Coldcard fixes seed-generation flaw after thefts tied to weak wallet entropy

Coldcard fixes seed-generation flaw after thefts tied to weak wallet entropy

Anthony Pompliano said the Coldcard losses reflect a third-party wallet failure, not a breach of Bitcoin’s protocol, as tracked sweeps from identified wallets climbed to at least 1,360 BTC.

BTC

Fact Check
The official Coinkite advisory confirms a Coldcard Mk3 seed/key-generation entropy flaw tied to firmware 4.0.1 (March 2021), and The Block and Cointelegraph confirm ~594 BTC (~$38.3M) drained from ~500 single-signature addresses within a short multi-block window (blocks 960188-960191). Block was reported to be investigating non-Bitkey wallet drains, supporting the joint attribution. The 'under 30 minutes' timing and 'rather than a broader device-wide failure' framing are consistent with Coinkite's Mk3-focused advisory and CEO denial of a wallet-wide vulnerability, though the advisory notes reduced entropy also touches other models—a minor nuance not undermining the core claim.
Summary

Coinkite patched a Coldcard seed-generation flaw that Block linked to thefts of about 594 BTC from around 500 single-signature wallets, while later public tracking showed at least 1,360 BTC, valued at about $85.76 million on a Coldcard Sweep Watch dashboard, had been swept from identified wallet clusters. Anthony Pompliano said the incident should be understood as a hardware-wallet security failure involving user funds rather than a compromise of Bitcoin’s network, consensus rules or ledger, warning that inaccurate descriptions could damage investor confidence in an already weak market. Coldcard said reduced entropy during seed creation left some recovery phrases easier to calculate than intended, with Coinkite’s hotfix notes indicating Mk3 seeds may have had roughly 40 bits of entropy and later models about 72 bits, versus a 128-bit target. Affected users have been urged to install corrected firmware, generate entirely new seeds, verify receiving addresses and migrate funds, because updating firmware alone does not secure previously created seeds.

Terms & Concepts
  • entropy: The unpredictability used to generate wallet seeds and private keys; lower entropy can make them easier to guess.
  • consensus rules: The protocol rules that nodes follow to validate blocks and transactions on Bitcoin’s network.
  • recovery phrases: Lists of words that let wallet owners restore access to their bitcoin if a device is lost or replaced.