Coldcard Seed Bug Drains Wallets, 1,000 BTC Moved On-Chain

iconNS3
Share
AI summary iconSummary
on-chain news reports that Coldcard MK3, MK4, MK5, and Q wallets are being drained due to a seed-generation flaw. Wallets created after 2020 with fewer than 50 dice rolls are vulnerable to brute-force attacks. About 1,000 BTC has been moved on-chain in connection with the issue. Coinkite has released a firmware patch. BTC update shows the ongoing impact of the vulnerability.

Key Point

Coldcard MK3, MK4, MK5 and Q wallets are being drained after a bug allowed attackers to find seed phrases without user action. Wallets generated after the end of 2020 without at least 50 dice rolls did not have enough randomness and can be brute forced. About 1,000 BTC has been seen moving on-chain in activity connected to the vulnerability. The issue also affects ephemeral keys, session keys for Clone Coldcard or Key Teleport, and BIP 85 seeds generated from a compromised seed. Coinkite has released a firmware patch, and word seeds generated after this firmware update should be secure.

Why it matters: A custody flaw may force users to rotate keys quickly because seed exposure can convert a device issue into direct asset loss.

Market Sentiment

Bearish, Stress-on, Event-driven, De-risking.

Reason: Coldcard wallets are being drained after a seed-generation bug, which makes the market read this as an urgent self-custody risk.

Similar Past Cases

In 2023, Trust Wallet fixed a browser-extension wallet-generation vulnerability that led to $170,000 in user losses, and Trust Wallet said only users who created addresses in the affected browser-extension window were affected. (The Block) The difference is that the current issue centers on Coldcard seed generation and reported active BTC movement, so remediation depends on seed rotation rather than only extension updates.

Ripple Effect

Custody risk can spread through user migration, hardware wallet trust, and exchange deposit behavior rather than through protocol liquidity. If more vulnerable seeds are swept before users migrate, then confidence in self-custody tooling could weaken. If firmware adoption and seed rotation reduce new drains, then the impact may stay contained to affected Coldcard users.

Opportunities & Risks

Opportunities: If Coinkite firmware patch adoption and new seed generation stop connected on-chain drains, then affected users can treat verified migration as a potential security-stabilization signal.

Risks: If more on-chain movements connected to the vulnerability appear before users migrate funds, then reducing exposure from vulnerable seeds limits direct custody loss.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.