Crypto, Decoded: The Coldcard Incident, Explained
Hundreds of bitcoin were stolen through a flaw in how some wallet seeds were generated. Here's what happened, why it matters, and what every Coldcard user should know.
I woke up to a flood of the same message this week:
“Kelly Ann, I thought hardware wallets were the safe option. What just happened with Coldcard?”
Fair question. It surprised a lot of experienced Bitcoin holders, too.
This one hit the Bitcoin community hard because it involved the very devices many people buy specifically to keep their bitcoin safe. So let’s decode what happened, without the jargon or the panic.
What Actually Happened
Late on the night of July 30 into July 31, an attacker drained hundreds of Bitcoin wallets in about 25 minutes. Initial estimates identified approximately 594 bitcoin stolen from around 500 wallets. As investigators continued tracing the attack, researchers identified additional affected wallets, pushing estimated losses beyond $70 million.
The wallets identified in the initial attack all appear to have been created using Coldcard hardware wallets, a popular device made by Canadian company Coinkite. Hardware wallets are designed to keep your private keys offline, making them one of the safest ways to secure bitcoin.
The incident was independently identified by researchers, including teams at Block and Galaxy Research. Coinkite has since confirmed a flaw affecting certain firmware versions and released updated firmware along with guidance for users.
The Part That Matters
What makes this incident unusual is what didn’t happen.
Nobody clicked a phishing link.
Nobody downloaded malware.
Nobody’s computer was remotely hacked.
Instead, the problem occurred at the very beginning, when some wallets were originally created.
A flaw in certain Coldcard firmware versions dating back to early 2021 meant that some devices did not generate wallet seeds with enough randomness. Instead, some recovery phrases were created using significantly less entropy than intended, making them far more predictable than they should have been.
Why does that matter?
Your recovery phrase, those 12 or 24 words that control your bitcoin, is only secure because it comes from an unimaginably large pool of random possibilities. With enough randomness, guessing that phrase is effectively impossible.
Reduce that randomness, and those possibilities shrink dramatically, making it possible for attackers to reproduce seeds that should have been impossible to guess.
Rather than breaking into the wallets themselves, researchers believe the attacker was able to recreate the private keys by exploiting weaknesses in how some wallet seeds had originally been generated.
One important exception involved users who added their own randomness during wallet setup, such as by rolling physical dice. Because those recovery phrases weren't created solely by the affected firmware, researchers believe those wallets were not vulnerable to this specific attack.
Many of the affected wallets had remained untouched for years, consistent with the timeframe during which the vulnerable firmware versions were in use.
Do You Own a Coldcard? Here’s What To Do
First, don’t panic. Not every Coldcard is affected. The risk depends primarily on the firmware version your device was running when your wallet was originally created, not simply on owning a Coldcard today.
If you think your wallet may have been created using one of the affected firmware versions:
Check Coinkite’s guidance to determine whether your firmware version may have been impacted.
Update your device to the latest firmware.
If your wallet may be affected, create an entirely new wallet using the updated firmware and move your bitcoin to the new wallet.
Do not simply import your old recovery phrase into another wallet. If the original seed was generated with weak entropy, it remains vulnerable no matter where you use it.
If you protected your wallet with a BIP-39 passphrase, your risk appears to be significantly lower. Even so, many security researchers recommend migrating to a newly generated wallet for additional peace of mind.
If you originally generated your wallet using your own dice rolls during setup, this specific vulnerability is not believed to affect those recovery phrases.
If you don’t own a Coldcard, this specific issue does not affect other hardware wallets. And despite the headlines, the broader Bitcoin market barely reacted.
The SheCrypto Takeaway
This is exactly why we talk about self-custody in plain language instead of treating it like a black box.
A hardware wallet doesn’t just keep your private keys offline. It also has to generate those keys using truly unpredictable randomness. If that very first step isn’t done correctly, every layer of security that comes afterward is built on a weaker foundation.
The good news is that incidents like this are rare, and the security community identified the issue quickly, shared the findings publicly, and provided guidance for affected users.
None of this means self-custody is broken. It means the tools we trust should be continually tested, improved, and understood.
It does remind us that understanding why a wallet is secure is just as important as knowing that it’s secure.
Questions are a good thing. Staying informed is one of the best security tools you have.
The more you understand your crypto, the more confident you’ll be using it.
Until next time,
Kelly Ann Collins
Disclaimer: SheCrypto is a nonprofit media and educational program of Unstoppable Future Corporation covering cryptocurrency, blockchain, and emerging technologies. The content published by SheCrypto is intended for informational, entertainment, and educational purposes only and should not be relied upon as financial, investment, legal, tax, or accounting advice. Views expressed are those of the author unless otherwise noted. Always conduct your own research (DYOR) and consult qualified professionals before making investment or financial decisions.



