Loading summary
A
Thousands of people with cold card hardware wallets are currently being drained while not using them because of a bug in the entropy generation in the actual generation of the key. If you have a cold card hardware wallet in a single sig or a multisig, please move your funds now. Take the time you need to move your coins. I'll get into the quickest route to do so and then we'll talk about what this means and some lessons we can learn from it. Okay, so we'll talk about what it is and what the bug is and all that stuff in a minute. But that's way less important than quickly and calmly. We need to go over what to do if you have a cold card. So the problem is that the seed generated on the cold card with the firmware and the entropy in the device is weak. It is not a strong key, it is not a 256 bit key. It actually has the amount of entropy as something like an eight character password, which is not hard to brute force. And the problem is that these addresses, imbalances and signatures are available on the chain to check against. And with just a few assumptions on the basic inputs that go into the seed generation from a cold card device, the thousands of these addresses and balances are just getting wiped. People in every one of my groups that I am talking to, the Bitcoin and AI group, the Audionauts, everybody, someone is saying that they just lost all of their savings or they just lost a wallet, or they just booted up their MK3 and everything is gone. Take this seriously because this, now that it's being disclosed, other people have actually recreated it because you can take Fable 5 and Chemi 3 and Deep Seek and all these, you know, Soul 5.6 or whatever, and basically one shot, a script to go test it yourself. This is red alert. And ColdCard was a really popular and highly respected wallet. So we need to talk about what to do and how to do it carefully and how to do it quickly. Just so you know, I haven't had much sleep, but because I've been up all night doing this myself and trying to contact everybody that I can think of that might have a cold card or that I know had a cold card, I spent about an hour this morning fighting with a cold card that wouldn't get NFC connection from one of my best friends to move his funds off. Now the one that is most affected is the MK3, the key entropy, the. The regeneration is literally deterministic. It is as bad as it gets for a bug of this kind if you have an mk3, I don't care what you're doing. If you're at work, please call into work, call in sick, whatever you need to do. Go find your hardware wallet or your seed phrase. We'll go into exactly what you need and how to use it. If you, if you're missing one of these and plan to move your keys, move your funds to a different seed phrase or to a different service or to a different wallet, however it is you need to do it now. If you have a so everybody's not panicking here. If you had a big box, a bitbox, you were safe. I have a discount code. If you have a Trezor like if you're trying to get a hardware wallet, these are all highly recommended but everything deserves a little bit of scrutiny these days. Trezor, Keystone, basically everything except for cold card. This is a cold card specific implementation bug with their firmware and it has been in their firmware since I think it was 2020 when this version was introduced. I personally am spent half the night last night moving everything from my, my main cold card wallet to over to bitbox and then Keystone and I'm setting up a Keystone and a bitbox for some friends just because these are the ones that I had extras of that that I can easily, I can quickly hand out. And we do have confirmation from numerous of these hardware wallets that they are not vulnerable to this, that they're. They've detailed out their random number generation. In fact I just got Joe from bitbox, I was talking to him to get details and I've got a link. I will actually have links to all the posts just so you can read about your hardware wallet. I'll try to find as many as I can so that you can just kind of get confirmation and a little bit more detail on how or why they are safe. So don't panic. Now we'll come back around to this and focus on MK3. Right now if you have a single signature wallet created without any dice rolls or anything that you just generated the seed directly on the device, do this now. Don't take any time. You if as soon as an attacker is trying to get into your key or your address and recognizes and potentially sees it as one to attack, it could be an extremely short period of time between the attack beginning and the attack being done. If you generated your seed phrase, which this was one of the features of cold card which I liked about it was that you could add your own entropy if you generated it with dice rolls, then consider Only the dice rolls as your level of meaningful entropy. So if you did 50 dice rol, you still need to move it as soon as possible. If you did a hundred dice rolls, get it done this week. If you are protected here, then take this as a moment to refocus. Go back, check your key setup, make sure that you can get back to all your hardware wallets and your PIN numbers and that you know a little bit about how this works. Learn something from this and take the opportunity that you are forced now to at least go look at your setup and reassess. Am I safe? Did I do this right? If I had to recover everything right now, how good of a position would I be in? If you have an MK4, an MK5 or a Q, you are also not safe. It is safer than if you have an MK3, but you are still vulnerable. And do not assume that you have the time, just get it done the very first moment that you have to get it done. My friend who we sorted out first thing this morning and had an MK4, his funds are now safe. And I don't know of anyone yet who has been hit with an MK4, MK5 or a Q. But I give it a couple of days before they start rolling in. So first you need to get to your hardware wallet and whatever software wallet you had attached to that so that you could see and interact with it. You could use it to sign. If you have access to all of that, then the quickest way to get your bitcoin out. My preferred route is to create a software wallet. To create a software key somewhere, back it up normally, write down your seed phrase. If they allow any additional entropy, do it just for the hell of it. Be careful, be deliberate, don't skip your process. This is a perfect example of like, oh, it's only going to be there for a couple of days. So I'm just. I don't have to write down the seed phrase and you drop your phone in the creek. Don't do that. Still do your whole process, read the address carefully, get your cold card plugged in, sign the transaction and move it to the new keys. Now if you don't know or you don't have access to the software wallet that you use your cold card with. Best thing to do is Sparrow. In my opinion, you can also do nunchuck, but I think Sparrow will be quicker to find. If there are any funds at all attached to a single sig. That is what I actually just booted up and used for. I just plugged in all my Cold cards, every device that I had and I was just like, do I have any, do I have any coins on this still? Does this old wallet still available? And it was very, very quick. I imported the key store as they, as it says in the thing, and did a quick search of all of the key space and found the two wallets that were vulnerable. If you do not have access to your cold card or the software wallet, get access to your seed phrase. You can then also punch your seed phrase into Nunchuck or into Sparrow. Again, Sparrow will be the one that I think will be easier. Nunchuck, I believe you have to select that OS is definitely Segwit or this was definitely legacy keys or taproot, etc. Whereas Sparrow I think will just go ahead and just grab everything all at once and then tell you whether or not there are any funds there. So Sparrow is definitely the quicker go to. And so for simplicity's sake, I say stick with that one. Carefully import your seed phrase. Make sure you have the official Sparrow going to do all your normal security checks and your normal I have the right software checks. Import your seed phrase, check to make sure your transactions, your history, your balance and all is still there and then send it to a new wallet, send it to a new seed. And importantly, if you cannot make a new key or you cannot make a new software wallet key, or you do not have a different hardware wallet to send it to, if you already have an existing wallet on a different set of hardware or a different set of keys, just send it there. Just send it there. There's no reason to do anything extra. Simplicity and calm speed is the best route. Now, if you do not have that available to you, and I realize the blasphemy that this is, you can send it to an exchange. Now obviously in a normal situation that is stupid because the exchange can be hacked too. But if you're drowning underwater and there's a rock on your arm, sometimes it's not the stupid thing to do to cut your arm off to get out so that you can breathe. This is that situation. You can send it to an exchange and then you have the time to deal with it. I would recommend somebody like Robot River. Keep it simple. Your software wallet should be Sparrow. If you are trying to get your keys out or you're trying to get stuff off of your cold card and you don't know which one to use, Sparrow will quickly search through and find all of the wallets related to those keys. Then you can easily sweep them into whatever place that you're trying to send them river is a very serious exchange that takes custody very seriously. And they build everything in house. They are the safest place in my opinion, because they're the only ones that I would do this with. Again, I'm. I'm telling you what I would do. What. I take that back. I am telling you what I am doing and what exactly my backup plan would be if I did not have available the things that I just did. I would send it to river and keep the coins on river until I had a new hardware wallet set up or a new multisig set up. Going forward, I'm never going to have anything other than multisig. I will always have multisig. It's not that hard. It is not. A bunch of people say it's added complexity and now you have to keep up with a wallet file. It's. It is really not that big a deal if you understand how to think about the different pieces. And for anybody who was in multisig, if you have a multisig with cold cards in it, consider that key compromised. Now, there's an interesting thing about Segwit multisig is you can't. If you haven't been spent from it, then the keys themselves are not actually vulnerable yet, so to speak, because it can't be identified on the chain. But the moment you spend from that multisig, the entire script has to be revealed, so the various keys and their relationships to it become visible and it becomes much easier to determine and, or potentially use this attack on multisig as well. Again, I do not know of a multisig situation that has yet been compromised in this way. But. But I do know people who have two Mk3s or an Mk3 and an Mk4 in a multisig setup, and that should be treated as compromised, and it should be treated no differently than if you had an mk, a mark 3 or a mark 4. In single sig that is exposed, you have the slight benefit of obscurity. And in the fact that you are one level more difficult than a whole lot of keys that are exposed right now. If you cannot access your cold card, if you cannot access your software wallet, and you cannot access your seed phrase, pray, or see if you have a trusted friend or family member who can access those things. If you have a Mark 3 single Sig, and you cannot access any of these things, go for a trusted friend. Time is your enemy here. If you have a Mark 4 or Mark 5 or Q& you cannot get to any of it, Consider all possible routes to do it. You might be okay. But again, time is your enemy. And whatever you can do, or whoever you can trust to get it out of harm's way, I suggest taking that chance. Trusting a loved one, or trusting even a friend might be the lesser of two evils. When someone can just generate your keys in a matter of minutes, the moment they realize your balance on the chain might be accessible. Now, if you have Sparrow Wallet and you don't have a node or a service to connect to, it can be kind of confusing at the end of the process when you're trying to send the transaction is that it just produces a transaction like the whole, like raw transaction data. It's not that hard to deal with. You can actually just copy that entire text. In fact, that's what I did the first time because I forgot my node. I had cut off my node recently and that was the one that was connected to. So you can copy that entire transaction data just in that, that text box at the bottom. Copy it, go to mempool, dot space, slash, TX, slash, push, and you can just send it out. That way they'll just quote, unquote, be your node. And all you need to do is get it to the chain as quick as possible. Pay a significant fee. Do not be stingy on the fee. People are actually getting sniped while doing this because you can watch the transactions coming in and then generate the keys and then try to get it taken over to the scammer's address. So Sparrow Wallet with either your seed phrase or your cold card. If you don't have your normal setup river if you need a trusted custodian, nunchuck. If you already have other setups and you want a good and simple multisig, it's really easy to use. This is what I was able to do with my friend and he's not a technical person and he did. I was able to do it over the phone. And if you need to publish raw transaction data from somewhere because of a messed up wallet or a signing, and then you know you've just got a PSBT in your little SD card, you can always just go to mempool space, tx slash, push and just send it out from there. MK3 get it out now. MK4 MK5Q get it out as quickly as you can. Multisig with any of the above. Get it out as quickly as you can. You seem safe, but you have a cold card in your mix. There's no reason to not just be safe. Be careful while you do this, this is the time in which most people get hit with oh, downloading the Imposter Sparrow wallet or downloading the imposter Nunchuck wallet or punching their seed into an email from Coin kite, these sorts of things. These are the moments where we lapse on exactly our process and how careful we can be. Now aside from the fact that you do need to act on this quickly, be smooth, be slow and steady focus, don't panic. Just go through the process and move things as quickly and as deliberately as possible. Then buy yourself some time to figure out how to get your setup better. On a personal note, I recommended cold card to a lot of people. I used cold card in everything that I do. I, I, I know what it feels like to lose a huge stash and I would wish that on anybody. I wouldn't wish it on NVK right now. And I'm hoping that everybody gets their stuff out of the way. Sometimes I kind of feel helpless and I feel like I can't do much of anything. This one hurts, this one really hurts. I know a lot of people are going to get hit and I do my, I do my best to try to recommend the right things, you know. And it's funny that there are so many things about the cold card that I loved and still loved. Even breaking it out in my panic to my calm panic to move all my stuff last night I was like, I've just, I've always, I loved this wallet. I mean I got my cool little things for it. You know. I always liked to use this thing. I always loved the like the number of edge case security things like the brick me pin and the, the like shoot me on this chip and to have, it's like one of those things that like you know, if you half ass two things you should just whole ass one thing to miss the most fundamental piece while having you know, 30 more like random little side case security things like. That's why I always considered this like the cypherpunk thing and it's why I didn't recommend it to every single person. If you came to me personally, I would only recommend it to hardcore people because you kind of have to know what you're doing a lot with this. Which makes it even worse because the people who I feel like were most prepared and most knowledgeable about this were potentially the ones that got hit the worst. And a lesson to learn from this is just that like don't assume, you know, like, like I did, I even did like deep dives on this. Like I, I Went at it before I even signed up with a sponsorship with them to try to assess it the best I could. But that's kind of the thing about the age of AI is that like I couldn't assess the code. You know, I couldn't. But now we can. We don't have any excuse not to be red teaming everything that we're using. And this, it might seem crazy, but this is actually a good thing from the broad perspective. You know, security lives in the world of anti fragility. So the, the silver lining, if there is one from this is that there will probably be more scrutiny on hardware wallets. There will probably be more scrutiny on anybody who is not building on open source, that, that there should, that we should be the ones to find the bugs before the hackers and the scammers do. And now everyone has the tools to do it. We have no excuse not to at least just stick it into Fable 5 before I use the hardware wallet, give it all the code, give it all the documentation and say, well, I guess not Fable 5 because they're going to say it was like, oh, this is cybersecurity, we can't do anything about this. You're going to have to stay vulnerable. Do Kimi three I guess and, and tell it to, to, to go hard to spend, you know, hell, as much as you spend on the hardware wallet and tokens trying to break into the thing because AI makes this super easy to recreate. Like, like if you just understand how it works, AI will execute it for you. Another thing I think we should learn from this is that mentality matters. Coinkite as much as I love, I tend to appreciate stubbornness in people. There has been a mentality of defensiveness and dismissal of some other bugs in the past. And in hindsight it's really hard to say that that couldn't, that might not have something to do with it. Humility is absolutely critical in this because nobody's perfect. This actually could have happened to anyone. And if we are not humble and accept that maybe my hardware wallet, maybe the bitbox, maybe the Trezor, maybe the Keystone, maybe the BIT key, everything could be vulnerable. And to not do our due diligence, to not be serious about the fact that it's open source and, and that I can actually check it now that I have a model that might actually be able to be meaningful in this battle, we need a little humility to recognize that nothing is perfect. This is the worst hardware device hack in Bitcoin history and this is a little bit different than most hacks because you know, back in Mount Gog's days and you know, the mixer, what was the mixer that got hit that was really popular and you know, people got confiscated on. God, I don't even know. There's so many, so many different things. They've always. Almost every one of them have been that were serious were either you have to have the hardware in person, you have to have access to some critical piece of information, or it is a centralized exchange and they were handling their keys poorly and someone hacked into them. This is the first time that I remember of people doing self custody the right way. Good practices using a trusted hardware wallet got hit en masse in a distributed. Nobody needs their keys. Excuse me, Nobody needs their hardware wallets. Nobody needs their email addresses. Nobody needs to phish them. Nothing. I am regenerating your key from scratch because the mechanism that generated it was so weak that I can do it in a matter of minutes. That is the worst. This is the worst of this kind that I believe in Bitcoin's history. And this is probably going to be a big hit. You know, this is how bitcoin does. You know, it kicks you when you're down. You know, there's so many times in the middle of a bear market there's some like extra terrible news to just stack on top of it. You know, when it rains, it pours. It's not, it's not totally unheard of. Bitcoin will survive. You know, this wasn't a bitcoin problem. This was a fallible humans problem. This was a hardware and software problem. This was a what we build is never perfect problem. And for better or for worse, this is kind of a dry run for what the quantum disaster would look like, which I also am not really concerned about. I'm not even sure if it's anything other than a theoretical issue, but it should provide a little bit of humility to. We sure as better have a plan. You know, we shouldn't dismiss it outright. We don't know everything and things are changing really, really fast. So I am so sorry to anyone who got a cold and did a single sig setup at my recommendation. It's not anything you can say to make it better. I'm so glad to hear that a lot of you managed to get coins out. But please, just be quick, be diligent, be careful. Your funds are at risk. Your funds are at risk. And do what you need to do to protect it. I am. Please reach out if you need help. I'm gonna try to take as much. I'm so busy for the next couple of days. We're preparing a big trip, which is the worst time to have to devote a lot of time to this. But I'm trying to just be available in dm. I've been trying to answer questions of people who are trying to figure out how to get stuff safe. So please feel free to reach out. I will try to answer as many questions as I can. I'm sorry if I can't get to you, but, you know, best we can do. I guess the best thing we can do is just move things. You know, I think this probably the end of cold card, if I'm honest, is something that's really, really, really hard to come back from. And I'm sure their firmware fixed it, their firmware update. But, you know, this is about trust. Like, the device is about trust. And you know, this is all about the Lindy effect. Like, that's just really hard to guy. I feel for them too. Even with, you know, belligerence and dismissal in the past and like, of all the people that got hit by this, it's not easy to build stuff, man. It's not easy to. To catch all of this. And it's so easy to get complacent. I feel like we all got complacent. I got complacent. We go through these kind of like cycles of like, oh, everything's fine and then something comes and just kicks you in the nuts and that's where we are. So. If you don't have a cold card, take the opportunity, go through your setup, check your keys again. Check your multisig. Oh, on the note of multisig, multisig is not that hard. Do. Do nunchuck. It's real easy to do. I've set it up with a bunch of different family members. People say, oh, well, you could lose your. Your wallet details, right? You're like, wallet file. Just email it to yourself. You know, like, do it. Use ProtonMail or whatever. Just use an encrypted email, store it in a couple of different places. There's no reason not to have a bunch of different backups of that. That is a privacy concern. But it's not a. Somebody's going to get your coins concerned if you have to trade off between, oh, I lost my coins and oh, somebody saw which coins I had. Go for the latter. Let. Let the latter be an okay trade off. So just keep your wallet file in as many places as possible. You can just import that into nunchuck, into any nunchuck on desktop or your phone. You can split it up into two software keys. Do a two of three. Just make sure you don't. You're not stuck on any one vendor or any one tool or any one seed generated for any one thing. And everybody who had, probably no one who is in multisig is going to get hit with this if, even if they have their cold card, if they move it quickly. So that is a lesson to learn from this as well. So I should maybe do an episode or a setup or video or something on how to do multisig. But BTC sessions is the gold standard for going to get that information. And you know, we don't, we don't need another person doing all the tutorials. But for everybody out there, I'm sorry, I know. I know what this is like. I've had to deal with it with myself and one of my best friends. It's been a long time. But you don't forget it. So good luck. Stay humble, stack sats, generate your own damn entropy, and I'll catch you on the next episode. Thanks, guys.
Host: Guy Swann
Date: July 31, 2026
In this urgent episode, Guy Swann addresses a catastrophic security flaw in Coldcard hardware wallets that threatens thousands of Bitcoin holders. The episode is a wake-up call for Coldcard users to immediately move their funds due to a newly discovered entropy bug exposing weak key generation. Guy outlines emergency steps for affected users, details the specifics of the vulnerability, discusses broader lessons about hardware security, and reflects on the implications for Bitcoin self-custody.
Guy’s recommended moving checklist:
Guy’s tone is urgent but calm, mixing technical details with heartfelt personal concern for listeners and the broader community. He’s candid about his own mistakes, takes responsibility for past recommendations, and offers practical, empathetic advice for everyone affected.
--
Summary in a Sentence:
If you have ever generated a Bitcoin key on a Coldcard since 2020, act immediately. Move your funds. The bug is catastrophic, but careful, fast action can save your coins. Use this harsh lesson to renew your security hygiene—and stay humble.