This week a hardware wallet brand Coldcard had an exploit that sent shockwaves through the community. A vulnerability in its entropy (randomness) generation algorithm allowed malicious bots to predict (or crack) seed phrases, leading to millions of $$ in stolen Bitcoin.

Users of Colcard had the worst day in their lives yesterday when they woke up to see their wallets completely drained. One user shared on X his story of losing $1.7m to this exploit. Others had similar and even larger amounts stolen in minutes.

The problem is, every single one of those users did nothing wrong. They followed the instructions, they kept their coins offline, they kept them protected with a hardware device, so nobody can hack them, and yet, their wallets were drained in just minutes.

Here is what happened with Coldcard and how you can protect yourself from any such issues in the future.

What Happened

Just yesterday automated (AI) “sweeper” bots executed a coordinated on-chain attack that drained over 1,000 Bitcoin addresses—totalling an estimated $70M+ in stolen Bitcoin.

The attack targeted single-signature Coldcard wallets whose seed phrases had been auto-generated directly on affected device models (Mk3, Mk4, Mk5, and Q) running firmware released between March 2021 and July 2026.

How It Happened (The Technical Flaw)

1. Silent Software Fallback

During a major firmware overhaul in March 2021, a code configuration check was misconfigured. Instead of pulling true physical randomness from the device’s STM32 Hardware Random Number Generator (TRNG), the device silently defaulted to a basic software Pseudo-Random Number Generator (PRNG) built into MicroPython.

2. Drastic Loss of Entropy

Because the software fallback relied primarily on internal processor timer states and unique hardware IDs without gathering fresh entropy, the randomness behind newly generated wallet seeds was severely degraded:

  • Intended Standard: 128 bits of entropy (making guessing mathematically impossible).
  • Flawed Reality: Effective entropy dropped to roughly 40 bits (on Mk3) and 72 bits (on Mk4/Mk5/Q).

3. Offline Enumeration & Automated Sweeping

A 40-to-72 bit entropy range is small enough that high-performance computers can calculate the potential seed phrase combinations offline. Attackers generated these predictable candidate seeds, derived their public Bitcoin addresses, matched them against active balances on the Bitcoin blockchain, and signed automated transactions to sweep the funds.

Who Was Safe vs. Who Was Vulnerable

  • Vulnerable: Anyone who created a brand-new seed using the default automated wallet creation on an affected Coldcard firmware without adding manual randomness.
  • Safe:
    • Users who created their seed using manual dice rolls (50+ physical rolls supplied enough true entropy to overwrite the flawed PRNG).
    • Users who protected their funds with a custom BIP-39 Passphrase (25th word).
    • Multi-signature (Multisig) wallet arrangements.

While fixing firmware or rolling physical dice helps patch a specific product, single-point failures in hardware architecture prove that true security requires a broader strategy. The real takeaway isn’t just updating software—it’s migrating to superior security architectures and diversifying your custody. To avoid single-vendor risks, switch to hardware wallets built around full transparency or true offline isolation. Some users prefer airgapped devices like Ellipal’s Titan 2.0 (I am a big fan of it and use mine a lot) and others insist on open-source devices, like Onekey or Trezor (I use both). But neither of these two factors play into what happened to Coldcard users yesterday. The seed phrase problem affected anyone who trusted the random generator of their device and this is where you have another solution.

The Ultimate Defense: The BIP-39 Passphrase (The “25th Word”)

The single most effective defense against seed-level vulnerabilities, including predictable PRNG bugs like Coldcard’s, is implementing an additional custom passphrase (often referred to as a 25th word).

How It Works

  1. Your hardware device generates standard 12 or 24 recovery seed words according to the BIP-39 standard.
  2. On devices like the Ellipal Titan, you can toggle on the Passphrase feature during setup. You enter a secret word, phrase, or character sequence of your choice.
  3. The wallet software mathematically combines your 12 (or 24) words plus your custom passphrase to create a completely unique master key.

This is the only method so far, that would have saved any of those users who woke up to see their wallets emptied.

Why This Guarantees Maximum Security

  • Renders Predictable Seeds Useless: Even if an attacker uses supercomputers to guess a flawed 24-word seed phrase generated by a weak algorithm, they cannot access your funds without the exact passphrase. Adding even a simple passphrase shifts the cryptographic address to an entirely different location on the blockchain.
  • Protection Against Physical Theft: If someone finds your written 24-word backup sheet in real life, your funds remain safe because your secret 25th word is stored separately (ideally memorized or kept in a different location).
  • Plausible Deniability: Ellipal allows you to attach different passphrases to the same recovery seed, creating distinct wallets. Entering a dummy passphrase unlocks a “decoy” account with minimal funds, keeping your main stash hidden under a secondary passphrase.

I won’t go into too many details on what the Ellipal Titan 2.0 is because I have a detailed review of this device (I’ve been using it for several years now) so just go to this post to find out all about it.

And there’s another thing I do, that most people overlook and that I strongly recommend:

Diversify: Never Put All Your Capital in One Wallet

Single-wallet dependency is a massive systemic risk. Even the best hardware can suffer physical damage, firmware flaws, or supply-chain compromises.

The golden rule of self-custody is asset distribution.

Split your holdings across multiple distinct wallets rather than consolidating everything into one seed. Use a mix of air-gapped security for long-term cold holdings (like Ellipal) and open-source models for active transactions (like OneKey). Should one vendor or seed ever suffer a compromise, the vast majority of your wealth remains completely untouched.

You can also download my eBook guide to all major crypto wallets – hot and cold, I talk about the differences between these, which ones I recommend from my personal experience and I go through all of the top hardware wallets there, so you can make the right choice which is the wallet for you. It’s a free eBook, just get it from this link.

Stay informed and level up your crypto strategy

👉Go to LearnCryptoNow.com for free guides, tutorials and all things crypto

👉 www.LearnCryptoNow.com

Disclaimer: This article is for informational purposes only and does not constitute financial advice. The content of this post reflects solely my own opinions. Purchasing cryptocurrencies poses considerable risk of losses.


Metamask Is Tracking Your IP and Wallet Address…

CRYPTO CORNER EPISODE 558 Market Analysis, Updates, News & Reviews In today’s episode I discuss the latest hot topics in crypto: ►Metamask Controversy – Is your Wallet Addy being Linked To Your IP Address?  ►How To Earn Bitcoin using the Bitget Launchpool (4 days left only, hurry up) ►Win A Hardware Wallet Device from Keystone…

Steel Plates For Seed Phrase Protection | xSeed Plus Review

CRYPTO CORNER EPISODE 449 Market Analysis, Updates, News & Reviews In today’s episode I review my latest purchase – the metal back up for my seed/mnemonic phrases by SecuX. This is a complete kit containing: 3x Stainless steel plates1x Aluminium plates1x Metal letter stamps A to Z1x Engraving pen2x Fraudproof security stickers1x Plate Holder (leather…

My crypto wallet got hacked. All funds gone.

After being in crypto for the last 5 years, today I found out that I became a victim of a cyber attack. A wallet hack to be more precise. I haven’t used my Exodus wallet in many months, possibly more than 8 months actually, so I had a bit of a shock today, when I…

Leave a comment