Coldcard is a physical hardware wallet made by Coinkite. It’s a small electronic device that creates and stores Bitcoin private keys while staying offline. The device runs its own software, called firmware.
That firmware is what generates the recovery seed phrase — the list of words that can restore your wallet.
Inside every Coldcard sits a hardware random number generator. This part is meant to produce truly unpredictable numbers. Under normal design, the firmware is supposed to use this hardware component when creating a new seed phrase. That strong randomness is what makes the seed secure.
What Went Wrong
Around March 2021, some versions of the Coldcard firmware stopped following that design. Instead of asking the hardware random number generator for strong randomness, those versions created the seed phrase using a weaker software method. The seeds ended up far less random than they should have been.
Attackers later worked out the private keys offline and moved about 1,082 Bitcoin (roughly $70 million) from more than 1,100 addresses.
This was not the user’s fault. People simply followed the normal setup steps on the screen. The problem came from those older firmware versions.
Why Updating Firmware Does Not Fix Existing Seeds
Installing newer firmware only protects wallets created after the update. It cannot change a seed phrase that was already made under the vulnerable firmware.
You do not need to throw the device away. Keep the same Coldcard. Install the corrected firmware on it, then generate a completely new seed phrase on that same device. Generating a new seed creates a brand new wallet. Move the Bitcoin from the old wallet to addresses that belong to the new one. After that, never use the old seed phrase again.
What Bitcoin Holders Should Do Now
Check when you first set up your Coldcard. If it was several years ago, look into whether the firmware version you used was among those affected.
Keep the firmware updated going forward.
If you hold a large amount of Bitcoin, consider using more than one type of wallet or more than one manufacturer. That way a single software flaw cannot hit everything at once.
Test your recovery process. Make sure the written seed phrase can actually restore the wallet before you ever need it in an emergency.
Keeping a wallet offline blocks many remote attacks, but it cannot protect a seed that was weakly generated from the start.
The Main Lesson
Self custody is a process. Buying a hardware wallet is only the first step. Real security depends on how the seed was created, how the backups are stored, and whether you review the setup over time.
**If Your Seed May Be Affected or Funds Have Already Moved**
Contact Bitcoin Recovery Co. today. Tell us when you set up the wallet and what has happened. We will review your situation, explain the realistic options for moving funds safely if needed, and assess possible recovery paths if Bitcoin has already left the wallet. The conversation stays private. We do not charge any fee upfront.
Reach out now. The sooner we look at the details, the more options usually remain available.