The Coldcard seed-generation failure has exposed about $116 million in Bitcoin to theft while renewing questions about how users verify the security of self-custody tools, according to TEXITcoin founder Bobby Gray.
Bobby Gray, founder of TEXITcoin, told crypto.news that Coldcard users suffered losses because they trusted the hardware wallet to generate secure seed phrases without independently checking the source of randomness.
“Coldcard sat on a broken seed generator for five years, and it still cost people $116 million,” Gray said.
“Some of these wallets were generating seeds with as little as 40 bits of entropy instead of the 128 they promised.”
Gray said the lower entropy turned recovery phrases designed to resist brute-force attacks into targets that determined attackers could search without gaining physical access to the devices.
Coldcard seed flaw weakened wallet security
Coldcard is a Bitcoin-only hardware wallet made by Canadian hardware manufacturer Coinkite. Hardware wallets keep private keys away from internet-connected computers and sign transactions within the device, reducing exposure to malware and online attacks.
Coldcard’s reported failure occurred before the private keys entered secure storage. According to a Coinkite security advisory, a firmware integration error caused affected devices to use a predictable software random-number generator instead of the intended hardware source while creating wallet seeds.
Firmware versions 4.0.1 through 4.1.9 on Coldcard Mk2 and Mk3 devices were affected. The first vulnerable release arrived in March 2021, leaving the error active for more than five years before Coinkite disclosed it on July 30.
Coinkite estimated that seeds created on affected Mk2 and Mk3 devices contained about 40 bits of effective entropy. Vulnerable Mk4, Mk5, and Q devices generated about 72 bits rather than the expected 128 bits, according to the advisory.
A correctly generated 128-bit seed provides an extremely large set of possible combinations. Reducing the effective randomness to 40 bits leaves about one trillion possibilities, a range that specialized computing systems can search when attackers have enough information about the wallet’s seed-generation process.
TRM Labs said the attackers could reconstruct affected private keys without opening, stealing, or modifying the hardware wallets. The blockchain intelligence firm attributed the error to a build configuration introduced with firmware version 4.0.1.
On-chain estimates cited by TRM Labs placed the preliminary loss at about 1,816 $BTC, worth approximately $116 million, across more than 5,200 addresses. Four suspected waves began on July 30, though TRM warned that the total could change as investigators confirm victim reports and trace additional addresses.
Gray says self-custody itself did not fail
In an Aug. 6 analysis, Gray described the incident as a failure in the process used to create private keys rather than a compromise of Bitcoin or the physical security components inside Coldcard devices.
No attacker needed to steal a device, obtain its PIN, or install malicious firmware, according to Gray. Once attackers reconstructed a vulnerable seed, they could derive its associated private keys and sign transactions from another system.
“The people who bothered adding their own dice rolls for extra entropy walked away untouched, while the people who just trusted the device to handle it got wiped out,” Gray said.
Coinkite’s advisory supports the distinction involving independent randomness. Users who entered at least 50 fair, private, and independent dice rolls while creating their seed are not considered at risk from the random-number-generator flaw alone. Between 50 and 98 rolls added at least 128 bits of entropy, while 99 or more added about 256 bits, the company said.
Fewer than 50 rolls do not meet Coinkite’s stated exception. Users who cannot remember how many rolls they entered, whether the process was private, or which final seed words they retained were advised to migrate their funds.





