Coldcard Hack: Was Your Bitcoin Wallet Affected, and Can It Be Recovered?
Sometimes, yes. If your Coldcard has not been drained yet, move your Bitcoin to a newly generated seed today, before the flaw is used against you. If it has already been drained, the theft is traceable on Bitcoin's public ledger, and Recoveris can assess whether the funds can still be intercepted.
Coinkite disclosed a firmware flaw on 1 August 2026 that let attackers reconstruct the private keys of certain Coldcard wallets without ever touching the device. Since 30 July, more than 1,500 BTC has been drained from thousands of addresses, and the theft is still active. If you own a Coldcard, this page shows how to check whether you are affected, what to do in the next few minutes, and what recovery realistically looks like if you were already hit.
Was my Coldcard wallet affected by the hack, and can stolen Bitcoin be recovered?
Your Coldcard may be affected if its seed phrase was generated on firmware released between March 2021 and 31 July 2026, without extra dice-roll entropy. A firmware update alone does not fix an already-generated seed. If funds are still in the wallet, move them to a freshly generated seed immediately. If they are already gone, the theft is traceable on Bitcoin's public blockchain, and recovery depends on where the funds are sent next.
Why this is different from a typical hack
- The weakness was in the randomness, not your behaviour. A firmware bug bypassed the device's hardware randomness chip and used a predictable software substitute instead.
- No phishing or physical theft was required. Attackers reconstruct private keys directly from the weak seed, without your seed phrase, device, or a single mistake on your part.
- The exploit is still active. Public research has identified at least 15 separate attacker groups targeting the same flaw, so unmigrated wallets remain exposed.
What to do now
- Check whether your seed was generated on vulnerable firmware (before v4.2.0 Mk3 / v5.6.0 Mk4-Mk5 / v1.5.0Q).
- If funds remain, generate a brand-new seed with real entropy on a wallet the flaw never touched, and move everything now, not just an update.
- If funds are already gone, preserve the transaction IDs, receiving addresses, and your device's firmware history, then request a free case review.
Is your Coldcard affected?
Start with your firmware version. Open Settings on your Coldcard and check which release it is running, then compare that against Coinkite's own security advisory. Broadly: any Mk3 running firmware from 4.0.1 to 4.1.9, and any Mk4, Mk5 or Q running firmware from the March 2021 release (v4.0.0) up to the 31 July 2026 fix, sits in the affected range. If your device predates that window, or you added significant extra randomness yourself during setup (Coinkite recommends at least 50 private dice rolls), your exposure is lower. If you are unsure, treat the wallet as exposed.
This matters even if your coins are still sitting untouched. The flaw does not require an attacker to see your device, your seed phrase or your transactions. It only requires enough computing time to reconstruct a weak key from public information. Updating the firmware protects any seed you generate from today onward. It does nothing for a seed that was already created before the fix.

"This was not a scam you fell for. A cryptographic flaw meant thousands of Coldcard wallets never had a truly random seed. If yours is one of them, updating the firmware is not enough, you need a brand-new seed on a wallet the flaw never touched. If you already lost funds, the trace works exactly like any other Bitcoin theft: public, and time-sensitive."
How the Coldcard exploit works
Coldcard hardware wallets, made by the Canadian company Coinkite, are built to generate a Bitcoin wallet's seed phrase, the 12 or 24 words that control every coin in it, using a dedicated chip whose only job is producing unpredictable randomness. On 1 August 2026, Coinkite disclosed that a firmware bug, present since a March 2021 release (v4.0.0), had in some cases bypassed that chip and fallen back to a predictable, software-based substitute instead.
The practical effect is that some wallets never had a truly random seed. Coinkite's own technical review found that affected Mk4, Mk5 and Q devices produced roughly 72 bits of randomness instead of the intended 128, and Mk3 devices running firmware 4.0.1 through 4.1.9 fell to around 40 bits, low enough that a well-resourced attacker can reconstruct the exact same private key through computation alone.
That is what makes this different from a typical scam. Nobody phished the owner, nobody stole a device, and no seed phrase was ever typed into a fake website. The weakness lived inside the wallet's own key generation, waiting.
The first confirmed wave hit on 30 July 2026: an attacker drained 1,196 addresses in 41 minutes, worth roughly $70 million at the time. Coinkite widened its advisory on 1 August after finding the flaw reached beyond the Mk3 line. Since then, researchers have tracked at least 15 separate attacker groups running the same reconstruction technique against different corners of the vulnerable address space, and the theft is still active.
If you own a Coldcard, none of this required you to make a mistake. It required your seed to have been generated on the wrong firmware, at the wrong time. What matters now is whether that seed still holds any Bitcoin.
The scale of the theft so far
This is one of the largest hardware-wallet incidents on record, and the figures below are still moving as investigators identify more exposed addresses. Treat them as a floor, not a final count.
Coinkite has described the threat as ongoing. If you have not yet confirmed whether your own wallet was exposed, the numbers above are the reason not to wait for a firmer total before you act.
If your Coldcard has not been drained yet: act now
Do these four things before anything else. Updating the firmware is step two, not step one, because it cannot repair a seed that already exists.
Confirm your firmware and seed origin
Check the version in your device settings against Coinkite's advisory.
Generate a brand-new seed with real entropy
On the fixed firmware, adding at least 50 private dice rolls during setup.
Move every coin to the new wallet immediately
Transfer the full balance without delay, before checking anything else.
Retire the old seed completely
Treat it as burned even if it looks untouched. Never reuse it on any device.
If your Bitcoin was already stolen: can it be recovered?
If your Coldcard has already been drained, the situation is the same as any other Bitcoin theft: painful, but not automatically hopeless. Every satoshi that left your wallet moved to a new address, and Bitcoin's ledger records that movement permanently and publicly. Recovery from a theft this size follows three stages.
Trace
We follow your stolen Bitcoin across addresses, mixers and swap services, the same forensic work behind how we recover stolen Bitcoin, cross-referenced against the wider set of addresses linked to this exploit.
Intercept
Once the funds hit a regulated exchange, the point where Bitcoin converts back into ordinary money, we move to freeze them there using court-admissible evidence.
Recover
From there, frozen funds make their way back through legal channels and law-enforcement cooperation.
Your odds rise if you act within hours or days of noticing the theft, if the funds land on an exchange that verifies identity (KYC), and if you can supply your wallet's address history and transaction IDs. They fall the longer funds sit unclaimed or move through non-KYC services. Because this exploit has drawn public attention from researchers and exchanges alike, addresses linked to it are already being watched more closely than an average theft, which can work in your favour if you report quickly. If the theft reached other assets tied to a hacked or drained software wallet, the same tracing principles apply there too. The assessment is free, and it is honest about where your specific case stands.

Advises OSCE and Interpol on virtual assets, and has served as a US court expert witness on the QuadrigaCX and DAO hack cases.
LinkedIn
An attorney who helped build the crypto-asset task force inside the Buenos Aires prosecutor's office.
LinkedIn
Specialises in Source of Funds work, with thousands of cases traced on behalf of corporations and banks.
LinkedIn
Previously led Global Investigations at MoonPay, and has run more than 1,000 complex crypto investigations.
LinkedIn
25+ years in OSINT and digital forensics, having started his career as a Guardia di Finanza investigator.
LinkedInAvoid the second scam: fake "Coldcard support"
Watch for fake "Coinkite support"
Large, public thefts always draw a second wave of criminals. Since this exploit became news, opportunists have been contacting Coldcard owners posing as Coinkite staff, wallet "migration specialists" or blockchain analysts who claim they can secure or recover your funds. The pattern is identical to other fake recovery scams: they ask for your seed phrase, remote access to your device, or an upfront fee tied to a guarantee. A legitimate firm never asks for your seed phrase, never guarantees an outcome, and never demands a large fee before assessing your case. If someone contacted you first, treat it as a second scam.
The same rule applies to firmware. Only update through the official Coldcard channel. A link sent to you by email, DM or a search ad is reason enough to stop and verify independently.
Frequently asked questions
Was my Coldcard affected by the hack?
I just updated my firmware - am I safe now?
My Coldcard hasn't been drained yet - what do I do right now?
My Bitcoin was already stolen from my Coldcard - can it be recovered?
How did hackers steal Bitcoin from an offline hardware wallet without touching it?
Someone contacted me claiming to be Coinkite or Coldcard support - is that real?
How much Bitcoin has been stolen in the Coldcard hack?
Is it still safe to use a Coldcard?
What should I preserve if my Bitcoin was already stolen?
Can law enforcement help with a theft this large?
The flaw is in the firmware. The trail is still permanent.
Tell us what happened and get a free, honest assessment of whether your Coldcard Bitcoin can still be secured or reached.
Every recovery case is different, and no outcome can be guaranteed. The scale figures on the Coldcard/Coinkite exploit reflect public reporting current as of early August 2026 and are likely to change. Nothing on this page is legal or financial advice.