What Bitcoin Did
What Bitcoin Did

EMERGENCY BITCOIN UPDATE: Coldcard Attack Explained | Rob Hamilton

July 31, 2026

AI Summary

5 min read

In early 2021, Coinkite pushed a firmware update to its Coldcard hardware wallets that introduced a catastrophic bug in how the devices generate random seed phrases. The error was a single line of code that, instead of checking whether a function returned "true" before skipping the entropy-generation step, merely checked whether the function existed — which it always did. The result: for over four years, every Coldcard MK3, MK4, MK5, and Q that was asked to "give me some seed words" produced a seed from a dramatically shrunken pool of possible values. On the MK3, the entropy collapsed to roughly 32 bits — a space trivially brute-forceable on consumer hardware. On the later models, estimates put the remaining entropy at 45 to 50 bits: more, but still far below the 128 or 256 bits users expect. By the time the bug was disclosed publicly, attackers had already begun scanning the entire table of possible seed phrases, sweeping low-hanging single-signature wallets. The starting gun had fired, and multiple well-capitalized hacking teams were now in the race.

The only protections that still hold

Continue reading the full summary in the app — free to try.

Read Full Summary →

Free • No credit card required

What you'll learn

  • 1 (00:02) **Emergency Declared: Critical Coldcard Bug** - Rob Hamilton announces a code-red security emergency affecting Coldcard MK3, MK4, MK5, and Q devices, demanding immediate action.
  • 2 (02:02) **The Bug: A Firmware Entropy Failure Since 2021** - A one-line coding error introduced in early 2021 firmware broke the secure random number generation for seed phrases.
  • 3 (03:05) **Who Is Affected (and Who Is Safe)** - Clarifying which devices and security measures are impacted.
  • 4 (05:56) **Why This Is Catastrophic: The Entropy Collapse** - Explaining the cryptographic scale of the failure.
  • 5 (10:04) **How the Bug Was Found: The Role of Open-Source AI** - The vulnerability was exposed using an uncensored large language model.
  • 6 (11:34) **The First Attackers: From Amateur to Sophisticated** - Describing the initial exploit and the escalating threat.
  • 7 (13:25) **Are Other Hardware Wallets Safe?** - Confirming the bug is isolated to Coldcard.

+ Full timestamped outline available in the app

Show Notes

“This is as code red as it can get for Bitcoin self-custody.”

Rob Hamilton joins me for an emergency episode on the catastrophic Coldcard entropy bug that has exposed Bitcoin held in wallets generated on affected firmware.

A firmware change introduced in 2021 prevented Coldcard devices from generating the level of randomness users believed they were getting. The result is that attackers may be able to reconstruct seed phrases and drain wallets, even when the device was air-gapped and the seed words never touched the internet. Rob explains which Coldcard models and setups are at risk, why updating the firmware does not repair an existing vulnerable seed, and what affected users need to do now.

We also get into the risks facing single-signature and multisig wallets, whether passphrases and independently generated entropy provide protection, how attackers are finding and sweeping vulnerable wallets, and the role AI may have played in discovering the bug.

THANKS TO OUR SPONSORS:

LEDN

SWAN

ANCHORWATCH

BLOCKWARE

BITKEY

CAPE

FOLLOW:

Danny Knowles: https://x.com/_DannyKnowles

Rob Hamilton: https://x.com/Rob1Ham

What Bitcoin Did

More from this podcast

What Bitcoin Did →