URGENT: Bitcoin on a COLDCARD? Check If You’re Affected and Secure Your Funds Now
Do not panic. Rushing can lead to serious and permanent mistakes. Take the time to check the receiving address, confirm that you can access the destination, protect your backups, and send a small test transaction before moving the full balance. Never share your seed words or passphrase with anyone.
This guide helps you check whether your wallet is affected by the July 2026 Coldcard vulnerability and shows you how to move your bitcoin to safety.
Updated July 31, 2026. This situation is still developing. Check Coinkite’s official security advisory again before acting.
Do not panic. Rushing can lead to serious and permanent mistakes. Take the time to check the receiving address, confirm that you can access the destination, protect your backups, and send a small test transaction before moving the full balance. Never share your seed words or passphrase with anyone.
On July 30, an attacker stole bitcoin from wallets that appear to have been created by vulnerable Coldcard firmware. Galaxy Research found 1,196 drained addresses holding a total of 1,082.65 BTC. This number comes from an independent review of activity on the Bitcoin network. Coinkite has not confirmed every address in that group. Galaxy Research published its findings on July 31.
The problem came from the way some Coldcards created seed words. The device used weak randomness in place of the secure randomness it was supposed to use. This made some seeds much easier for an attacker to guess. Once an attacker found the seed, they could control the wallet and spend its bitcoin. Block’s engineering team explains the technical cause here.
The Bitcoin network continues to work normally. The security failure happened inside affected Coldcard firmware.
Short Version
Read this section if you need the safest simple plan. The Detailed Version below explains every case.
1. First, assume you are affected if you are unsure
Treat your wallet as affected if your seed was created by:
- A Coldcard Mk2 or Mk3 running firmware 4.0.0 through 4.1.9. Version 4.0.0 was released on March 17, 2021. Version 4.1.9 was released on June 26, 2023 and remained the latest Mk2/Mk3 version until July 31, 2026.
- Any Coldcard Mk4, Mk5, or Q before the fixed firmware released on July 31, 2026. For Mk4 and Mk5, the fixed versions are standard firmware 5.6.0 and Edge firmware 6.6.0X. For Q, they are standard firmware 1.5.0Q and Edge firmware 6.6.0QX.
The dates can help you identify the firmware, but the version that matters is the firmware used when the seed words were created. A Coldcard can keep running old firmware for years. Updating the device later does not fix an old seed.
Your risk may be lower if you added at least 50 private dice rolls, used a strong and unique BIP-39 passphrase, or held the bitcoin in multisig. Read the relevant section in the Detailed Version before deciding what to do. If you do not remember how the seed was created, treat it as affected.
2. Move the bitcoin to a safe destination
If you already have another hardware wallet with a seed you know was created securely, you can use it as the destination. A device from a different manufacturer running its latest official firmware is a simple choice. You can also use another Coldcard, but install the latest official hotfix before using it to generate a new seed. Never restore the affected seed on the receiving wallet.
You can still use the affected Coldcard to sign the transaction that moves the bitcoin. The bug weakened the creation of seeds and other secrets. It did not stop the device from signing a normal Bitcoin transaction. You do not need to update the affected Coldcard before signing the move, although you must update it before using it to create a replacement seed.
If another hardware wallet is unavailable, temporarily use a trusted hot wallet installed from its official website or app-store page on a clean, updated phone or computer. This is an emergency step. Do not keep a large balance in a hot wallet longer than needed.
Create the receiving address yourself and check it inside the official wallet app. Send a small test transaction first. Confirm that the test arrived. Then move the remaining balance.
Keep the old Coldcard backup until the full balance has arrived safely.
3. Rebuild the Coldcard safely
After the bitcoin is in the new hardware wallet or temporary hot wallet:
- Download the fixed firmware for your exact Coldcard model and release track from the official Coldcard firmware page.
- Follow Coldcard’s instructions to verify and install it.
- Restart the Coldcard and confirm the new firmware version on its screen.
- Generate a completely new seed. The old seed stays vulnerable after the update.
- Add a strong, unique BIP-39 passphrase.
- Write down the new seed and passphrase. Label them clearly and store them in separate places.
- Confirm the new wallet fingerprint and a receive address on the Coldcard screen.
- Test that you can recover the new wallet from your backups.
A simple way to make a strong passphrase is to generate a new 12-word wallet in BlueWallet and use those 12 words as the Coldcard passphrase. Keep that BlueWallet wallet empty. Label the words PASSPHRASE so they are never confused with the Coldcard seed. The Detailed Version explains the full process and its security tradeoff.
4. Move the bitcoin into the new wallet
Send a small test transaction from the hot wallet or second hardware wallet to the new Coldcard wallet. Verify the receiving address on the Coldcard screen. Confirm that the test arrived. Then send the rest.
Check the final balance before retiring any old backup. Mark the affected seed COMPROMISED AND RETIRED so nobody uses it again.
5. Decide on your long-term setup
Your bitcoin is now controlled by a new seed created on fixed firmware and protected by a strong passphrase.
You can keep this setup, order a hardware wallet from another manufacturer, use a Coldcard with the latest official hotfix and a completely new seed, or build a multisig wallet using devices from different manufacturers. Take your time with this choice. Every later move should follow the same process: create a new wallet, back it up, verify the address on the device, send a test transaction, then move the rest.
Five rules that prevent the worst mistakes
- Never enter seed words or a passphrase on a website.
- Never use an address sent by email, text message, Telegram, WhatsApp, or direct message.
- Never send the full balance before a small test transaction succeeds.
- Never throw away the old backup before the full balance is confirmed in the new wallet.
- Never believe anyone who says they need your seed words to help you.
Detailed Version
Find your situation
| Your situation | What to do | Go to |
|---|---|---|
| Mk2 or Mk3 created the seed on firmware 4.0.0 through 4.1.9; single-signature wallet; no strong passphrase; fewer than 50 dice rolls or unknown | Prepare carefully and move the funds today. | Critical Mk2 or Mk3 wallet |
| Mk4, Mk5, or Q created the seed before the fixed July 31 firmware; single-signature wallet; no strong passphrase; fewer than 50 dice rolls or unknown | Move the funds as soon as you have a verified destination. Aim to complete the move today. | Affected Mk4, Mk5, or Q wallet |
| You have another hardware wallet with a securely generated seed | Use it as the destination. If it is a Coldcard that will generate a new seed, install the latest official hotfix first. | Use another hardware wallet |
| The Coldcard is your only hardware device | Use the one-device process carefully. | Use one Coldcard |
| The Coldcard is lost or broken and you only have the seed words | Recover the old wallet only long enough to move the funds. | Recover from the backup |
| You used a BIP-39 passphrase | Check how strong it is, then plan the move. | Passphrase users |
| You added at least 50 fair, private dice rolls when creating the seed | Coinkite says this seed is safe from this specific randomness bug. | Dice users |
| The Coldcard is one key in a multisig wallet | Check every key and find out how many may be weak. | Multisig wallets |
| Your bitcoin was acquired without KYC | Prefer a new self-custody wallet if privacy matters. | Privacy and no-KYC bitcoin |
| Bitcoin has already left without your permission | Protect anything left, then save evidence. | If bitcoin was stolen |
Am I affected?
Answer these questions:
- Which device created your seed words?
- Which firmware was installed when the seed was created?
- Did you add at least 50 fair, private dice rolls through Coldcard’s Add Dice Rolls feature?
- Did you use a BIP-39 passphrase? This is separate from the Coldcard PIN.
- Is the wallet single signature or multisig?
The device that holds the seed today may not be the device that created it. The seed’s origin is what matters.
Affected and fixed versions
| Device and firmware used to create the seed | Relevant release date | What it means |
| Mk1 through version 3.0.6 | Version 3.0.6: December 19, 2019 | Outside this bug according to Block |
| Mk2 or Mk3 through version 3.2.2 | Version 3.2.2: January 14, 2021 | Outside this bug according to Block |
| Mk2 version 4.0.0 through 4.1.9 | 4.0.0: March 17, 2021; 4.1.9: June 26, 2023 | Treat as critically affected |
| Mk3 version 4.0.0 through 4.1.9 | 4.0.0: March 17, 2021; 4.1.9: June 26, 2023 | Treat as critically affected. Coinkite begins its warning at 4.0.1, released March 29, 2021. Block also includes 4.0.0. |
| Mk4 or Mk5 before standard firmware 5.6.0 | Fixed version 5.6.0: July 31, 2026 | Affected |
| Mk4 or Mk5 before Edge firmware 6.6.0X | Fixed version 6.6.0X: July 31, 2026 | Affected |
| Q before standard firmware 1.5.0Q | Fixed version 1.5.0Q: July 31, 2026 | Affected |
| Q before Edge firmware 6.6.0QX | Fixed version 6.6.0QX: July 31, 2026 | Affected |
These dates show when Coinkite released each version. They cannot prove which firmware was installed when a particular seed was created. Check the version on the device and any records you kept. If you remain unsure, treat the seed as affected.
The fixed versions published on July 31, 2026 are:
- Mk3: 4.2.0 or later, released July 31, 2026
- Mk4 and Mk5, standard firmware: 5.6.0 or later, released July 31, 2026
- Mk4 and Mk5, Edge firmware: 6.6.0X or later, released July 31, 2026
- Q, standard firmware: 1.5.0Q or later, released July 31, 2026
- Q, Edge firmware: 6.6.0QX or later, released July 31, 2026
Standard and Edge are different release tracks. Install the correct one for your device. Use the official firmware page and follow Coinkite’s verification instructions.
TAPSIGNER, OPENDIME, and SATSCARD use different software and are not part of this incident.
Common situations that cause confusion
- You updated the Coldcard after creating the wallet. The old seed keeps the weakness it had when it was created.
- You restored the Coldcard seed on another hardware wallet. Moving the same seed to another device does not make it stronger.
- You need to move the bitcoin but have not updated the affected Coldcard. You can still use it to sign the outgoing transaction. Update it before asking it to generate a replacement seed.
- You created the seed securely somewhere else and later imported it into a Coldcard. This bug did not weaken that seed because the Coldcard did not create it.
- You used BIP-85 to create child seeds from an affected master seed. Treat the child seeds as affected too.
- You created other secrets on vulnerable firmware. Paper-wallet keys, some Seed XOR values, cloning keys, Key Teleport keys, and other features may have used the same weak randomness. Review the other affected features in Block’s report.
- You cannot remember the firmware version or number of dice rolls. Treat the seed as affected.
How quickly should I act?
Nobody can give you a guaranteed number of safe hours or days. An attacker can search for weak seeds without connecting to your wallet. They can spend the bitcoin as soon as they find a funded seed.
1. Critical Mk2 or Mk3 wallet
This is the highest-risk group. Affected Mk2 and Mk3 seeds had about 40 bits of effective randomness. That is low enough for a well-funded attacker to search.
The July 30 thefts mainly came from single-signature wallets in this group. Prepare a verified destination and move the funds today. Slow down long enough to confirm the backup, wallet fingerprint, receiving address, and test transaction.
2. Affected Mk4, Mk5, or Q wallet
Coinkite estimates that these affected seeds had about 72 bits of randomness. They are harder to search than affected Mk2 and Mk3 seeds. They still fall far below the level expected from a secure seed.
Treat the wallet as unsafe for meaningful savings. Move the funds as soon as a verified destination is ready. The first thefts focused on older models. This does not make the newer models safe.
3. You used a BIP-39 passphrase
A passphrase creates a separate wallet from the same seed words. An attacker who finds the weak seed must also guess the exact passphrase.
Your protection depends on the passphrase:
- Names, dates, quotations, song lyrics, common expressions, keyboard patterns, and reused passwords are weak.
- Several words chosen by a person are often weaker than they appear.
- Six or seven words chosen randomly with dice from a large word list provide strong protection.
- A fresh 12-word phrase generated by a trusted wallet provides very strong protection when the random generator works correctly.
Move urgently if the passphrase is short, reused, or created from memory. A long, random, unique passphrase gives you more time to prepare. Coinkite still recommends moving to a new seed.
Each passphrase opens a different wallet. If you used several passphrases, check and move every balance separately.
4. You added dice rolls
Coinkite says this bug does not put the seed at risk when all of the following are true:
- You used Coldcard’s Add Dice Rolls feature before accepting the final seed words.
- You added at least 50 rolls from a fair six-sided die.
- The rolls were random and private.
- Nobody recorded, photographed, or watched the rolls.
Fifty to 98 rolls provide at least 128 bits of randomness from the dice. Ninety-nine or more provide about 256 bits. Coinkite explains this exception in its advisory.
Treat the seed as affected if you used fewer than 50 rolls or cannot remember the exact process. Update the firmware before creating another wallet.
5. Your Coldcard is part of a multisig wallet
Multisig requires more than one key to spend bitcoin. A 2-of-3 wallet has three keys and needs any two of them to sign.
Write down your policy, such as 2-of-3 or 3-of-5. Check how every key was created.
- In a 2-of-3 wallet with one affected key, the attacker still needs another key. Replace the affected key promptly.
- In a 2-of-3 wallet with two affected keys, an attacker may have enough keys to spend. Move the funds immediately.
- In a 3-of-5 wallet with one or two affected keys, the attacker does not yet have enough keys. Replace the affected keys soon.
- A multisig wallet made only with affected Coldcards may have several weak keys from the same bug. Treat it as urgent.
Replacing a multisig key usually means creating a new multisig wallet and moving the bitcoin to it. Back up the complete wallet setup. This includes all public keys, fingerprints, derivation paths, address type, and the number of signatures required. Casa explains why all public keys are needed to recover a multisig wallet.
Choose where to move the bitcoin
Option A: Use another hardware wallet
A hardware wallet with a seed that was created securely can serve as the destination. Using a device from another manufacturer running its latest official firmware is a simple choice and reduces dependence on one company’s software. Another Coldcard can also serve as the destination. If that Coldcard will generate a new seed, install the latest official hotfix for its model and release track first. In every case, the destination must use a different, secure seed. Restoring the affected seed on another device does not make it safe.
The affected Coldcard can still sign the transaction that moves the bitcoin. This vulnerability concerns how it generated seeds and certain other secrets. You do not need to update it before signing the outgoing transaction. You must update it before using it to generate the replacement seed.
Install the latest official firmware on the receiving device.
Generate a completely new seed on that device.
Write down the backup offline.
Add a passphrase only after you understand how to back it up and recover it.
Restart the device and confirm the wallet fingerprint.
Create a receive address and verify it on the hardware wallet’s screen.
Send a small test transaction from the affected wallet.
Confirm that the test arrived.
Send the remaining balance. Use send all when available so the old wallet keeps no change.
Check every account, address type, and passphrase wallet connected to the old seed.
Option B: The Coldcard is your only hardware device
This process requires switching between the affected seed and the new seed. Follow each step carefully. Write down both wallet fingerprints so you always know which wallet is open.
Confirm that you have a correct backup of the affected seed. Record its wallet fingerprint.
Download the fixed firmware for your model and release track from coldcard.com.
Follow Coldcard’s firmware verification and installation guide.
Restart the device. Confirm the fixed version on its screen.
Remove the old seed from the device only after checking its backup.
Generate a new seed. Record the words and wallet fingerprint.
Create a receive address. Verify it on the Coldcard screen and write it down carefully.
Restore the affected seed. Confirm its fingerprint.
Send a small test amount to the new address.
Restore the new seed. Confirm its fingerprint and check that the test arrived.
Restore the affected seed again. Send the remaining balance.
Restore the new seed and confirm the final balance.
Keep both backups until the full balance is confirmed. Then mark the old backup COMPROMISED AND RETIRED.
Advanced users can create a seed from dice on an updated Mk3 by choosing Import Existing > Dice Rolls and entering at least 99 private rolls. Keep the rolls away from cameras and connected devices. The regular seed generator is fixed in firmware 4.2.0.
Option C: The Coldcard is unavailable
If the device is lost or broken, use the seed backup only long enough to move the funds. A replacement hardware wallet is the safest recovery tool. Restore the affected seed on that device, then send the bitcoin to a different wallet with a completely new seed.
A reputable software wallet can help in an emergency when waiting for new hardware creates more risk. Sparrow and Electrum are common Bitcoin-only choices.
If you use software:
Use a clean, fully updated computer.
Download the wallet from its official website.
Verify the download using the project’s instructions.
Enter the seed only inside the installed wallet application.
Check that the addresses and transaction history match your old wallet.
Send the full balance to a new secure destination.
Remove the affected seed from the software wallet after the move.
Never use an online seed checker. A seed entered on a phone or computer should not become your long-term savings wallet. Generate the final wallet seed on secure hardware.
Protecting the privacy of no-KYC bitcoin
You can move bitcoin between two wallets you control without providing identity documents. The move will still appear publicly on the Bitcoin network.
If privacy matters:
Move the bitcoin to a new self-custody wallet that you control.
Keep separate sources of bitcoin separate when you know how to use coin control. Spending several pieces of bitcoin together can show that they belong to the same person.
Use a new receiving address for every transfer.
Verify every address on the receiving hardware wallet’s screen.
Use your own node or your usual private connection if it is already working. An emergency is a poor time to learn new privacy software.
Protect the funds first. A simple, verified transfer is safer than a rushed privacy process you have never used. Avoid unknown mixing services and anyone who contacts you offering private recovery help.
Nunchuk offers DIY multisig and paid assisted plans, including options it describes as zero-KYC. Casa offers assisted multisig and says its vault service does not require identity documents. Buying or selling through a partner may require KYC. Check each company’s current terms and privacy policy before signing up.
Check the new wallet before moving the full balance
Use this checklist:
- The destination uses a completely new seed.
- The seed was created on fixed Coldcard firmware or an unaffected hardware wallet.
- The words are written down offline and in the correct order.
- The passphrase is strong, unique, and recorded exactly.
- The seed and passphrase are stored separately.
- The device shows the expected wallet fingerprint after a restart.
- The receiving address matches the address shown on the hardware wallet screen.
- A small test transaction arrived.
- You checked the amount, fee, destination, and change on the signing device.
- The final transaction leaves no bitcoin in the affected wallet.
- You checked every account, address type, and passphrase wallet tied to the old seed.
- The final balance is confirmed before you retire the old backup.
A compromised computer can replace an address copied to the clipboard. Trust the address shown on the receiving hardware wallet’s screen.
What is a BIP-39 passphrase?
A BIP-39 passphrase is an extra secret used with the seed words. Together, they open a separate wallet. The passphrase is sometimes called a “25th word,” although it can contain several words. It is separate from the Coldcard PIN.
Every passphrase opens a valid wallet. The Coldcard cannot warn you about a typo. One missing space or changed capital letter opens a different wallet that will usually appear empty.
You need both the seed and the exact passphrase to recover the bitcoin. Losing either one can make the funds impossible to access.
A simple way to create a strong passphrase
You can use a new 12-word phrase generated by BlueWallet as the Coldcard passphrase. These words provide about 128 bits of randomness when the phone’s random generator works correctly.
Download BlueWallet from its official website or official app-store page.
Create a new Bitcoin wallet.
Write down the 12 words in their exact order.
Keep this BlueWallet wallet empty. Never use the seed from a wallet that holds or previously held bitcoin.
Enter all 12 words on the Coldcard as the BIP-39 passphrase. Use one space between each word.
Label the backup PASSPHRASE. These words are not the Coldcard seed.
Store the passphrase offline and in a different place from the Coldcard seed.
Confirm the wallet fingerprint created by the seed and passphrase.
Test a complete recovery before moving a meaningful balance.
Delete the empty wallet from BlueWallet after the backup and recovery test are complete.
Do not keep a screenshot, digital photo, cloud note, email, or clipboard copy of the words.
This method shows the passphrase on a phone connected to the internet. Malware on the phone could record it. The phrase still gives strong protection against an attacker trying to guess an affected Coldcard seed.
For a large balance, you can generate the passphrase offline. Six or seven words selected with physical dice from the EFF long word list provide about 77 or 90 bits of randomness. Another hardware wallet can also generate a fresh 12-word phrase without showing it on a phone or computer.
Do not invent the passphrase yourself. People tend to choose words and patterns that computers can guess. Keep a physical backup even if you memorize it.
How should I store the new backups?
For a single-signature wallet with a passphrase:
Write the seed words on paper or a durable metal backup.
Keep a second protected copy in another safe location if fire, theft, or a natural disaster could destroy the first.
Store the passphrase separately and keep its own backup.
Label each item clearly.
Record the wallet fingerprint and simple recovery instructions.
Test recovery before depositing a large amount.
Make sure your heirs can eventually find both secrets without storing them together today.
Do not store seed words or passphrases in photos, cloud notes, emails, shared documents, or unencrypted files.
A multisig wallet needs a different backup plan. Keep a backup for every key. Also save the full wallet setup, including public keys, fingerprints, derivation paths, address type, and number of signatures required.
Can I trust Coldcard’s fixed firmware?
Coinkite says the new firmware removes the weak random-number fallback and adds a check that stops the firmware from building when the correct hardware random generator is missing. The company explains the fix in its technical backgrounder. The source code is available for outside review.
The fixed firmware solves the known seed-generation bug. It does not repair seeds created before the update. Those funds still need to move to a new seed.
You have several reasonable choices:
Use fixed Coldcard firmware to create a completely new seed and follow Coinkite’s migration guide.
Add at least 99 private dice rolls so the seed’s randomness comes from a source you control.
Create the new wallet on a hardware wallet from another manufacturer.
Use an updated Coldcard as one key in a multisig wallet with devices from other manufacturers.
For a large balance, using another manufacturer or a multi-vendor multisig reduces the damage that one future vendor bug could cause.
Can I trust hardware wallets again?
Hardware wallets keep private keys away from everyday phones and computers. Their screens let you check receiving addresses and transaction details before signing. This Coldcard incident shows that hardware wallets still depend on correct firmware and secure seed generation.
A safer setup includes:
Current firmware downloaded from the manufacturer’s official source
A completely new seed created after the update
Independent dice entropy when you know how to add it correctly
A strong passphrase with a tested backup
Address and transaction checks on the hardware screen
Multisig with devices from different manufacturers for large balances
A recovery test completed before an emergency
Choose a setup that you can understand, back up, and recover. Complexity can create its own mistakes.
What is multisig, and when should I use it?
A single-signature wallet needs one key to spend. A 2-of-3 multisig wallet has three keys and needs any two of them. One stolen key cannot spend the bitcoin. One lost key still leaves two keys for recovery.
Consider multisig when losing the balance would change your life, harm your family, or damage a business. It also works well for shared company funds and inheritance plans.
Multisig requires more work:
More devices and higher setup cost
More steps when sending bitcoin
Larger transactions and sometimes higher fees
A complete backup of the wallet setup
A clear inheritance plan
Regular checks that the keys and instructions still work
A common setup is 2-of-3 with devices from different manufacturers in separate secure locations. Practice the full setup with a small amount before trusting it with long-term savings.
Nunchuk, Casa, or DIY multisig?
| Option | What it does | Main benefit | Main risk or cost |
| Sparrow DIY 2-of-3 | You build and manage the multisig wallet | Full control and no service provider holds a key | You must set up, document, and recover everything yourself |
| Nunchuk DIY | App for single-signature and multisig wallets | Free tools, broad hardware support, and recovery with other software | You manage the wallet design and every backup |
| Nunchuk assisted | Paid multisig plans with help for recovery, key replacement, and inheritance | Guided setup and zero-KYC options | Subscription cost and some wallet information shared with the service |
| Casa | Assisted 2-of-3 or 3-of-5 wallets; Casa holds one recovery key | Setup help, key checks, and an independent recovery process | Subscription cost and an ongoing service relationship |
Nunchuk and Casa cannot spend from their standard multisig vaults with only the key they hold. Both publish ways to recover without their service. See Nunchuk’s recovery guide and Casa’s recovery guide.
Test the full recovery process before choosing a long-term setup. Assisted custody can reduce setup mistakes. DIY custody gives you more control and requires more skill.
If some or all of the bitcoin has already been stolen
Bitcoin transactions cannot be reversed by the network. You can still protect any bitcoin left and save information that may help trace the stolen funds.
Move every remaining balance tied to the affected seed to a new secure wallet.
Save the transaction ID, receiving addresses, timestamps, screenshots, and the addresses you controlled.
Record the Coldcard model, serial information, purchase source, approximate seed-creation date, firmware used at the time, current firmware, dice process, passphrase use, and wallet software.
Keep the Coldcard and MicroSD cards after the remaining funds are safe. Do not erase possible evidence.
Contact Coinkite through the contact details on its official website.
Report the theft to the proper cybercrime or law-enforcement agency. Include the transaction IDs and saved evidence.
Contact any exchange or service that receives the stolen bitcoin through its official fraud channel. Law enforcement may need to send the formal request to preserve or freeze funds.
Recovery scammers search for victims during incidents like this. They may promise to reverse a transaction, ask for the seed, request payment in bitcoin, or tell you to “synchronize” the wallet. Do not engage with them.
Sources and updates
This guide provides general security information. A complex multisig wallet, business treasury, inheritance plan, or large balance may require help from a qualified Bitcoin security professional. A legitimate professional will never ask for your seed words or passphrase.