ColdCard Is Compromised: What You Need to Do Now
The ColdCard RNG vulnerability is real, it's expanding, and it's already cost people their coins. James O'Beirne joins me to walk through who's affected, what the entropy numbers actually mean, and how to get out safely.

↓ Jump to the video and timestamps
I've been recommending ColdCard for years. If you've listened to this show, you've heard me do it. So when I say this is close to home, I mean it.
I was at PubKey in DC when word started spreading. I spent the rest of the night in the corner of that room on my phone, texting people I knew had ColdCards, trying to get them moving.
The confidence that I and a lot of people in this community placed in ColdCard was ill-gotten. The hardware is genuinely impressive. The secure enclaves, the engineering, all of it.
But they broke the one thing that everything else depends on: the random number generator that creates entropy for your private keys. It's like you got a Ferrari on top of a lawnmower engine.
I got James O'Beirne on tape as fast as I could. He's one of the people who was up all night on the technical side of this, using AI to triage and independently reproduce the vulnerability. This post covers everything we walked through: what the bug is, who's affected, what the numbers mean, how to migrate safely, and what this means for Bitcoin custody going forward. If you're on a post-2021 CoinKite device and you haven't acted yet, start here.
Key takeaways
- If you generated a key on a post-2021 CoinKite device without 99 or more dice rolls and without a cryptographically strong passphrase, move your funds now. Not this weekend. Now.
- Updating your ColdCard firmware is not enough. The vulnerability lives in the key you already generated. You must create a new wallet and move your coins to it.
- Multisig buys you time, not safety. If your signing threshold can be met entirely by CoinKite devices, treat it with the same urgency as single-sig. Don't get clever by half.
- AI has ended security by obscurity. The same models that found this bug are being pointed at every open-source Bitcoin repository right now. Proactive, continuous AI-assisted auditing is the new baseline, not a nice-to-have.
- Multi-vendor multisig has always been the answer. No single hardware wallet manufacturer deserves your full trust. This event is the proof, not the warning.
- Don't panic and foot-gun yourself. Test transactions first. Move deliberately. Steady is smooth, smooth is fast.
What happened, the ColdCard RNG vulnerability explained
The private key that secures your Bitcoin needs to be generated from 256 bits of cryptographically strong randomness. That's the standard. Anything less, and an attacker with enough compute can narrow the search space and grind out your key.
ColdCard's random number generator, on devices with firmware produced after 2021, is not delivering that. On MK2 and MK3 devices from that window, O'Beirne estimates the actual entropy is somewhere in the 20-something bit range. That's not a rounding error, that's a catastrophic shortfall. On newer devices like the MK4 and Q, it's partially mitigated, but O'Beirne's estimate as of our conversation was roughly 70 bits of security, still nowhere near the required 256.
It gets worse. One of the fallback RNGs used to patch over the original defect is, by O'Beirne's assessment from the ongoing investigation, less random than researchers initially thought and appears to be specified by the manufacturer in a way that may reduce entropy further. His words: the 70-bit estimate was still moving downward when we recorded.
The firmware that was running when you generated your key determines your exposure, not the firmware currently running on your device. You can update to the latest firmware today and still be sitting on a compromised private key that was generated two years ago.
O'Beirne and other researchers independently reproduced the vulnerability using AI assistance, specifically Kimi, a Chinese-origin model, which chewed through the relevant firmware history and found the RNG problem readily once pointed at the right window. The CoinKite MK3 security warning and the 594 BTC sweep that followed confirmed the stakes are real. For a clean summary of the vulnerability as it was first disclosed, see our earlier post COLDCARD's RNG Failed. Move Your Coins.
Are you affected, scenarios and urgency levels
| Your setup | Urgency | What to do |
|---|---|---|
| Single-sig, post-2021 device, no dice rolls, no passphrase | Critical | Move now. This is the worst case. |
| Single-sig, post-2021 device, passphrase only | Move | Don't rely on the passphrase unless you know it is cryptographically strong. |
| MK4 or Q, post-2021, no dice rolls | Move | Partial mitigation does not get you to 256 bits. |
| Multisig, signing threshold met entirely by CoinKite devices | Move | Treat it with the same urgency as single-sig. |
| Single-sig, post-2021 device, 99 or more dice rolls | Likely safe | The dice-roll path was verified by hand. O'Beirne is moving his own coins anyway. |
| Multisig requiring a non-CoinKite device to sign | Protected | That device is what is protecting your coins. |
Single-sig, post-2021 CoinKite device, no dice rolls, no passphrase: Move now. This is the worst-case scenario. The key you're holding was generated with entropy far below what you need for any reasonable security margin.
Single-sig, post-2021 CoinKite device, 99 or more dice rolls: O'Beirne says he verified by hand that the dice-roll code path is safe. If you did it correctly and you're confident you hit 99 or more rolls, you're likely okay. Even so, he's moving his own coins out of an abundance of caution, and I think that's the right call.
Single-sig, post-2021 CoinKite device, passphrase only: This is more complicated than it sounds. When I asked O'Beirne about using 6 or more BIP-39 words as a passphrase, he walked it back. Each BIP-39 word is drawn from a list of 2,048 words, so the math sounds large, but "given enough GPUs," something you think is a strong passphrase may not be. His guidance: unless you're a specialist and you know your passphrase is cryptographically strong, don't rely on it. Move.
MK4 or Q, post-2021, no dice rolls: Still move. The partial mitigation doesn't bring you to 256 bits, and O'Beirne confirmed the footprint of affected devices expanded during the investigation, with MK4s being swept from. The initial assumption that the red zone was only 2021-2023 MK2/MK3 firmware turned out to be wrong.
Multisig: Here's where it gets nuanced, and O'Beirne walked it through carefully. When you spend from a multisig, you reveal the public keys for all keys involved. An attacker who has those pubkeys can theoretically grind out the corresponding private keys from a compromised CoinKite device and construct a valid spend.
The rule he laid out: if your signing threshold can be met entirely by CoinKite devices, move. Don't think twice. If your multisig requires a non-CoinKite device to hit the signing threshold, your coins are protected by that device.
If you're an Unchained customer, the question is whether Unchained's pubkey is on-chain from a prior spend. O'Beirne's guidance: contact Unchained directly, they can answer that. Don't try to reason it out yourself. If there's any doubt, move.
How to migrate safely
First: don't panic. Panicking is how you lose coins that the RNG bug never would have taken from you. O'Beirne said it plainly: a lot of people are going to foot-gun themselves in the rush to migrate.
The process is straightforward but needs to be done deliberately.
Generate a new wallet on a device and software stack you trust, ideally one where you understand how the entropy was constructed. Move a small test amount first. Verify it arrived. Then move the rest.
If you're not sure where to park funds while you figure out a longer-term setup, O'Beirne's recommendation was practical: find an exchange you trust. Doxxing yourself is a real cost, but so is losing your coins. Get out of the compromised key first, sort out the ideal long-term custody arrangement after.
Firmware update alone does nothing for this. You cannot patch your way out of a key that was generated under the vulnerable RNG. New key, new wallet, move the coins.
On white-hat sweeping: there was discussion in Spaces the night this broke about whether researchers should rent GPU and proactively sweep vulnerable wallets to protect people who aren't plugged in enough to know what's happening. O'Beirne called it ethically gray and said he personally wouldn't be rushing to do it. The attribution problem is real: if you sweep someone's funds as a white hat, verifying back to the original owner and returning them requires presenting the physical device, and that mechanism hasn't been demonstrated conclusively and is legally murky in ways nobody fully thought through in real time.
It might help people who will otherwise never find out, and it might create its own set of legal and ethical disasters. Nobody had a clean answer.
AI changed the security game, permanently
The same night the vulnerability went public, O'Beirne and other researchers independently reproduced it using AI. He pointed the model at a specific firmware window, asked it to look for an RNG problem, and it found it. That's the world we're in now.
Security by obscurity is going to zero rapidly. Someone described it to O'Beirne this way the night of the discovery: "the tide's washing out." Every open-source Bitcoin repository, every firmware history, every cryptographic implementation, all of it is now being indexed and analyzed continuously by models that are getting better every few months. If there's a bug in there, it will be found. The only question is whether it's found by a researcher or an attacker.
The frustrating parallel to all of this is that the US frontier models were largely useless for this kind of security work. O'Beirne said explicitly that when he and colleagues tried to use US-based models during the triage, they locked up and refused to go further on certain lines of inquiry. He used Kimi exclusively to do the investigation.
I find that infuriating. Bitcoin teams have been trying to get access to frontier models for exactly this kind of auditing work, and the access restrictions are real. We need the ability to run proactive, continuous AI-assisted security audits on critical Bitcoin infrastructure, and the current model-access situation is not set up to support that.
The arms race framing is the right one. The tools that find these vulnerabilities are the same tools you need to defend against them. If you're building Bitcoin security infrastructure and you're not doing routine AI-assisted fuzz testing and auditing with the latest available models, you are at a structural disadvantage. That's the new baseline.
This event didn't create that reality, it just made it undeniable. The Claude security evaluation that breached real organizations earlier this year was another data point in the same direction.
What this means for self-custody and covenants
O'Beirne made a point I've been sitting with since we recorded: it feels like every single hardware wallet manufacturer has had a fatal misstep. Ledger spilled client data, Marty says twice; O'Beirne mentioned 2018, though the major documented Ledger breach was in 2020, and regardless, it happened. BitBox had physical defects that O'Beirne says allowed key exfiltration. Now ColdCard.
The domain is just genuinely hard, and O'Beirne's read is that even companies doing everything right are likely targeted at the supply chain level.
The Szabo line that keeps coming back is: trusted third parties are security holes. Nick Szabo wrote it, and it keeps proving true. You cannot fully delegate the security of bearer assets to a packaged product from a single vendor. That's not a criticism of any one company, it's the nature of the problem.
O'Beirne mentioned BitKey as a migration target people are discussing. He thinks highly of the team. But he also pointed out that some of their backend services are closed source, which means you're extending trust to a stack you can't fully audit, a real tradeoff, not a reason to dismiss it outright.
The categorical fix O'Beirne keeps returning to is the covenant layer. Multi-vendor multisig is a real improvement, he's been saying it for years, I've been saying it for years, and this event is the proof. But the user experience is bad, and it still requires trusting your key construction across multiple vendors. The only path to multisig-level security with genuinely good UX, in his view, is covenant-based vaults at the protocol layer.
The specific thing that would have helped here: a vault model with a clawback window, O'Beirne mentions six hours, where even if an attacker constructs a valid spend from a compromised key, you have a window to claw those funds back to a trusted counterparty like an exchange. The key construction failure wouldn't have mattered in the same way if the coins couldn't be moved without a clawback opportunity.
I think this event lights a fire under the covenant conversation. The community has been fractured on protocol development, and O'Beirne is honest about that. But the antifragile read, the one I'm holding onto, is that this could catalyze a real push toward the final form of individual-level Bitcoin security, one where AI-assisted audits and protocol-layer vaults work together, and where a key construction failure doesn't mean instant irreversible loss.
The community response, no CEO, no problem
I was at an event at PubKey in DC when it broke. Started as a normal evening. Then it became clear something real was happening, and I spent the rest of the night in the corner of the room on my phone.
Bitcoin has no CEO to call. There's no emergency hotline, no corporate comms team pushing updates.
What there was: Rob Hamilton, James, Portland HODL, and others hopping on Spaces in real time to walk people through it. Researchers independently reproducing the vulnerability. People texting their networks one by one.
I texted a friend who'd been heads down all day and had no idea. His brother was on vacation, sitting on a bare single-sig MK3, no dice entropy, no passphrase. Someone physically went to his house and helped him move the coins. That's what it looked like on the ground.
O'Beirne noted something worth sitting with: the excitement and camaraderie you feel in a moment like this is only possible because the people feeling it didn't lose their savings. There are people who did. That's horrible, and I don't want to paper over it. But the community's instinct, to self-organize, to reach out to one person who reaches out to ten more, to go over to someone's house, that instinct is worth protecting and leaning into.
I don't think this is the time to sling shit and throw people under the bus. The vulnerability is inexcusable, O'Beirne used that word, and I agree with it. Accountability matters and will come. Right now the priority is getting people out of harm's way.
About James O'Beirne
James O'Beirne is a Bitcoin protocol engineer and custody systems specialist who has spent years working on Bitcoin's scripting layer, with a particular focus on covenant proposals and vault constructions. He has contributed to Bitcoin Core and has done extensive work designing enterprise-grade custody systems. He is one of the primary advocates for adding covenant primitives to Bitcoin as a path toward better self-custody UX and protocol-level security guarantees.
Sources mentioned
- COLDCARD's RNG Failed. Move Your Coins. (TFTC): the initial TFTC disclosure as the vulnerability broke
- Coinkite Issues Mk3 Security Warning After 594 BTC Swept in Minutes (TFTC): confirmation of real-world funds swept under the vulnerability
- Claude Breached Three Real Organizations During Misconfigured AI Security Test (TFTC): context on AI-assisted security breaches as the broader threat model
- Nick Szabo, "Trusted Third Parties Are Security Holes" (Satoshi Nakamoto Institute, 2001): the Szabo formulation O'Beirne invokes on delegating custody trust
Watch the conversation
Timestamps
- 0:07 - Intro / Bitcoin as safe haven
- 0:59 - The vulnerability explained
- 4:39 - O'Beirne's own ColdCard situation
- 7:09 - The entropy math: 70 bits vs. 256
- 8:16 - How AI reproduced the bug
- 9:51 - Second-order effects on self-custody confidence
- 13:55 - Covenants and the categorical fix
- 18:01 - US model restrictions and the auditing problem
- 22:02 - Affected device footprint expands to MK4
- 23:14 - Multisig: pubkey exposure and the safety rule
- 28:19 - White-hat sweeping: ethics and attribution
- 31:16 - Don't panic, don't foot-gun yourself
- 35:15 - Silver lining: antifragile path to final-form custody
Sponsors
- Cash App: For a limited time, new customers can get $21 added to their balance. Just use code TFTC10 when you sign up, and send at least $5 to a friend in the first two weeks. cash.app/app/TFTC
- Square: For up to $200 off eligible Square hardware. square.com/go/tftc
- Bitkey: Use code TFTC10 for 10% off the new Bitkey. bitkey.world
- Aven: aven.com/bitcoin
- CrowdHealth: joincrowdhealth.com/tftc
- Unchained: unchained.com/tftc
- Salt of the Earth: drinksote.com/tftc
Frequently Asked Questions
All ColdCard models with firmware from 2021 onward are affected to some degree. MK2 and MK3 devices from the 2021-2023 firmware window are the most severe cases, with estimated entropy in the 20-something bit range according to O'Beirne's assessment. MK4 and Q devices are partially mitigated but still estimated at roughly 70 bits of entropy rather than the required 256, and that number was still moving downward as the investigation continued. If you're on any post-2021 CoinKite device without dice rolls or a cryptographically strong passphrase, treat it as compromised.
No. The firmware update addresses the RNG going forward, but it does nothing for the key you already generated. Your existing private key was created under the vulnerable RNG, and that doesn't change when you update firmware.
You must generate a new wallet with a new key and move your coins to it. The firmware you were running when you generated your key is what determines your exposure, not what's running on the device today.
If you used 99 or more dice rolls and you're confident you did it correctly, O'Beirne says he verified by hand that code path is safe. The dice-roll process bypasses the device's RNG by letting you supply your own entropy, so the RNG bug doesn't apply. Even so, given that the investigation is ongoing and the situation has expanded beyond initial estimates, moving coins as a precaution is reasonable. If you're uncertain whether you hit 99 rolls, don't guess, move.
Likely yes. When you spend from a multisig, you reveal the public keys for all keys involved. An attacker who has those pubkeys can theoretically derive the private keys from compromised CoinKite devices and construct a valid spend.
O'Beirne's rule: if the signing threshold of your multisig can be met entirely by CoinKite devices, move without overthinking it. If you've never spent from the wallet, your pubkeys may not yet be on-chain, but that's a subtlety that cuts both ways. Don't rely on it. If you're an Unchained customer in this situation, contact Unchained directly to understand whether their pubkey is on-chain.
Bitcoin private keys are supposed to be generated from 256 bits of randomness, meaning there are 2^256 possible keys, a number so large that brute-forcing it is computationally impossible by any realistic measure. If entropy drops to 70 bits, the search space shrinks to 2^70, which is still large but reachable with serious compute resources. At 20-something bits, the search space collapses to a range that can be swept quickly. The difference isn't incremental, it's the difference between security and none.
Generate a new wallet on a device and entropy source you trust and understand. Send a small test transaction first and verify it arrives before moving the full balance.
If you need somewhere to park funds temporarily while you sort out a long-term custody setup, O'Beirne's recommendation was straightforward: use a trusted exchange. Yes, it means doxxing yourself, but getting out of the compromised key is the priority. Move deliberately, not fast. As O'Beirne put it: steady is smooth, smooth is fast.
A vault is a covenant-based Bitcoin construction where a spend triggers a time-locked delay, O'Beirne mentions a six-hour window, before funds become fully accessible to the destination. During that window, the original owner can claw the funds back to a trusted counterparty like an exchange. If ColdCard users had been holding in vault-style constructions, a compromised key alone wouldn't have been enough for an attacker to achieve irreversible loss, the clawback mechanism would have provided a second line of defense. Getting covenant primitives into Bitcoin protocol is why O'Beirne has been focused on this area for years, and events like this are exactly the kind of forcing function that brings the conversation back.


