URGENT: Bitcoin on a COLDCARD? Check If You’re Affected and Secure Your Funds Now
Do not panic. Rushing can lead to serious and permanent mistakes. Take the time to check the receiving address, confirm that you can access the destination, protect your backups, and send a small test transaction before moving the full balance. Never share your seed words or passphrase with anyone.
URGENT: Bitcoin on a COLDCARD? Check If You’re Affected and Secure Your Funds Now
This guide helps you check whether your wallet is affected by the July 2026 Coldcard vulnerability and shows you how to move your bitcoin to safety.
Updated August 3, 2026. This situation is still developing. Check Coinkite’s official security advisory again before acting.
Do not panic. Rushing can lead to serious and permanent mistakes. Take the time to check the receiving address, confirm that you can access the destination, protect your backups, and send a small test transaction before moving the full balance. Never share your seed words or passphrase with anyone.
On July 30, an attacker stole bitcoin from wallets that appear to have been created by vulnerable Coldcard firmware. Galaxy Research found 1,196 drained addresses holding a total of 1,082.65 BTC. This number comes from an independent review of activity on the Bitcoin network. Coinkite has not confirmed every address in that group. Galaxy Research published its findings on July 31.
The problem came from the way some Coldcards created seed words. The device used weak randomness in place of the secure randomness it was supposed to use. This made some seeds much easier for an attacker to guess. Once an attacker found the seed, they could control the wallet and spend its bitcoin. Block’s engineering team explains the technical cause here.
The Bitcoin network continues to work normally. The security failure happened inside affected Coldcard firmware.
Important update about the emergency firmware
Some users have reported that COLDCARD devices became unusable after they installed the emergency firmware released on July 31. A firsthand Mk4 report describes a crash while applying a passphrase, followed by a device that displayed BRICKED after restarting. Other public summaries describe these reports as anecdotal and unconfirmed. Coinkite has not yet publicly confirmed a widespread firmware defect. The possible consequence is serious enough to change the guidance in this article.
This guide does not recommend updating your COLDCARD or using any COLDCARD to create the replacement wallet at this time. An update cannot repair a weak seed. Move the bitcoin first, using the affected COLDCARD only to sign the outgoing transaction. Send the funds to a securely created wallet on a device from a different manufacturer, or use a reputable hot wallet as a short temporary step.
Short Version
Read this section if you need the safest simple plan. The Detailed Version below explains every case.
1. First, assume you are affected if you are unsure
Treat your wallet as affected if your seed was created by:
A Coldcard Mk2 or Mk3 running firmware 4.0.0 through 4.1.9. Version 4.0.0 was released on March 17, 2021. Version 4.1.9 was released on June 26, 2023 and remained the latest Mk2/Mk3 version until July 31, 2026.
Any Coldcard Mk4, Mk5, or Q that created a seed before the emergency firmware releases dated July 31, 2026. The relevant version boundaries are 5.6.0 and 6.6.0X for Mk4 and Mk5, and 1.5.0Q and 6.6.0QX for Q.
The dates can help you identify the firmware, but the version that matters is the firmware used when the seed words were created. A Coldcard can keep running old firmware for years. Updating the device later does not fix an old seed.
Your risk may be lower if you added at least 50 private dice rolls, used a strong and unique BIP-39 passphrase, or held the bitcoin in multisig. Read the relevant section in the Detailed Version before deciding what to do. If you do not remember how the seed was created, treat it as affected.
2. Move the bitcoin to a safe destination
If you already have a hardware wallet from a different manufacturer with a seed you know was created securely, you can use it as the destination. Check the manufacturer’s current security notices and setup instructions before using it. Never restore the affected seed on the receiving wallet.
You can still use the affected Coldcard to sign the transaction that moves the bitcoin. The bug weakened the creation of seeds and other secrets. It did not stop the device from signing a normal Bitcoin transaction. Do not update, wipe, or reset it before the funds have moved.
If another hardware wallet is unavailable, temporarily use a trusted hot wallet installed from its official website or app-store page on a clean, updated phone or computer. This is an emergency step. Do not keep a large balance in a hot wallet longer than needed.
Create the receiving address yourself and check it inside the official wallet app. Send a small test transaction first. Confirm that the test arrived. Then move the remaining balance.
Keep the old Coldcard backup until the full balance has arrived safely.
3. Create a new long-term wallet
If the bitcoin is already on a secure hardware wallet from a different manufacturer, you can keep it there. If you used a hot wallet temporarily, obtain a hardware wallet from a different manufacturer through an official source. Check the manufacturer’s current security notices and follow its setup instructions.
Generate a completely new seed on the new hardware wallet. Never import the affected COLDCARD seed.
Write down the new seed in the correct order.
If the device supports BIP-39 passphrases and you choose to use one, create a strong, unique passphrase.
Label the seed and passphrase clearly. Store them offline in separate places.
Restart the device and confirm the expected wallet fingerprint or other wallet identifier.
Create a receive address and verify it on the hardware wallet’s own screen.
Test that you can recover the wallet from the backup before moving a meaningful balance.
A simple way to make a strong passphrase is to generate a new 12-word wallet in BlueWallet and use those 12 words as the passphrase on the new hardware wallet. Keep that BlueWallet wallet empty. Label the words PASSPHRASE so they are never confused with the wallet seed. Confirm first that your new hardware wallet supports a BIP-39 passphrase of this length, including spaces. The Detailed Version explains the full process and its security tradeoff.
4. Move the bitcoin into the new wallet
Send a small test transaction from the temporary hot wallet or old wallet to the new hardware wallet. Verify the receiving address on the new device’s screen. Confirm that the test arrived. Then send the rest.
Check the final balance before retiring any old backup. Mark the affected seed COMPROMISED AND RETIRED so nobody uses it again.
5. Decide on your long-term setup
Your bitcoin is now controlled by a new seed created on a device from a different manufacturer and, if you chose to use one, protected by a strong passphrase.
You can keep this setup or later build a multisig wallet using devices from different manufacturers. Take your time with this choice. Every later move should follow the same process: create a new wallet, back it up, verify the address on the device, send a test transaction, then move the rest.
Five rules that prevent the worst mistakes
Never enter seed words or a passphrase on a website.
Never use an address sent by email, text message, Telegram, WhatsApp, or direct message.
Never send the full balance before a small test transaction succeeds.
Never throw away the old backup before the full balance is confirmed in the new wallet.
Never believe anyone who says they need your seed words to help you.
Detailed Version
Find your situation
| Your situation | What to do | Go to |
|---|---|---|
| Mk2 or Mk3 created the seed on firmware 4.0.0 through 4.1.9; single-signature wallet; no strong passphrase; fewer than 50 dice rolls or unknown | Prepare carefully and move the funds today. | Critical Mk2 or Mk3 wallet |
| Mk4, Mk5, or Q created the seed before the July 31 emergency release; single-signature wallet; no strong passphrase; fewer than 50 dice rolls or unknown | Move the funds as soon as you have a verified destination. Aim to complete the move today. | Affected Mk4, Mk5, or Q wallet |
| You have a hardware wallet from a different manufacturer with a securely generated seed | Use it as the destination after checking its current security notices and setup guidance. | Use another hardware wallet |
| The Coldcard is your only hardware device | Move temporarily to a reputable hot wallet, then set up a hardware wallet from a different manufacturer. | Use a temporary hot wallet |
| The Coldcard is lost or broken and you only have the seed words | Recover the old wallet only long enough to move the funds. | Recover from the backup |
| You used a BIP-39 passphrase | Check how strong it is, then plan the move. | Passphrase users |
| You added at least 50 fair, private dice rolls when creating the seed | Coinkite says this seed is safe from this specific randomness bug. | Dice users |
| The Coldcard is one key in a multisig wallet | Check every key and find out how many may be weak. | Multisig wallets |
| Your bitcoin was acquired without KYC | Prefer a new self-custody wallet if privacy matters. | Privacy and no-KYC bitcoin |
| Bitcoin has already left without your permission | Protect anything left, then save evidence. | If bitcoin was stolen |
Am I affected?
Answer these questions:
Which device created your seed words?
Which firmware was installed when the seed was created?
Did you add at least 50 fair, private dice rolls through Coldcard’s Add Dice Rolls feature?
Did you use a BIP-39 passphrase? This is separate from the Coldcard PIN.
Is the wallet single signature or multisig?
The device that holds the seed today may not be the device that created it. The seed’s origin is what matters.
Affected versions and July 31 release boundaries
| Device and firmware used to create the seed | Relevant release date | What it means |
| Mk1 through version 3.0.6 | Version 3.0.6: December 19, 2019 | Outside this bug according to Block |
| Mk2 or Mk3 through version 3.2.2 | Version 3.2.2: January 14, 2021 | Outside this bug according to Block |
| Mk2 version 4.0.0 through 4.1.9 | 4.0.0: March 17, 2021; 4.1.9: June 26, 2023 | Treat as critically affected |
| Mk3 version 4.0.0 through 4.1.9 | 4.0.0: March 17, 2021; 4.1.9: June 26, 2023 | Treat as critically affected. Coinkite begins its warning at 4.0.1, released March 29, 2021. Block also includes 4.0.0. |
| Mk4 or Mk5 before standard firmware 5.6.0 | Version boundary 5.6.0: July 31, 2026 | Affected |
| Mk4 or Mk5 before Edge firmware 6.6.0X | Version boundary 6.6.0X: July 31, 2026 | Affected |
| Q before standard firmware 1.5.0Q | Version boundary 1.5.0Q: July 31, 2026 | Affected |
| Q before Edge firmware 6.6.0QX | Version boundary 6.6.0QX: July 31, 2026 | Affected |
These dates show when Coinkite released each version. They cannot prove which firmware was installed when a particular seed was created. Check the version on the device and any records you kept. If you remain unsure, treat the seed as affected.
Coinkite used the following July 31 releases as the boundaries for identifying older affected seeds:
Mk3: 4.2.0 or later, released July 31, 2026
Mk4 and Mk5, standard firmware: 5.6.0 or later, released July 31, 2026
Mk4 and Mk5, Edge firmware: 6.6.0X or later, released July 31, 2026
Q, standard firmware: 1.5.0Q or later, released July 31, 2026
Q, Edge firmware: 6.6.0QX or later, released July 31, 2026
Standard and Edge are different release tracks. The version numbers above help identify whether a seed was created during the affected period. They are not a recommendation to install those releases. Users have reported devices becoming unusable after installing the emergency firmware. Coinkite has not publicly confirmed a widespread defect. Because the update cannot repair an existing weak seed, this guide uses another manufacturer for the replacement wallet.
TAPSIGNER, OPENDIME, and SATSCARD use different software and are not part of this incident.
Common situations that cause confusion
You updated the Coldcard after creating the wallet. The old seed keeps the weakness it had when it was created.
You restored the Coldcard seed on another hardware wallet. Moving the same seed to another device does not make it stronger.
You need to move the bitcoin from an affected Coldcard. You can still use it to sign the outgoing transaction. Do not update, wipe, or reset it before the funds have moved. Do not use it to generate the replacement seed.
You created the seed securely somewhere else and later imported it into a Coldcard. This bug did not weaken that seed because the Coldcard did not create it.
You used BIP-85 to create child seeds from an affected master seed. Treat the child seeds as affected too.
You created other secrets on vulnerable firmware. Paper-wallet keys, some Seed XOR values, cloning keys, Key Teleport keys, and other features may have used the same weak randomness. Review the other affected features in Block’s report.
You cannot remember the firmware version or number of dice rolls. Treat the seed as affected.
How quickly should I act?
Nobody can give you a guaranteed number of safe hours or days. An attacker can search for weak seeds without connecting to your wallet. They can spend the bitcoin as soon as they find a funded seed.
1. Critical Mk2 or Mk3 wallet
This is the highest-risk group. Affected Mk2 and Mk3 seeds had about 40 bits of effective randomness. That is low enough for a well-funded attacker to search.
The July 30 thefts mainly came from single-signature wallets in this group. Prepare a verified destination and move the funds today. Slow down long enough to confirm the backup, wallet fingerprint, receiving address, and test transaction.
2. Affected Mk4, Mk5, or Q wallet
Coinkite estimates that these affected seeds had about 72 bits of randomness. They are harder to search than affected Mk2 and Mk3 seeds. They still fall far below the level expected from a secure seed.
Treat the wallet as unsafe for meaningful savings. Move the funds as soon as a verified destination is ready. The first thefts focused on older models. This does not make the newer models safe.
3. You used a BIP-39 passphrase
A passphrase creates a separate wallet from the same seed words. An attacker who finds the weak seed must also guess the exact passphrase.
Your protection depends on the passphrase:
Names, dates, quotations, song lyrics, common expressions, keyboard patterns, and reused passwords are weak.
Several words chosen by a person are often weaker than they appear.
Six or seven words chosen randomly with dice from a large word list provide strong protection.
A fresh 12-word phrase generated by a trusted wallet provides very strong protection when the random generator works correctly.
Move urgently if the passphrase is short, reused, or created from memory. A long, random, unique passphrase gives you more time to prepare. Coinkite still recommends moving to a new seed.
Each passphrase opens a different wallet. If you used several passphrases, check and move every balance separately.
4. You added dice rolls
Coinkite says this bug does not put the seed at risk when all of the following are true:
You used Coldcard’s Add Dice Rolls feature before accepting the final seed words.
You added at least 50 rolls from a fair six-sided die.
The rolls were random and private.
Nobody recorded, photographed, or watched the rolls.
Fifty to 98 rolls provide at least 128 bits of randomness from the dice. Ninety-nine or more provide about 256 bits. Coinkite explains this exception in its advisory.
Treat the seed as affected if you used fewer than 50 rolls or cannot remember the exact process. Create the replacement wallet on a device from a different manufacturer.
5. Your Coldcard is part of a multisig wallet
Multisig requires more than one key to spend bitcoin. A 2-of-3 wallet has three keys and needs any two of them to sign.
Write down your policy, such as 2-of-3 or 3-of-5. Check how every key was created.
In a 2-of-3 wallet with one affected key, the attacker still needs another key. Replace the affected key promptly.
In a 2-of-3 wallet with two affected keys, an attacker may have enough keys to spend. Move the funds immediately.
In a 3-of-5 wallet with one or two affected keys, the attacker does not yet have enough keys. Replace the affected keys soon.
A multisig wallet made only with affected Coldcards may have several weak keys from the same bug. Treat it as urgent.
Replacing a multisig key usually means creating a new multisig wallet and moving the bitcoin to it. Back up the complete wallet setup. This includes all public keys, fingerprints, derivation paths, address type, and the number of signatures required. Casa explains why all public keys are needed to recover a multisig wallet.
Choose where to move the bitcoin
Option A: Use a hardware wallet from a different manufacturer
A hardware wallet from a different manufacturer can serve as the destination. If it already holds a seed that you know was created securely, you may use that wallet. If it is new or empty, generate a completely new seed on it. Check the manufacturer’s current security notices and setup instructions before you begin. The destination must use a different seed. Restoring the affected COLDCARD seed on another device does not make it safe.
The affected COLDCARD can still sign the transaction that moves the bitcoin. This vulnerability concerns how it generated seeds and certain other secrets. Do not update, wipe, or reset it before the transfer. Use it only to sign the outgoing transaction.
Obtain the receiving device through the manufacturer or an authorized seller.
Read the manufacturer’s current security notices and setup instructions.
Generate a completely new seed on the receiving device.
Write down the backup offline.
Add a passphrase only after you understand how to back it up and recover it.
Restart the device and confirm the wallet fingerprint or other wallet identifier.
Create a receive address and verify it on the hardware wallet’s screen.
Send a small test transaction from the affected wallet.
Confirm that the test arrived.
Send the remaining balance. Use send all when available so the old wallet keeps no change.
Check every account, address type, and passphrase wallet connected to the old seed.
Option B: The Coldcard is your only hardware device
Do not try to create the replacement wallet on the same COLDCARD. Use a reputable hot wallet as a temporary destination while you obtain a hardware wallet from a different manufacturer.
Confirm that the affected COLDCARD still opens and can sign. Do not update, wipe, or reset it.
On a clean, updated phone or computer, download a reputable wallet from its official website or official app-store page.
Create a completely new wallet in the app. Write down its seed words offline.
Close and reopen the app. Confirm that you can access the new wallet and its receive address.
Copy a receive address from the temporary wallet and check every character you can reasonably verify.
Send a small test transaction from the affected COLDCARD wallet.
Confirm that the test arrived in the temporary wallet.
Send the remaining balance. Use send all when available.
Check every account, address type, and passphrase wallet connected to the affected seed.
Keep the old COLDCARD backup until the full balance is confirmed. Then mark it COMPROMISED AND RETIRED.
Obtain a hardware wallet from a different manufacturer and create another completely new seed on it.
Verify a receive address on the new hardware wallet’s screen. Send a small test transaction from the temporary wallet, confirm it, then move the rest.
The temporary wallet seed has been exposed to a phone or computer and should not protect long-term savings. Retire it after the final transfer is confirmed.
Option C: The Coldcard is unavailable
If the device is lost or broken, use the seed backup only long enough to move the funds. Restore the affected seed in a reputable software wallet on a clean device, then send the bitcoin to a separate wallet with a completely new seed. A hardware wallet from a different manufacturer is the preferred destination.
A reputable software wallet can help in an emergency when waiting for new hardware creates more risk. Sparrow and Electrum are common Bitcoin-only choices.
If you use software:
Use a clean, fully updated computer.
Download the wallet from its official website.
Verify the download using the project’s instructions.
Enter the seed only inside the installed wallet application.
Check that the addresses and transaction history match your old wallet.
Send the full balance to a new secure destination.
Remove the affected seed from the software wallet after the move.
Never use an online seed checker. A seed entered on a phone or computer should not become your long-term savings wallet. Generate the final wallet seed on secure hardware.
Protecting the privacy of no-KYC bitcoin
You can move bitcoin between two wallets you control without providing identity documents. The move will still appear publicly on the Bitcoin network.
If privacy matters:
Move the bitcoin to a new self-custody wallet that you control.
Keep separate sources of bitcoin separate when you know how to use coin control. Spending several pieces of bitcoin together can show that they belong to the same person.
Use a new receiving address for every transfer.
Verify every address on the receiving hardware wallet’s screen.
Use your own node or your usual private connection if it is already working. An emergency is a poor time to learn new privacy software.
Protect the funds first. A simple, verified transfer is safer than a rushed privacy process you have never used. Avoid unknown mixing services and anyone who contacts you offering private recovery help.
Unchained offers assisted 2-of-3 multisig, but it requires identity verification and currently accepts only clients with a U.S. residential address. Casa offers assisted multisig and says its vault service does not require identity documents. Buying or selling through a partner may require KYC. Check each company’s current eligibility rules, terms, and privacy policy before signing up.
Check the new wallet before moving the full balance
Use this checklist:
- The destination uses a completely new seed.
- The seed was created on a hardware wallet from a different manufacturer and is not tied to the affected COLDCARD seed.
- The words are written down offline and in the correct order.
- The passphrase is strong, unique, and recorded exactly.
- The seed and passphrase are stored separately.
- The device shows the expected wallet fingerprint after a restart.
- The receiving address matches the address shown on the hardware wallet screen.
- A small test transaction arrived.
- You checked the amount, fee, destination, and change on the signing device.
- The final transaction leaves no bitcoin in the affected wallet.
- You checked every account, address type, and passphrase wallet tied to the old seed.
- The final balance is confirmed before you retire the old backup.
A compromised computer can replace an address copied to the clipboard. Trust the address shown on the receiving hardware wallet’s screen.
What is a BIP-39 passphrase?
A BIP-39 passphrase is an extra secret used with the seed words. Together, they open a separate wallet. The passphrase is sometimes called a “25th word,” although it can contain several words. It is separate from the Coldcard PIN.
Every passphrase opens a valid wallet. The Coldcard cannot warn you about a typo. One missing space or changed capital letter opens a different wallet that will usually appear empty.
You need both the seed and the exact passphrase to recover the bitcoin. Losing either one can make the funds impossible to access.
A simple way to create a strong passphrase
If the new hardware wallet supports a BIP-39 passphrase of this length, including spaces, you can use a fresh 12-word phrase generated by BlueWallet as the passphrase. These words provide about 128 bits of randomness when the phone’s random generator works correctly.
Download BlueWallet from its official website or official app-store page.
Create a new Bitcoin wallet.
Write down the 12 words in their exact order.
Keep this BlueWallet wallet empty. Never use the seed from a wallet that holds or previously held bitcoin.
Enter all 12 words on the new hardware wallet as the BIP-39 passphrase. Use one space between each word.
Label the backup PASSPHRASE. These words are not the hardware wallet’s seed.
Store the passphrase offline and in a different place from the hardware wallet’s seed.
Confirm the wallet fingerprint created by the seed and passphrase.
Test a complete recovery before moving a meaningful balance.
Delete the empty wallet from BlueWallet after the backup and recovery test are complete.
Do not keep a screenshot, digital photo, cloud note, email, or clipboard copy of the words.
This method shows the passphrase on a phone connected to the internet. Malware on the phone could record it. The phrase gives strong protection when it is created on a clean phone, recorded correctly, and kept separate from the new seed.
For a large balance, you can generate the passphrase offline. Six or seven words selected with physical dice from the EFF long word list provide about 77 or 90 bits of randomness. Another hardware wallet can also generate a fresh 12-word phrase without showing it on a phone or computer.
Do not invent the passphrase yourself. People tend to choose words and patterns that computers can guess. Keep a physical backup even if you memorize it.
How should I store the new backups?
For a single-signature wallet with a passphrase:
Write the seed words on paper or a durable metal backup.
Keep a second protected copy in another safe location if fire, theft, or a natural disaster could destroy the first.
Store the passphrase separately and keep its own backup.
Label each item clearly.
Record the wallet fingerprint and simple recovery instructions.
Test recovery before depositing a large amount.
Make sure your heirs can eventually find both secrets without storing them together today.
Do not store seed words or passphrases in photos, cloud notes, emails, shared documents, or unencrypted files.
A multisig wallet needs a different backup plan. Keep a backup for every key. Also save the full wallet setup, including public keys, fingerprints, derivation paths, address type, and number of signatures required.
Should I install the COLDCARD emergency firmware?
This guide does not recommend installing it at this time. Some users have reported that COLDCARD devices became unusable after installing the July 31 emergency firmware. A firsthand Mk4 report describes a crash during passphrase use, followed by a device that displayed BRICKED after restarting. Coinkite has not yet publicly confirmed a widespread firmware defect.
The firmware update cannot repair a seed that was created with weak randomness. The urgent task is to move the bitcoin to a completely different seed. An affected COLDCARD can still sign that outgoing transaction, so updating it first adds an avoidable operational risk.
Move the funds to a wallet created on a device from a different manufacturer. If that device is not available, use a reputable hot wallet temporarily. Once the balance is secure, keep the empty COLDCARD and its backup unchanged while you wait for a clear response from Coinkite and further independent review.
Can I trust hardware wallets again?
Hardware wallets keep private keys away from everyday phones and computers. Their screens let you check receiving addresses and transaction details before signing. This Coldcard incident shows that hardware wallets still depend on correct firmware and secure seed generation.
A safer setup includes:
A hardware wallet from a different manufacturer whose current security notices you have reviewed
A completely new seed generated by that device
Independent dice entropy when you know how to add it correctly
A strong passphrase with a tested backup
Address and transaction checks on the hardware screen
Multisig with devices from different manufacturers for large balances
A recovery test completed before an emergency
Choose a setup that you can understand, back up, and recover. Complexity can create its own mistakes.
What is multisig, and when should I use it?
A single-signature wallet needs one key to spend. A 2-of-3 multisig wallet has three keys and needs any two of them. One stolen key cannot spend the bitcoin. One lost key still leaves two keys for recovery.
Consider multisig when losing the balance would change your life, harm your family, or damage a business. It also works well for shared company funds and inheritance plans.
Multisig requires more work:
More devices and higher setup cost
More steps when sending bitcoin
Larger transactions and sometimes higher fees
A complete backup of the wallet setup
A clear inheritance plan
Regular checks that the keys and instructions still work
A common setup is 2-of-3 with devices from different manufacturers in separate secure locations. Practice the full setup with a small amount before trusting it with long-term savings.
Unchained, Casa, or DIY multisig?
| Option | What it does | Main benefit | Main risk or cost |
| Sparrow DIY 2-of-3 | You build and manage the multisig wallet | Full control and no service provider holds a key | You must set up, document, and recover everything yourself |
| Unchained | Assisted 2-of-3 vault; you hold two keys and Unchained holds one backup key | Guided setup, help if one key is lost, inheritance support, and recovery without Unchained using your two keys | Annual cost, identity verification, a U.S. residential-address requirement, and some wallet information shared with the service |
| Casa | Assisted 2-of-3 or 3-of-5 wallets; Casa holds one recovery key | Setup help, key checks, and an independent recovery process | Subscription cost and an ongoing service relationship |
Unchained and Casa cannot spend from their standard multisig vaults with only the key they hold. Both publish ways to recover without their service. See Unchained’s external recovery guide and Casa’s recovery guide.
Confirm which hardware devices will protect each key before setting up either service. For this migration, create your two keys on devices from different manufacturers. Do not reuse the affected COLDCARD seed as one of those keys.
Test the full recovery process before choosing a long-term setup. Assisted custody can reduce setup mistakes. DIY custody gives you more control and requires more skill.
If some or all of the bitcoin has already been stolen
Bitcoin transactions cannot be reversed by the network. You can still protect any bitcoin left and save information that may help trace the stolen funds.
Move every remaining balance tied to the affected seed to a new secure wallet.
Save the transaction ID, receiving addresses, timestamps, screenshots, and the addresses you controlled.
Record the Coldcard model, serial information, purchase source, approximate seed-creation date, firmware used at the time, current firmware, dice process, passphrase use, and wallet software.
Keep the Coldcard and MicroSD cards after the remaining funds are safe. Do not erase possible evidence.
Contact Coinkite through the contact details on its official website.
Report the theft to the proper cybercrime or law-enforcement agency. Include the transaction IDs and saved evidence.
Contact any exchange or service that receives the stolen bitcoin through its official fraud channel. Law enforcement may need to send the formal request to preserve or freeze funds.
Recovery scammers search for victims during incidents like this. They may promise to reverse a transaction, ask for the seed, request payment in bitcoin, or tell you to “synchronize” the wallet. Do not engage with them.
Sources and updates
This guide provides general security information. A complex multisig wallet, business treasury, inheritance plan, or large balance may require help from a qualified Bitcoin security professional. A legitimate professional will never ask for your seed words or passphrase.