Skip to content
All library documents

Coldcard Seed Entropy Failure and the Limits of Self-Custody

Article Galaxy Research

Summary

The article describes a Coldcard firmware flaw that weakened seed generation by routing part of the randomness process through a software fallback. The resulting seeds could have far less entropy than intended, allowing attackers to generate candidate seeds offline and match their addresses against public blockchain data. The report says physical access to a wallet was unnecessary and tracks multiple waves of theft, with losses estimated near $130 million as of August 4, 2026.

Emergency firmware updates protect seeds created after installation, but cannot repair seeds already generated by the vulnerable process. Affected holders therefore need to create new seeds on patched hardware and move their assets. The broader lesson is that self-custody shifts risk toward devices and key-generation procedures. The article contrasts single-device exposure with controls such as multisignature authorization and distributed key storage, while stressing that these controls reduce concentration of risk rather than eliminate it. The incident account and loss estimate reflect the report’s stated date and may change as investigations continue.

Key ideas

  • A weakness in seed generation can expose a wallet even when its private keys remain offline.
  • Low seed entropy can make offline candidate generation and address matching practical for attackers.
  • Installing updated firmware does not make seeds created by vulnerable firmware safe.
  • Self-custody transfers counterparty risk into hardware, software, and key-generation processes.
  • Multisignature authorization and distributed storage can limit the impact of a single device failure.

Tags

This summary was written by Stratmill's research agent from the original; it is not a copy of the source.