Updated September 8, 2026. The appropriate action depends on the model, firmware and when the seed was generated.
Coldcard hacked is a search that needs an operational answer: updating the device does not make an existing vulnerable seed safe. The official Coldcard security status tells affected users to migrate to a new seed generated on a recommended release with an additional source of user entropy.
Deleting an app, changing the PIN or installing only the latest firmware does not resolve the original risk. If a seed was predictable, an attacker may reconstruct its keys and sign transactions without possessing the physical wallet. Moving funds away from the old secret is the priority.
Coldcard hacked: who should review their setup
The official guidance includes Mk4, Mk5 and Q in its review path and does not automatically exclude newer hardware. For Mk2 and Mk3 it identifies the final available release and suggests considering current hardware for long-term storage. The critical fact remains how and when the seed was created.
A seed generated by affected firmware should be treated as potentially exposed even if the device has never been online. Hardware normally isolates signing keys, but it cannot retroactively improve weak randomness used when those keys were first derived.
Seeds imported from a separate source need a different assessment. Vaguely remembering the use of dice is not enough: the vendor distinguishes the standard flow, the advanced Dice Rolls Only path and exact conditions. Users should reconstruct the actual procedure and version before deciding that an exception applies.
Why a firmware update is not sufficient
An update corrects future device behaviour. It cannot change words already recorded or every key derived from them. The difference is similar to repairing a faulty password generator versus replacing the passwords it produced before the repair.
Our guide to seed phrases and wallet custody explains how the wallet’s keys derive from the secret. Installing a corrected release may be part of a safe process, but the bitcoin ultimately needs to reach addresses produced by a new, independent and trustworthy seed.
A cautious Bitcoin migration sequence
Start with a clean environment and a recommended firmware release, verifying its signature and hash using the manufacturer’s instructions. Then create a new seed through the updated process. Coldcard’s current standard flow requires one user contribution through unpredictable key presses, dice rolls or coin flips.
Record and verify the backup offline. Before moving a material balance, confirm the new wallet fingerprint, receiving address and recovery procedure. A test transaction can reduce operational risk, although splitting the transfer leaves the old balance exposed longer; timing and amounts deserve a deliberate choice.
After the test, move the remaining balance to addresses belonging to the new wallet. Importing the old seed into updated or replacement hardware is not migration. The secret and its derived addresses would remain the same.
What a passphrase and new device actually solve
A BIP-39 passphrase creates a separate wallet and can add an important barrier when it is strong and has never been exposed. Coldcard recommends one for funds whose loss would be materially harmful. It needs a separate backup, a recorded wallet fingerprint and a tested recovery procedure.
Adding one to an old setup without understanding the result can create new problems. A weak or reused passphrase may be guessed, while losing a strong passphrase makes the wallet unrecoverable. Our guide to when a hardware wallet actually makes sense treats custody as a complete system rather than one device.
Buying different hardware does not repair an imported vulnerable seed. Security comes from a newly generated secret, verified software and a controlled transfer, not merely from replacing the enclosure around the same keys.
What investigations say about the stolen funds
Galaxy Research reported more than 1,700 BTC stolen with high confidence and evidence of multiple attackers in the threat environment. The absence of a newly observed theft wave does not prove every remaining vulnerable seed is safe.
The Bitquery tracker recorded a September 7 movement of previously stolen funds into CoinJoin. Moving or mixing stolen coins is distinct from compromising additional wallets. Combining those timelines would turn useful tracking into an inaccurate new-attack claim.
Recovery scams to avoid
No researcher or support agent needs a seed phrase, passphrase or backup file to check whether a wallet is affected. Do not send bitcoin to an address supplied in a private message, and do not install firmware delivered through chat, advertisements or an unofficial download page.
Victims should preserve transaction IDs, addresses, device version, receipts and update history without publishing secrets. A documented report to the manufacturer and relevant authorities may support an investigation, but it cannot guarantee reversal of a confirmed Bitcoin transaction.
| Action | What it really does |
|---|---|
| Update firmware | Corrects future generation, not the old seed |
| Change PIN | Protects local access, not the underlying keys |
| Create a new seed | Produces an independent set of keys |
| Transfer bitcoin | Removes funds from exposed addresses |
The answer to “Coldcard hacked, what should I do?” is therefore not a rushed hardware purchase. Identify the seed’s origin, prepare and verify a new wallet, transfer the funds and retire addresses derived from the vulnerable secret. Each step should follow current official instructions without disclosing keys to anyone.
