Coldcard Forces User-Supplied Entropy After Bitcoin Theft Pegged at $114M-$130M
Coinkite's Coldcard wallet ships firmware requiring manual entropy input after a bitcoin exploit reported at $114M to $130M by two outlets.

Coinkite has shipped new firmware for its Coldcard hardware wallet that forces users to supply their own randomness when generating a seed phrase, following a bitcoin theft that Decrypt reported at $130 million and CoinDesk put at $114 million. The mismatch in figures reflects how fresh the incident still is, but both outlets agree on the core event: a flaw in seed generation exposed user funds, and Coinkite has now closed it.
What the new firmware changes
Under the update, Coldcard no longer relies solely on its internal random number generator to produce a wallet’s seed phrase. Users must now add their own source of randomness, known as entropy, during setup. Entropy is the raw unpredictability that makes a seed phrase impossible to guess or reproduce; if the device alone controls that process and something goes wrong in its implementation, an attacker who understands the flaw could potentially predict or narrow down possible seeds.
Coinkite says the change followed a three-week internal review that turned up additional security issues beyond the original vulnerability. CoinDesk reported that artificial intelligence tools helped the team catch some of these extra bugs during the audit, a detail that points to how hardware wallet makers are now using AI-assisted code review alongside traditional manual checks.
Updating the firmware is not enough on its own
Both reports carry the same caution: installing the new firmware does not automatically make a previously exposed wallet safe. If a seed phrase was generated on vulnerable firmware and may have been compromised, the funds tied to that seed remain at risk regardless of whether the device itself is later patched. The fix protects future seed generation, not past exposure.
For holders who suspect their existing Coldcard seed could be affected, the practical response is to move funds to a brand-new wallet generated under the updated firmware, using the added user-supplied entropy step, rather than assume an update alone resolves the risk.
Why this matters for bitcoin self-custody
Coldcard is one of the more established air-gapped hardware wallets used by bitcoiners who prioritize keeping keys offline. A theft in the $114 million to $130 million range, whichever figure proves accurate once forensic details settle, is large enough to rattle confidence in a device category that markets itself on being harder to exploit than software wallets or exchange custody.
The episode is a reminder that self-custody security depends not just on keeping a device offline, but on the integrity of the randomness behind every seed phrase it ever generates. Coinkite has not disclosed a timeline for a full technical post-mortem of the original exploit.
Sources
Related articles
Bitcoin-Gold Ratio Hits 18.17, Highest Since January, as CZ Flags Cycle Flip
The BTC/gold ratio climbs to 18.17, its highest level since January, as debt fears lift both assets and CZ floats a market-cap…
Liquid Network’s 4,019 BTC ($320M) Drain: What Two Sources Actually Confirm
Blockstream's Liquid sidechain lost 4,019 BTC (~$320M) in a peg-out. Two outlets confirm the figure; the on-chain "message" claim is single-sourced.
Liquid Sidechain Balance Falls From 4,200 BTC to 207 BTC After $320M Drain
Blockstream's Liquid federation wallet dropped to about 207 BTC after purported white-hat hackers withdrew roughly $320M; the sidechain is now paused.