BITWU.ETH 🔆|Aug 02, 2026 09:17
Hardware wallets aren’t absolutely safe either—this is an ongoing Coldcard low-entropy seed sweeping incident!
CZ shared this today as well. Everyone should pay attention to this security issue.
We’re now in the third wave, with a total of 1,367.05 BTC stolen, approximately $88.6 million, affecting 4,585 addresses.
The root cause? Attackers are suspected of exploiting low-entropy seeds generated by older Coldcard firmware to offline derive/enumerate some users’ private keys, then quickly sweeping BTC on-chain.
This has nothing to do with BTC itself or the protocol—it’s an issue with the hardware wallet!
So, if you or someone you know has used Coldcard and hasn’t been affected yet, migrate your funds as soon as possible.
Suggested steps to handle this:
1) Don’t generate new seeds on old firmware. Upgrade to the official patched version first.
2) Don’t assume upgrading will fix old seeds. Old seeds must be abandoned, and funds need to be migrated to a newly generated wallet.
3) After generating a new seed, verify your backup, wallet fingerprint, and receiving address.
4) Start with a small test transaction. Once confirmed, migrate the remaining funds.
5) Don’t discard old backups until all balances are confirmed and migration is complete. Handle old seeds only after that.
6) Never input your mnemonic phrase into websites, online tools, or unknown checkers—this could lead to secondary scams.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink