly. Recovery from a theft this size follows three stages.

Stage 01

Trace

We follow your stolen Bitcoin across addresses, mixers and swap services, the same forensic work behind how we recover stolen Bitcoin, cross-referenced against the wider set of addresses linked to this exploit.

Stage 02

Intercept

Once the funds hit a regulated exchange, the point where Bitcoin converts back into ordinary money, we move to freeze them there using court-admissible evidence.

Stage 03

Recover

From there, frozen funds make their way back through legal channels and law-enforcement cooperation.

Your odds rise if you act within hours or days of noticing the theft, if the funds land on an exchange that verifies identity (KYC), and if you can supply your wallet's address history and transaction IDs. They fall the longer funds sit unclaimed or move through non-KYC services. Because this exploit has drawn public attention from researchers and exchanges alike, addresses linked to it are already being watched more closely than an average theft, which can work in your favour if you report quickly. If the theft reached other assets tied to a hacked or drained software wallet, the same tracing principles apply there too. The assessment is free, and it is honest about where your specific case stands.

Umberto Buonora, Head of Investigations at Recoveris
Led by Umberto Buonora, Head of Investigations

Spent his early career as a Guardia di Finanza investigator working financial crime, and now leads Recoveris' tracing, exchange-freeze and court-ready evidence work. LinkedIn

Meet the intelligence team
Roman Bieda, Co-founder and Head of Product at Recoveris
Roman Bieda
Co-founder and Head of Product

Advises OSCE and Interpol on virtual assets, and has served as a US court expert witness on the QuadrigaCX and DAO hack cases.

LinkedIn
Sol Cinosi, Chief Government & Corporate Affairs Officer at Recoveris
Sol Cinosi
Chief Government & Corporate Affairs Officer

An attorney who helped build the crypto-asset task force inside the Buenos Aires prosecutor's office.

LinkedIn
Dominik Konopacki, Blockchain Investigations Manager at Recoveris
Dominik Konopacki
Blockchain Investigations Manager

Specialises in Source of Funds work, with thousands of cases traced on behalf of corporations and banks.

LinkedIn
Dawid Koperski, Blockchain Investigations Manager at Recoveris
Dawid Koperski
Blockchain Investigations Manager

Previously led Global Investigations at MoonPay, and has run more than 1,000 complex crypto investigations.

LinkedIn
Alessandro Rella, Blockchain Investigations Manager at Recoveris
Alessandro Rella
Blockchain Investigations Manager

25+ years in OSINT and digital forensics, having started his career as a Guardia di Finanza investigator.

LinkedIn

Avoid the second scam: fake "Coldcard support"

06

Watch for fake "Coinkite support"

Large, public thefts always draw a second wave of criminals. Since this exploit became news, opportunists have been contacting Coldcard owners posing as Coinkite staff, wallet "migration specialists" or blockchain analysts who claim they can secure or recover your funds. The pattern is identical to other fake recovery scams: they ask for your seed phrase, remote access to your device, or an upfront fee tied to a guarantee. A legitimate firm never asks for your seed phrase, never guarantees an outcome, and never demands a large fee before assessing your case. If someone contacted you first, treat it as a second scam.

The same rule applies to firmware. Only update through the official Coldcard channel. A link sent to you by email, DM or a search ad is reason enough to stop and verify independently.

Frequently asked questions

07
Was my Coldcard affected by the hack?
Possibly, if your seed phrase was generated on Coldcard firmware released between March 2021 (v4.0.0) and 31 July 2026, on a Mk3, Mk4, Mk5 or Q device, without extra dice-roll entropy added during setup. Check your firmware version in the device menu and compare it against Coinkite's security advisory at coinkite.com. If you are unsure, treat the wallet as exposed and act now.
I just updated my firmware - am I safe now?
No, not on its own. The new firmware (v4.2.0 for Mk3, v5.6.0 for Mk4/Mk5, v1.5.0Q for Q) fixes how future seeds are generated, but it cannot repair a seed that already exists. If that seed was created on vulnerable firmware, it is still weak. You need to move your Bitcoin to a brand-new seed generated after the fix, on a wallet the flaw never touched.
My Coldcard hasn't been drained yet - what do I do right now?
Generate a new seed with genuine entropy (Coinkite recommends at least 50 private dice rolls during setup), move every coin from the old wallet to the new one immediately, and then retire the old seed completely. Do this before checking anything else. Attackers do not need your device or your seed phrase, only enough time to reconstruct the key.
My Bitcoin was already stolen from my Coldcard - can it be recovered?
Sometimes, yes. The theft moved your Bitcoin to a new address, and every movement on Bitcoin's ledger is public and permanent. Recoveris traces the funds toward the exchange or service where they are eventually cashed out and pursues a freeze there with forensic evidence. Recovery is never guaranteed, and speed matters. A free case review tells you honestly where your case stands.
How did hackers steal Bitcoin from an offline hardware wallet without touching it?
Through a software flaw, not physical theft. A bug in Coldcard's firmware caused some devices to bypass their dedicated hardware randomness chip and generate seed phrases with a predictable software substitute instead. With weak enough randomness, an attacker can reconstruct the same private key mathematically, entirely offline, and empty the wallet without ever seeing the device or the seed phrase.
Someone contacted me claiming to be Coinkite or Coldcard support - is that real?
Treat it as a scam unless you verify it through Coinkite's official site yourself. Panic around this exploit has already drawn opportunists who impersonate wallet makers, ask victims to "verify" or "migrate" their seed phrase, or send fake firmware update links. No legitimate support team will ever ask for your seed phrase. Hang up, close the chat, and go directly to coinkite.com.
How much Bitcoin has been stolen in the Coldcard hack?
Public reporting as of early August 2026 puts confirmed losses above 1,500 BTC (more than $100 million) across multiple attack waves and thousands of addresses, with researchers tracking at least 15 separate attacker groups. Coinkite has described the threat as still active, so the total is likely to keep rising. Check Coinkite's advisory for the current figure.
Is it still safe to use a Coldcard?
A Coldcard running the fixed firmware, with a seed generated after 31 July 2026 and genuine dice-roll entropy, is not affected by this specific flaw. The risk sits with seeds generated before the fix, not with the hardware itself. If your seed predates the fix, migrate it regardless of which model you own.
What should I preserve if my Bitcoin was already stolen?
Save the outgoing transaction IDs and the addresses they went to, your Coldcard's serial number and firmware version history, the date you set up the wallet, and any communication from someone who later offered to "help" recover the funds. Those details are what a trace is built on.
Can law enforcement help with a theft this large?
Yes, and at this scale they likely already are. Report the theft to your local police and, if you're in the US, the FBI's IC3, and to Coinkite directly. A court-admissible forensic report strengthens whatever action they can take, and cases tied to a widely reported exploit often move faster because exchanges are already watching for related addresses.
Free Strategic Assessment

The flaw is in the firmware. The trail is still permanent.

Tell us what happened and get a free, honest assessment of whether your Coldcard Bitcoin can still be secured or reached.

Start Your Recovery →

Every recovery case is different, and no outcome can be guaranteed. The scale figures on the Coldcard/Coinkite exploit reflect public reporting current as of early August 2026 and are likely to change. Nothing on this page is legal or financial advice.

/.lp-template