Close Menu
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
What's Hot

This $163M crypto stash collapsed to just $15M, forcing ZeroStack to literally stake its survival on token rewards

August 3, 2026

Coldcard Exploit Sparks Bitcoin Flight, ‘Bullish’ Crypto Consolidation: Hodler’s Digest,

August 2, 2026

A tiny cluster of Solana bots unlocked a 3x trading advantage by routing through one proprietary protocol

August 2, 2026
Facebook X (Twitter) Instagram
Monday, August 3 2026
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
Facebook X (Twitter) Instagram
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
StreamLineCrypto.comStreamLineCrypto.com

Coldcard users face urgent seed migration warning

August 2, 2026Updated:August 3, 2026No Comments7 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Coldcard users face urgent seed migration warning
Share
Facebook Twitter LinkedIn Pinterest Email
ad

Dogecoin neighborhood contributor Mishaboar urged Coldcard customers on Aug. 1 to maneuver their Bitcoin to wallets managed by newly generated seed phrases. 

Abstract

  • 1,367.05 BTC price $88.6 million was drained from 4,585 addresses throughout three suspected assault waves.
  • Coinkite says firmware updates defend new seeds however can’t restore seed phrases from susceptible variations.
  • Mishaboar suggested customers by no means to reuse affected seeds or enter restoration phrases into computer systems on-line.

The warning adopted Galaxy Analysis’s estimate that three suspected assault waves drained 1,367.05 BTC, price about $88.6 million, from 4,585 addresses.

Mishaboar wrote, “When you’ve got ever used a COLDCARD machine of any form, migrate your funds to a brand new pockets instantly.” He additionally warned customers to not reuse their current Coldcard seed phrase or enter restoration phrases into an internet-connected pc. Nevertheless, his reference to each Coldcard machine is broader than Coinkite’s official safety advisory, which identifies particular firmware variations and several other exceptions.

When you’ve got ever used a COLDCARD machine of any form, migrate your funds to a brand new pockets instantly.

IMPORTANT: DO NOT reuse the COLDCARD seed phrase ever once more – create a brand new one on the brand new pockets, and as I’ve been recommending for some time set additionally the twenty fifth/thirteenth password. https://t.co/NRnlV2eXkQ

— Mishaboar (@mishaboar) August 1, 2026

Coldcard losses rise as attackers goal smaller wallets

Galaxy Analysis’s newest on-chain estimate recognized 1,367.05 BTC throughout three suspected assault waves. The analysis agency described $88.6 million as its “estimated noticed dimension,” that means the overall has not been confirmed by Coinkite, regulation enforcement or each affected person.

The primary wave eliminated 1,082.65 BTC from 1,196 addresses in about 41 minutes on July 30. A later third wave drained roughly 208 BTC from 1,912 addresses, with the common stability falling to barely greater than 0.1 BTC per handle. The altering sample suggests attackers moved from bigger holdings towards smaller wallets.

Galaxy mentioned every wave appeared internally in keeping with one operator. Nevertheless, it couldn’t decide whether or not one attacker managed all three waves. The third group used separate vacation spot addresses, batched a number of victims into particular person transactions and checked solely the default derivation path, making it completely different from the sooner sweeps.

The analysis agency additionally warned that its recognized transaction patterns can’t determine each theft. A unique attacker may generate legitimate transactions with out repeating the charges, vacation spot codecs or assortment strategies seen within the first three waves.

Official Coldcard warning covers particular firmware

Coinkite mentioned the issue impacts seeds generated on Mk2 and Mk3 units working firmware variations 4.0.1 by means of 4.1.9. Seeds created on Mk4 and Mk5 units earlier than normal model 5.6.0 or Edge model 6.6.0X are additionally lined. For Coldcard Q, the mounted releases are normal model 1.5.0Q and Edge model 6.6.0QX.

Coldcard Mk1 units are outdoors the firmware regression recognized by Block’s researchers. Coinkite additionally mentioned TAPSIGNER, OPENDIME and SATSCARD are unaffected as a result of they use completely different codebases. Due to this fact, the accessible technical proof doesn’t set up that each product ever made by Coinkite is susceptible.

Block’s Bitcoin engineering and safety crew traced the flaw to a firmware integration error. The affected software program used a deterministic MicroPython fallback as a substitute of the meant STM32 {hardware} random-number generator when creating pockets secrets and techniques. On Mk2 and Mk3 v4 firmware, the affected path added no cryptographic entropy. Later fashions obtained a restricted secure-element reseed.

Block cautioned that its evaluation represented its present technical view and didn’t embrace full empirical testing of each machine. Coinkite has additionally mentioned its investigation stays open and promised a proper technical report.

Firmware updates can’t restore current seeds

Coinkite has launched mounted firmware for each affected mannequin and launch observe. The patches right the seed-generation course of for brand spanking new wallets, however they can’t add randomness to a seed phrase created earlier. Shifting the identical susceptible phrase into one other {hardware} or software program pockets additionally carries the weak point into the brand new machine.

Affected customers ought to set up the proper mounted firmware earlier than producing a substitute seed. Coinkite advises recording and verifying the brand new backup, checking a receiving handle on the machine display screen and sending a small check transaction. Customers ought to transfer the remaining stability solely after confirming that the check funds reached the brand new pockets.

The corporate advises customers to maintain the outdated backup till your entire migration is confirmed. Mishaboar individually warned customers by no means to kind a seed phrase into a pc and beneficial protecting offline copies in separate safe places. That recommendation can scale back publicity to phishing, malware and cloud synchronization throughout a rushed migration.

Coinkite recognized a restricted exception for customers who added a minimum of 50 truthful, unbiased and personal cube rolls earlier than the ultimate seed phrases have been produced. The corporate mentioned these rolls contributed a minimum of 128 bits of unbiased entropy. Customers who entered fewer than 50 rolls, can’t keep in mind the quantity or uncovered the roll sequence ought to migrate.

A powerful, distinctive BIP-39 passphrase creates an extra barrier, however Coinkite mentioned it doesn’t restore an affected seed. Quick, reused or predictable passphrases could also be guessable. Even customers with robust passphrases are suggested to switch the underlying seed as quickly as sensible.

Coldcard incident renews the self-custody debate

Bitcoin investor Anthony Pompliano mentioned the losses confirmed how technically demanding self-custody could be, despite the fact that people retain the best to manage their property immediately. He additionally confused that Bitcoin itself was not hacked as a result of the failure occurred in third-party pockets firmware relatively than the Bitcoin protocol.

A number of ideas on the Coldcard safety incident (in no explicit order):

1. That is devastating for lots of people. They misplaced their hard-earned financial worth in a approach most didn’t understand was doable. Not everyone seems to be a technical genius, however nearly all are merely trying to…

— Anthony Pompliano (@APompliano) August 2, 2026

That distinction issues as a result of an attacker reportedly reproduced weak pockets keys offline. The incident didn’t require altering Bitcoin transactions, breaking its cryptography or compromising the community’s consensus guidelines. As soon as an attacker obtains a sound personal key, the ensuing transaction seems on-chain like one licensed by the reputable proprietor.

As beforehand reported, the noticed loss estimate rose from an early 594.48 BTC calculation to 1,367.05 BTC as researchers discovered further handle teams. In associated protection, crypto.information examined how the firmware construct error weakened seed era for greater than 5 years.

The case has additionally entered the U.S. institutional-custody debate.As crypto.information reported, Bloomberg ETF analyst Eric Balchunas argued that the losses strengthen the case for spot Bitcoin ETFs amongst buyers in search of worth publicity with out managing personal keys. ETFs take away private seed-management duties, though they change these dangers with institutional custody and counterparty publicity.

Coinkite’s promised technical assessment and additional Galaxy handle evaluation are the subsequent anticipated updates. Till then, $88.6 million stays the most recent public on-chain estimate relatively than a remaining confirmed loss. Customers lined by the official advisory face the extra quick process of putting in mounted firmware and shifting funds to a very new seed.

ad
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Related Posts

This $163M crypto stash collapsed to just $15M, forcing ZeroStack to literally stake its survival on token rewards

August 3, 2026

Coldcard Exploit Sparks Bitcoin Flight, ‘Bullish’ Crypto Consolidation: Hodler’s Digest,

August 2, 2026

A tiny cluster of Solana bots unlocked a 3x trading advantage by routing through one proprietary protocol

August 2, 2026

Another crypto wallet pulls the plug tomorrow with no exact cutoff, leaving users racing to rescue tokens

August 2, 2026
Add A Comment
Leave A Reply Cancel Reply

ad
What's New Here!
This $163M crypto stash collapsed to just $15M, forcing ZeroStack to literally stake its survival on token rewards
August 3, 2026
Coldcard Exploit Sparks Bitcoin Flight, ‘Bullish’ Crypto Consolidation: Hodler’s Digest,
August 2, 2026
A tiny cluster of Solana bots unlocked a 3x trading advantage by routing through one proprietary protocol
August 2, 2026
CLARITY Act vanishes from Monday’s Senate schedule, triggering 72-hour countdown to save it before recess
August 2, 2026
Another crypto wallet pulls the plug tomorrow with no exact cutoff, leaving users racing to rescue tokens
August 2, 2026
Facebook X (Twitter) Instagram Pinterest
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
© 2026 StreamlineCrypto.com - All Rights Reserved!

Type above and press Enter to search. Press Esc to cancel.