The Coinkite Coldcard Wallet Hack Explained

The Coinkite Coldcard Wallet Hack Explained

What Is a Coldcard Wallet Hack?

Cold wallets are often seen as one of the safest ways to store bitcoin. Still, things went badly wrong this week at Coldcard, Coinkite’s hardware wallet. Because of an old bug in the firmware, some recovery phrases were less random than expected, which let hackers crack the matching wallets remotely. In total, an estimated 1,816 BTC was stolen, worth about $116 million at the time of writing.

In this case, a Coldcard wallet hack is mainly about a weakly generated recovery seed, not about an attacker simply getting physical access to your Coldcard (hardware wallet).

Coldcard is a Bitcoin-only hardware wallet from crypto company Coinkite. This kind of crypto wallet stores your private keys offline and uses them to sign Bitcoin transactions.

During the 2026 security incident, it turned out that certain firmware versions could create a seed with too little randomness. That randomness is called entropy. Simply put, the more entropy there is, the larger the number of possible seeds and the harder it is to guess or recreate your seed.

If someone can reconstruct a weak seed, they can also derive the private keys from it. After that, the attacker can restore the wallet on another system and send Bitcoin. That means they do not necessarily need your Coldcard, PIN, or recovery words. In other words, even people who kept their hardware wallet in a physical safe were not safe. A wallet is always digitally accessible if someone has your seed phrase and private keys.

So the term “hack” is actually a bit broad here. It was specifically a flaw in the seed generation of vulnerable firmware, not an online Coinkite account or an attack where every Coldcard was automatically taken over.


Key Takeaways

  • The incident was about a flaw in how some Coldcard seeds were created.
  • A seed with too little entropy can be easier to reconstruct than intended.
  • Anyone who can reconstruct a seed can derive the matching Bitcoin private keys.
  • A PIN protects the device, but it does not fix a weak seed.
  • An existing vulnerable seed needs to be migrated to a new, securely generated seed.

How Was the Coinkite Wallet Hacked?

The vulnerability was in the way some Coldcards created a new recovery phrase. Because of a software bug, these recovery phrases were less random than they should have been.

That meant hackers had far fewer possible combinations to try. With enough computing power, they could figure out certain recovery phrases and gain access to the bitcoin tied to them. They did not need to get their hands on the Coldcard itself. So many investors were also unaware of the problem and only found out later that their coins had been stolen.

The problem had been in several software versions since 2021. Users who created a new recovery phrase on their Coldcard during that period were especially at risk. Updating the software alone is not enough: an old, vulnerable recovery phrase stays vulnerable because it never changes. That is why users need to create a new recovery phrase after the update and move their bitcoin to the new wallet.

An extra password on top of the recovery phrase could protect the wallet better. The device’s regular PIN did not help against this attack, because hackers could use the stolen recovery phrase on another device.

What Security Layers Did Coinkite's Coldcard Wallet Use?

The Coldcard had several security layers. For example, the private keys stayed offline on the device, and transactions could be signed without connecting the wallet directly to the internet. A PIN kept someone from simply opening the device, while special security chips were meant to protect the secret keys against physical attacks.

Users could also set an extra password or combine multiple wallets, so that a transaction needed multiple digital signatures. They could also store their recovery phrase offline to restore the wallet if it was lost or damaged.

Still, one crucial layer did not work properly: creating the recovery phrase. If that is too predictable from the start, many other security measures can be bypassed. In that case, an attacker does not need to crack the device or the PIN, but can try to figure out the recovery phrase directly. Unsuspecting customers were therefore also completely caught off guard by the fact that Coinkite did not have its security in order.

What Can You Do If Your Hardware Wallet Is Hacked?

Do you see unknown transactions or think your recovery phrase has been leaked? Then assume your wallet is no longer safe. A software update is not enough: your existing recovery phrase and keys stay the same.

Act quickly, but be careful. A wrong address or a badly stored backup can also cause losses while you move your bitcoin.

  1. Update the software If your wallet is not empty yet, install the latest official software for your hardware wallet as soon as possible. Only download updates from the manufacturer’s website.
  2. Create a completely new wallet After the update, create a new wallet with a new recovery phrase. Do not simply move your old recovery phrase to another device, because the risk will still remain.
  3. Store and check your new recovery phrase Write down the new recovery phrase and store it offline. Then check on your hardware wallet’s screen whether the new receiving address is correct.
  4. Send a small test amount first Send a small amount to the new wallet and check whether it arrives. Only then move the rest of your bitcoin.
  5. Keep the old backup temporarily Do not throw away your old recovery phrase right away. Keep it until the full move has been confirmed. After that, do not use the old wallet anymore.

Stolen bitcoin transactions usually cannot be reversed. So record unknown transactions and report the theft to the police.

Never share your recovery phrase or extra password with anyone. Not even if an exchange asks for it. Even a real support agent will not ask for this. Whoever has your recovery phrase can, in principle, access your bitcoin.

How Do You Prevent a Coldcard Wallet Hack?

You can never rule out a hack completely, but you can greatly reduce the risk. With Coldcard, it is especially important to use the latest software and handle your recovery phrase carefully.

  1. Keep your Coldcard updated Always install the latest official software before creating a new wallet. Only download updates from Coldcard’s website.
  2. Create a new recovery phrase if needed Was your recovery phrase created with vulnerable software? Then updating alone is not enough. After the update, create a new wallet and move your bitcoin to the new address.
  3. Keep your recovery phrase fully offline Do not take a photo or make a digital copy, and do not store the words in your email or cloud storage. Also never share them with a website or support agent.
  4. Use an extra password if you want A strong, unique extra password can better protect your wallet if someone figures out your recovery phrase. Store this password separately and carefully: if you forget it, you may no longer be able to open the matching wallet.
  5. Check every transaction on the device Before approving, always check the receiving address, amount, and transaction fees on your Coldcard’s screen. Do not rely only on the information shown by your computer or phone.
  6. Test your backup Check whether you can actually regain access to your wallet with your recovery phrase before sending a large amount to it.

If you want to add extra randomness yourself when creating your recovery phrase, you can use dice for that. Only do this if you know exactly how it works. If you are unsure, creating a new recovery phrase with the updated software is the safer choice.

What If You Are a Victim of This Hack?

Do you think your Coldcard was affected? Then assume your recovery phrase is no longer safe. First update your Coldcard, create a completely new wallet, and move your bitcoin as quickly as possible. Send a small test amount first and carefully check the new address before transferring the rest.

Have your bitcoins already been stolen? Then unfortunately the transaction cannot be reversed. Save all information about the transactions and addresses and report the theft to Coinkite and the police. Never share your recovery phrase with anyone who promises to get your bitcoin back: these are often scammers trying to strike again. If the Bitcoins have actually been taken from your wallet, there is no one, except the hacker themselves, who can recover those coins anymore.

Conclusion

The Coldcard hack shows that even a hardware wallet is not automatically fully safe. Because of a software bug, some recovery phrases were generated with less randomness than intended. Hackers were then able to reconstruct these recovery phrases and empty the matching wallets without needing the physical Coldcard or PIN. In total, an estimated 1,816 BTC was stolen, worth about $116 million at the time of writing.

The incident highlights how important it is to keep hardware wallets updated regularly and take security warnings from manufacturers seriously. Anyone who may be using an affected recovery phrase should not only update the software, but also create a completely new wallet and carefully move the remaining bitcoin. An update does not make a previously created, vulnerable recovery phrase safe after the fact.

Cold storage reduces many risks, but it does not remove them completely. In the end, a wallet’s security depends not only on the physical device, but also on the software, the recovery phrase creation process, and how the user stores the backup. So the main lesson from this hack is simple: do not blindly trust one security layer, stay aware of vulnerabilities, and act right away when your wallet may be at risk.

About Finst

Finst is a leading cryptocurrency platform in the Netherlands, providing ultra-low trading fees, institutional-grade security, and a comprehensive suite of crypto services such as trading, custody, staking, and fiat on/off-ramp. Finst, founded by DEGIRO's ex-core team, is authorized as a crypto-asset service provider under MiCAR by the Dutch Authority for Financial Markets (AFM) and serves both retail and institutional clients in 30 European countries.

The crypto platform for all investors

Whether you're an active trader or long-term investor, Finst enables you to grow your crypto wealth with confidence and peace of mind.

Sign up