Quick Read
-
An attacker drained $70 million from 1,200 Coldcard wallets in 40 minutes by remotely reproducing predictable seeds, on July 30 without touching a single device.
-
A 2021 firmware bug cut possible seed values to 4 billion, making them reproducible from public data like serial numbers and clock readings.
-
Coldcard owners who rolled their own dice during setup ended up with seeds the attacker could not reproduce, and those wallets survived untouched.
-
Updating the firmware cannot fix an affected seed, so the only cure is a new seed generated on fixed firmware and a careful migration.
-
Two retirees, same $1 million, same 4% rule, buy one finished with $1.4 million, the other hit $0 in 12 years. Our free reader guide explains the flaw that separated them, and the income-first method built to avoid it.
A hardware wallet keeps your Bitcoin (CRYPTO:BTC) keys on a small device that never connects to the internet, so there is nothing online for a hacker to reach. For years, that design has kept holdings safe while hackers went after exchanges and online wallets, and it’s the reason many long-term holders keep their coins in cold storage.
But the protection failed on July 30, when an attacker drained about $70 million in Bitcoin from roughly 1,200 Coldcard wallets in around 40 minutes without touching a single device. Many of the owners were holders whose coins had not moved in years.
So if the safest way to hold Bitcoin can fail like this, how do you keep your assets safe?
How Hackers Drained Cold Wallets Without Touching Them

PR Image Factory / Shutterstock.com
When you set up a hardware wallet, the device picks a random number so large that guessing it is meant to be impossible, then turns that number into the 12 or 24 seed words you write down. The words and the number are the same secret in two forms, and every address and private key you will ever own comes from that seed by rules that are public, so anyone who knows it owns the coins.
The 4% Rule is Broken, Built On A World That No Longer Exists
Every retiree knows about the 4% rule, but it frames retirement as a slow liquidation and still causes retirees with seven-figure accounts to agonize over a dinner out.
There’s a different way to run the math that makes more sense today. Build an income floor — dividends, interest, and Social Security that cover your essential bills every month — and you never have to sell shares into a down market just to pay them.
Our free reader guide, The 4% Rule Is Broken, walks through it in about 15 minutes. Access the report here.
However, a change to Coldcard’s firmware in March 2021 quietly stopped the device from using its own hardware randomness generator. Key generation fell back to a basic software substitute built from the chip’s serial number and its internal clock readings. Neither of those is secret, since the serial number is fixed factory data and the clock readings are timings that anyone can reproduce on a device of their own.
That left each device able to produce only a small set of possible seeds. Block’s engineering team, which found the flaw, worked out that the newer models could only draw from roughly four billion possible values, a number that sounds enormous until a computer starts counting through it.
So the attacker never needed the hardware. They generated candidate seeds on their own machine, worked out the addresses each one would produce, then checked those addresses against the public blockchain, where every wallet’s balance is visible to anyone. Nothing in that process touches the victim, whose device might as well have been locked in a vault the whole time.
Chainalysis traced the sweep and found it was planned, with the attacker hitting the highest-value wallets first, including one holding $1.8 million, and collecting about $30 million inside the first ten minutes. The sweep also ran almost 30 hours before Coinkite published its first warning, so the coins were long gone by the time owners knew there was anything to check.
Why a Firmware Update Won’t Save a Weak Seed

Apichatn / Shutterstock.com
Coinkite has released fixed firmware for every affected model, and its own advisory is blunt about what the fix does. The new firmware makes the device generate proper random seeds from now on, and it cannot repair a seed the broken firmware already produced, because the update changes the machine, and the weakness lives in the number the machine already picked.
And moving that seed somewhere safer doesn’t work. Block’s team, which published the findings, warned that a seed born on a vulnerable Coldcard stays guessable wherever it goes, so importing it into a Trezor, a Ledger, or a brand-new Coldcard changes nothing, since the attacker isn’t searching devices, but searching the small pool of numbers the broken firmware could have picked, and that pool still contains your seed.
So the genuine fix is a completely new seed generated on the fixed firmware, followed by moving the coins across to it. The Block engineer who published the findings advised owners to plan the move with someone who knows the process, then carry it out without waiting.
The reason waiting is dangerous is that no owner can check their own exposure. The blockchain shows the attacker which addresses hold coins, but nothing shows you whether your seed falls inside the pool they can reproduce, and Galaxy Research also warned that future attacks are possible on any address a Coldcard generated.
The 4 Ways Coldcard Owners Could Have Protected Their Bitcoin

Andrey_Popov / Shutterstock.com
Not every Coldcard owner was exposed, and the ones who came through unscathed did a few things differently.
The first is mixing your own randomness into the seed. Coldcard lets owners roll a physical die during setup and enter each result, and the device blends those rolls into the seed it creates. The broken firmware still did this part properly, so an owner who entered 50 or more rolls ended up with a seed the attacker had no way to reproduce, and those wallets survived the same flaw untouched.
The second is a strong passphrase, since rolling dice is not for everyone. The CEO of custody firm, Casa, called it unrealistic to expect ordinary holders to secure their coins that way. A passphrase is an extra word the owner adds on top of the seed, and Coinkite says a strong, unique one still works as a barrier even on an affected seed. However, a weak passphrase gives weak protection, with Block warning that the attacker will reach those wallets next, and Coinkite advises moving to a new seed even with a strong one.
The third is keys from different makers. A multisig wallet needs several keys to approve a transaction, but Block said a multisig built entirely of affected devices keeps the exposure. The setup only protects when enough of its keys came from hardware the flaw never touched.
The fourth is taking the migration slowly. Coinkite’s guidance has owners record the new wallet’s fingerprint, which is the short code that identifies it, and confirm a receiving address on the device’s own screen. From there, the owner sends a small test amount to the new wallet, waits for it to arrive, and only then moves everything else across. Coinkite warns that rushing that sequence can create a more immediate risk than the issue it fixes.
How Do You Keep Bitcoin Safe if Cold Wallets Can Be Hacked?
Cold storage does two jobs at once, which are keeping your key where no hacker can reach it and creating a key no computer can guess. The Coldcard attack broke the second job while the first held perfectly, since every drained wallet stayed offline and untouched while its seed was rebuilt on someone else’s machine.
So Bitcoin safety now starts with one question, which is where your seed’s randomness came from. A seed the device made alone is only as strong as the firmware behind it, while a seed the owner helped randomize was never in the attacker’s pool at all.
For holders who don’t want that responsibility, a regulated custodian or a spot Bitcoin ETF is a fair trade, swapping the risks of self-custody for trust in someone else. Blockaid found that most crypto losses in the first half of 2026 came from compromised keys and operational mistakes, which is exactly the family this hack belongs to, and those risks follow the keys whoever holds them.
Before Your Next Withdrawal, Run One Number ( It’s Not The 4% Rule Everyone Knows)
Take your essential monthly expenses and subtract your guaranteed income — Social Security, plus any pension. What’s left is your income gap, and how you close it determines whether retirement runs on share sales or on a paycheck your portfolio writes you every month. Our free reader guide, The 4% Rule Is Broken, shows exactly how to close that gap with portfolio income: a worked example (one retiree needed about $480,000 in income-producing assets to cover his essentials for good), an eight-point conversion checklist, and the 20-year numbers comparing dividends to withdrawals. It’s free and takes about 15 minutes to read. Get the guide here before you take your next withdrawal.
Contact editorial@247wallst.com for any questions or corrections.
