Coldcard Wallet Flaw Shows How Small Coding Errors Can Have Big Consequences

31 July 2026 - 21:45 UTC
By Jona Jaupi
DeFi hack
Sandmark

Hardware wallet maker Coinkite urged some of its Coldcard users to move their Bitcoin into newly created wallets after disclosing a software flaw that may have enabled the theft of more than $38mn, highlighting how a small coding mistake can quietly weaken an otherwise secure system.

Coldcard is a hardware wallet that stores Bitcoin private keys offline instead of an internet-connected computer or phone. When users create a new wallet, the device generates a random recovery phrase, also known as a seed phrase, which can be used to restore access to the wallet. Anyone who obtains the phrase can access the funds.

Coinkite said it became aware of the flaw on 30 Jul, more than five years after it was accidentally introduced during a software update in 2021. The issue affects wallets created on Coldcard Mk3 devices running firmware versions 4.0.1 through 4.1.9, as well as certain firmware versions on Mk4, Mk5 and Q models.

The Coldcard incident was the largest crypto security incident reported in July, according to blockchain security firm CertiK's research. It follows the roughly $24mn Ostium hack and the $1.34mn Cascade exploit, which experts said underscored a broader shift toward attacking the infrastructure that crypto projects rely on rather than only exploiting flaws in smart contracts.

Overall, CertiK recorded 74 crypto security incidents in July, with total losses of about $187.8mn. Software bugs accounted for the biggest share at $68.4mn, followed by compromised wallets ($42.4mn), price manipulation ($34.9mn), governance attacks ($20.1mn) and phishing ($19.7mn).

In the case of Coldcard, the software flaw quickly drew attention across the crypto industry after blockchain security firms said it may be linked to tens of millions in Bitcoin thefts. Security experts say it shows how a small software mistake can have major security consequences, even when the cryptography itself is not broken.

"This is a textbook example of how a single preprocessor misconfiguration can silently undermine an otherwise well-designed security architecture," Yuannan Yang, audit partner at CertiK, told Sandmark.

Small bug, big impact

Coinkite said the problem was a software mistake that caused the wallet to use the wrong source of randomness when creating new recovery phrases. Randomness is what makes each recovery phrase unique – the more random it is, the harder it is for someone else to guess.

However, Yang said that the bug was difficult to find because the correct security code was still included in the software, making it look as though everything was working properly. In reality, the wallet creation process was using different code.

Coinkite said the bug had the biggest impact on Mk3 devices. Later models used additional sources of randomness that reduced the risk, although the company said they were still affected.

New wallets are advised

Coinkite said updating the device's software is not enough and anyone who created a wallet using the affected versions should create a new recovery phrase on the updated device and move their Bitcoin to a new wallet. The only exception is for users who added at least 50 private dice rolls when creating their wallet. 

The company said those wallets are not considered at risk from this issue alone. Coinkite also released security updates on 31 Jul for its Coldcard Edge devices and advised affected users in an X post to "update first, create a new seed (phrase), then migrate."

Yang said the incident shows that companies need to test not only their cryptography, but also the software that connects everything together. "It's easy to audit the parts that look important and miss the plumbing that quietly decides which implementation actually ships," Yang added. 

Add as a preferred source on Google