EMERGENCY BITCOIN UPDATE: Coldcard Attack Explained | Rob Hamilton artwork

EMERGENCY BITCOIN UPDATE: Coldcard Attack Explained | Rob Hamilton

What Bitcoin Did

July 31, 2026

“This is as code red as it can get for Bitcoin self-custody.” Rob Hamilton joins me for an emergency episode on the catastrophic Coldcard entropy bug that has exposed Bitcoin held in wallets generated on affected firmware.
Speakers: Danny Knowles, Rob Hamilton
**Danny Knowles** (0:02)
Rob Hamilton, damn man, crazy, crazy 24 hours. We have a legitimate emergency in Bitcoin. What's been going on?

**Rob Hamilton** (0:11)
In the spirit of emergency, I'm just going to start this with, if you or anyone you know has used a Coldcard, MK3, MK4, MK5, Q, any of those devices with any wallets that were generated from the device, you clicked, give me some seed words.
You need to immediately stop what you're doing and contact friends. This is a canceling of weekend plans. This is getting on planes for any ability for you to be able to recover your Bitcoin. This is as about as code red as it can get for Bitcoin self-custody as it relates to the urgency in which you need to act.
I will go more into the details. With that urgency, I want to caution. Slow is smooth, and smooth is fast. So you need to act very decisively, and you need to be able to act deliberately. You should reach out to your friend networks and people that can help you support any questions you may have. But time is of the essence right now.

**Danny Knowles** (1:20)
So maybe we should just start with what happened.

**Rob Hamilton** (1:24)
Stop your podcast if you have to. Like you need to stop, but you can keep on going now. This is not a drill. Continue.

**Danny Knowles** (1:31)
And so I obviously first saw this pop up on Twitter yesterday.
I actually had a Coldcard Mark 4 that was using almost like a spending wallet, but the amount in there had got to a point where I was very uncomfortable. As soon as I saw this news, I text you being like, I've seen this thing with the Mark 3, is it overblown or do I need to do something? And again, you were like, this is not a drill, you need to do something now. I wasn't with my wallet, managed to sort that out. But this is like a serious product, a serious problem that's impacting a ton of people. Where did it all start?

**Rob Hamilton** (2:01)
So in early of 2021, there was a change to the Coldcard firmware as it relates to the entropy that gets created. And that is when a bug was introduced. Now, since I will take a moment to explain the nature of the problem. If you had an air-gapped wallet, never talked to the internet, it doesn't matter. The things that would save you, if you were using a Coldcard MK3, MK4, MK5, and Q is if you have a sufficiently strong 25th word passphrase. If you also rolled dice or provided your own entropy from outside of the Coldcard, the nature of this bug is that when you turn on a Coldcard, and you have a clean device, and you say, this is amazing, can you please give me some seed words? Those are not secure.
And from that, everything else needs to go down, yeah.

**Danny Knowles** (3:05)
I just want to be really clear so that we don't miss anyone here. You obviously said MK3, 4, 5, or Q. What about the MK1 or 2 if they were on updated firmware and they still generate those keys after 21?

**Rob Hamilton** (3:18)
To my understanding, the MK2 is not supported in any of the impacted firmware. I'd have to go double check. But if you have an MK1 and MK2 technically, the firmware bug that we're talking about has not been introduced because that is long end of life hardware. There aren't updates for that really anymore.
And so if you have an MK2 or MK1, you should not be impacted by this.

**Danny Knowles** (3:41)
Okay. And then I think we should also be really clear on the past phrase because that's essentially a 25th word. At this point, that's the only word really keeping your Bitcoin secure. Is that right?

**Rob Hamilton** (3:51)
If you really only used one word, that is right, which means you are not secure.
You have to assume with what we're discussing right now, is that many attackers, not just one person, there are many attackers right now who are scanning to get the entire table of all possible seed phrases a Coldcard could generate, whether it was 12 words or 24 words, and they are sitting on all of those words, and they are taking all of the low-hanging fruit of single signature keys. My assumption is they're going to move on to other things, but we'll get to that, yes.

**Danny Knowles** (4:26)
And so the passphrase is the only thing keeping it secure. If you've done that, you should still probably move funds, would you agree?

35 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000779344488