Coldcard with the message Danger

Coldcard Security Vulnerability: Self-Custody Remains Secure – With the Right Setup

A critical security vulnerability has weakened the seed generation process in older Coldcard firmware. In connection with this incident, more than 1,000 Bitcoin have been moved from numerous wallets. It has not yet been definitively determined which transactions are linked to the attack.

The most important takeaway: Self-custody was not the problem. The error lay in the software of a specific hardware wallet. It generated seeds with insufficient randomness.

What happened in the Coldcard incident?

When a Bitcoin wallet is set up, it creates a seed. The wallet's private keys are derived from this seed. Therefore, the seed must be based on sufficiently random data.

According to the manufacturer, Coinkite, this is exactly where the error occurred. Certain Coldcard versions did not use the device's intended random number generator during seed creation. Instead, a weaker software-based random number generator was used.

As a result, there were significantly fewer possible seeds than expected. Attackers were able to test potential seeds in an automated fashion. From these, they derived Bitcoin addresses and then compared them against public blockchain data.

With a securely generated seed, such an attack would be practically impossible.

Coinkite assesses the security of the affected seeds as follows:

  • Coldcard Mk2 and Mk3: approximately 40 bits of security
  • Coldcard Mk4, Mk5, and Q: approximately 72 bits of security due to additional random data from security chips

The intended level was 128 bits. These figures show that even the newer models did not reach the planned level of security.

At the end of July, approximately 594 Bitcoin were initially moved from about 500 wallets. Later analyses reported a total of around 1,082.65 Bitcoin from 1,196 addresses. Coinkite has confirmed the vulnerability. However, a detailed investigation into the attack is still ongoing.

Which Coldcard models are affected?

According to the security advisory from Coinkite updated on August 1, 2026, seeds created with the following devices and firmware versions are affected:

  • Coldcard Mk2 and Mk3: Firmware 4.0.1 to 4.1.9
  • Coldcard Mk4 and Mk5, standard version: before firmware 5.6.0
  • Coldcard Q, standard version: before firmware 1.5.0Q
  • Coldcard Mk4 and Mk5, Edge version: before firmware 6.6.0X
  • Coldcard Q, Edge version: before firmware 6.6.0QX

The firmware version used when the seed was created is the deciding factor. Updating the firmware later does not make an existing seed more secure; it only protects seeds generated after the update.

Coinkite notes one possible exception: users who added at least 50 fair, secret, and independent dice rolls during creation. A strong additional password for the wallet can also make attacks more difficult. This additional password is known as a BIP39 passphrase.

However, neither of these changes the recommendation: affected users should create a new seed and transfer their Bitcoin.

Why self-custody was not the problem

With self-custody, users control their own private keys, making them less dependent on a custodian. However, this does not automatically protect against flaws in a wallet.

In the Coldcard incident, the error lay in the seed generation process. The principle of self-custody remained unchanged; it was a specific technical implementation that was affected.

Self-custody is not an automatic guarantee of security

"Not your keys, not your coins" describes a key advantage of Bitcoin: those who hold the keys control the Bitcoin.

But this advantage does not protect against every risk. Errors can occur even with self-custody. Examples include:

  • insecure seed generation,
  • tampered or outdated firmware,
  • an unprotected backup,
  • an incorrectly verified receiving address,
  • phishing or user error.

Self-custody remains a robust model. However, it requires a clear security process. A well-known device or brand alone is not enough.

What affected Coldcard users should do now

Anyone who created a seed with affected firmware should check the warning from Coinkite. It is important to transition to a new wallet in a calm and controlled manner.

Coinkite essentially recommends these steps:

  1. Check if you are affected: Determine the model and firmware used during the initial seed generation.
  2. Update firmware: Only use the official Coinkite download page.
  3. Create a new seed: Do not re-import the old seed.
  4. Check backup: Store the new seed phrase securely and offline.
  5. Verify receiving address: Check the address directly on the device.
  6. Send a test transaction: Transfer a small amount first.
  7. Remaining balance transfer: Only send the remaining Bitcoin after a successful verification.

A firmware update alone is not enough. Resetting the device with the same seed will not solve the problem either.

Never share your seed phrase on a website, in a chat, or with anyone claiming to be support. If you are unsure about the migration process, do not take any impulsive steps.

What does this incident mean for 21bitcoin users?

The vulnerability affects specific Coldcard versions. It does not affect the Bitcoin network or the 21bitcoin app.

Action is only required if you are using an affected Coldcard wallet. This also applies if you are sending Bitcoin from 21bitcoin to such a wallet.

Before your next transfer, check when and with which firmware your seed was created. Only set up a new receiving address after a secure migration.

Combining self-custody and professional custody

With 21bitcoin, purchased Bitcoin can initially remain in your account. Users can also send them to their own wallet.

The Auto-Wallet-Transfer automatically transfers Bitcoin to an external wallet. Users set a personal threshold for this.

Transfers can be paused during a security migration. If you are still learning about self-custody, you can start by transferring small amounts to test the process.

Bitcoin in your 21bitcoin account is held using the cold storage infrastructure of BitGo Custody.

Both models have their own risks:

  • Self-custody reduces dependence on a custodian. However, users must protect their wallet, seed, and backup themselves.
  • Professional custody reduces the technical burden. In return, users must trust the provider and its infrastructure.

There is no single right solution for every user. What matters is which risks they understand and can safely manage.

Five lessons from the Coldcard incident

The incident highlights what users should look for in hardware wallets:

  1. Even well-known devices can contain flaws. Brand and model are no substitute for a security process.
  2. Firmware matters. Updates should always come from official sources.
  3. A weak seed remains weak. A later update will not fix it.
  4. Additional sources of entropy can help. But they must be used correctly.
  5. Transfers require testing. Test the new wallet first, then send the full amount.

Self-custody does not require expert knowledge. However, users should understand how their wallet, seed, and backup work together.

Frequently asked questions about the Coldcard security vulnerability

Was Bitcoin itself hacked?

No. The flaw was in the firmware of specific Coldcard models. The Bitcoin network and its cryptography were not compromised.

Is a firmware update enough?

No, if the seed was already created with an affected firmware version. In that case, users need a new seed. They must then transfer their Bitcoin to the new wallet.

Are all Coldcard wallets affected?

No. The decisive factors are the model and the firmware used during seed generation. The standard or edge version used also plays a role.

Does a BIP39 passphrase provide protection?

A strong BIP39 passphrase can make attacks more difficult. It acts as an additional password for the wallet. However, it does not retroactively make a weak seed secure.

Is self-custody still secure?

Yes, provided users implement it carefully. Self-custody protects against the risks associated with a custodian. However, it does not automatically protect against insecure software, poor backups, or user error.

Do 21bitcoin users need to take action?

Only if they are using a potentially affected Coldcard. In that case, they should check the original firmware. Further transfers should only be made after a secure migration.

Conclusion: Control requires a secure setup

The Coldcard incident was not a failure of self-custody. A specific piece of wallet software generated seeds with insufficient randomness, making it easier for attackers to test potential keys.

The right response is neither blind trust nor abandoning self-custody. Users should keep their firmware up to date, protect their backups, and test larger transfers first.

At 21bitcoin, users can decide for themselves: they can have their Bitcoin professionally custodied or send it to their own wallet. The important thing is to understand the chosen solution and secure it carefully.

Note: Past performance is not an indicator of future results. Marketing communication, FIOR Digital GmbH

Teile diesen Artikel
No items found.