- A random number generator flaw in COLDCARD firmware let attackers reconstruct recovery phrases. The tally: 1,367 BTC, about 88.6M USD, from 4,585 addresses.
- A seed phrase has to be protected in two contradictory directions: so you never lose it, and so nobody but you ever reads it.
- A firmware update does not repair a seed that was already generated from weak randomness.
- Paper solves the first problem, a digital legacy mechanism solves the second. The words themselves never go digital.
A seed phrase backup is the weakest point in most crypto wallets. Almost nobody checks whether the copy actually works, and almost nobody leaves a trace that the copy exists at all.
On 30 July 2026, a firmware flaw in COLDCARD hardware wallets, one of the more popular devices for storing bitcoin, let attackers reconstruct their owners' recovery phrases. One attacker emptied 1,196 addresses in 41 minutes. Later waves on 1 August pushed the tally to 1,367 BTC, roughly 88.6M USD, across 4,585 addresses. Nobody clicked a phishing link and nobody lost a device.
What happened with COLDCARD
The firmware had an RNG integration error. Instead of the hardware RNG in the STM32 chip, the device fell back to a software generator, MicroPython's deterministic Yasmarang, seeded with the microcontroller ID and system timing. Neither is a cryptographically secure source of randomness.
That let an attacker generate candidate seeds offline, derive their addresses and compare them against what is visible on the blockchain. A match confirmed the seed, and after that it was just a matter of signing. The bug had been in the code since March 2021, and the attack started roughly 30 hours before the manufacturer disclosed it.
Two weeks earlier ZachXBT wrote on Telegram: "All hardware wallets are complete garbage, and I do not advise using them for important tasks like signing transactions or storing funds". He suggested a dedicated iPhone used only for crypto instead. Trezor answered the next day that he was generalising from the experience of a small group moving large sums. After 30 July that post reads differently.
What does good protection look like?
You have to protect a seed phrase in two directions - unfortunately contradictory ones.
First, you have to secure it so that you do not... forget it. It has to be written down somewhere so you can reach your crypto at any moment. Storing it on a device turns out to be unreliable, so in practice a well hidden sheet of paper does the job.
On the other hand, you do not want anyone besides you to ever read it. But what about your heirs? If something happened to you, it would be better for your crypto to reach someone than to "hang" on the network forever, unrecoverable. So somebody has to find that sheet of paper at the right moment.
There are no official statistics on how much bitcoin died with its owners. Estimates run from 2.3 to 3.7 million BTC and all of them are guesses based on address activity. The problem will only grow, because the first generation of crypto holders is now getting older.
There is a way around it. You can build your own "system" that combines the safety of paper (no digital form, well hidden) with a digital legacy mechanism (which never holds the words themselves). Here is how to do it.
Start by checking whether your seed is already burned
1. Check whether your device is on the list
For COLDCARD this covers seeds generated on Mk2 and Mk3 with firmware 4.0.1 through 4.1.9, Mk4 and Mk5 before version 5.6.0 (Edge 6.6.0X), and Q before 1.5.0Q (Edge 6.6.0QX). If you own another brand, go to its security advisory page. Do it today, not at some point.
2. Do not expect a firmware update to repair an old seed
New software improves how the next keys are generated. A key that was already created from weak randomness stays weak forever. If you were in the affected group, you need a new seed and a move of funds.
3. Generate the new seed so you are not trusting the device alone
Coinkite stated that seeds supplemented with at least 50 fair, independent and private dice rolls are not at risk from this flaw alone. Many wallets let you mix in your own entropy. Use it, because it is five minutes of dice rolling once in your life.
Part one: the sheet of paper you can always reach
4. Write the words on something that survives
Paper is enough if it stays dry and out of the basement. A steel plate survives fire and flooding. What not to do: a phone photo, a note in the cloud, a password manager, an email to yourself, a scan on a drive. Every one of those places will eventually leak or stop being yours.
5. Make two copies in two locations
One copy at home means fire risk and burglary risk at once, and two copies in the same flat are still one copy. A sensible layout: one with you, one in a safe deposit box or with a person you trust unconditionally.
6. Consider a passphrase and keep it separate
BIP39 lets you add an extra word to the phrase. Anyone who finds the paper alone sees an empty or decoy wallet. Roman Storm pointed out that mobile still lacks convenient support for this feature. If you use it, remember: a lost passphrase means lost funds, so it needs its own copy, in a different place from the words.
7. Check your backup before you need it
Manufacturers ship a function for this. Trezor calls it "Check backup" (dry-run recovery) and has had it in firmware since version 1.5.1, Ledger offers the Recovery Check app. You type in the words from the paper, the device compares them with what it holds, and nothing gets wiped. Trezor recommends doing it once a year and before every firmware update.
8. When migrating to a new seed, move funds in stages
Generate the new seed, record the words, verify the address on the device screen and send a small test transaction. Only once it arrives, move the rest. Keep the old copy until everything is confirmed.
Write that you hold crypto, on which device, and where the paper is. Never the words.
Part two: making sure someone finds that paper
9. Write instructions for the person who comes after you
A sheet with 24 words is useless to someone who does not know what a seed phrase is. The instructions have to say that you hold crypto and roughly how much, on which device and in which wallet, where the paper is, whether a passphrase is involved, and who to call for technical help. The words stay on the paper, never in the instructions.
10. Put a review date in your calendar
Once a year: are the copies where they should be, is the material holding up, is the person named in the instructions still the right person, have new wallets appeared.
- The paper exists, but nobody ever checked whether the words were copied without a mistake.
- The passphrase lives in the owner's head and nowhere else.
- The instructions for the family exist in the form of "my wife roughly knows".
- The heir gets the words, types them into a bitcoin wallet and sees nothing from another chain, because derivation paths differ.
- Crypto made it into the will with no information on how to physically get to it. A legal clause does not replace technical access.
- There is a safe deposit box, but after the owner's death nobody has title to it.
What a digital legacy mechanism is
Steps 1 through 8 you do alone, with paper and a device. Step 9 is harder, because the information has to reach someone at a moment nobody can schedule: not too early and not too late. Too early means someone has your crypto today. Too late means nobody has it at all.
That is what digital legacy apps are for. You record what you hold and where to look for it, you name the person who should receive it, and the app asks from time to time whether everything is fine on your end. If you stop answering, the person you named, confirmed by your trusted contacts, gets secure access to what you chose to share.
When choosing an app, check where the data physically sits. In LegacyApp the notes stay on your phone and the encrypted copy goes to your own Google Drive or iCloud, never to the operator's servers. Check the encryption too (AES-256, GDPR compliance) and whether you are the one deciding who gets access and when.
The rule holds on both sides of the system. In the app you record where to look and what to do with it. The words themselves have no digital form and stay on the paper.
A hardware wallet protects your crypto from the entire world, your family included. A hidden sheet of paper plus a mechanism that shows someone where to find it at the right moment does more for your money than another device.
Questions & answers
The short version, for people (and assistants) in a hurry.
Do hardware wallets still make sense after COLDCARD?
Yes. For most people they remain the strongest available form of self-custody. What changes is how much trust you place in the device itself: your own entropy at seed generation and a verified backup limit the damage from a manufacturer's mistake.
Is a firmware update enough?
No. It improves how new keys are generated, but a seed created earlier from weak randomness has to be replaced and the funds moved to a new wallet.
Is a dedicated phone a better idea than a hardware wallet?
ZachXBT thinks so. Trezor replied that a phone has Wi-Fi, Bluetooth, iMessage and cellular, meaning more ways in than a device with no connectivity, and that a separate screen for verifying transactions is worth the inconvenience. For most people Trezor's argument lands harder, though at large sums nobody serious stays with a single device.
Paper or steel?
Steel, if the amount matters to you. Paper works until there is a fire, a flood or damp. Both beat a photo on your phone.
Can I put my seed phrase in my will?
Bad idea. Once probate opens, the will becomes available to the parties, and before that it sits with a lawyer. What goes in the will is the information that the assets exist and where to look for the instructions. The words stay offline. For larger amounts, discuss it with your lawyer or notary.
What happens to my crypto if nobody finds the paper?
Nothing. It stays on the blockchain forever, visible and out of reach. There is no institution that can unlock it.
How often should I check the backup?
Once a year, and after every change: a new wallet, a move, a different trusted person, a larger purchase.
Paweł Soproniuk - CEO of LegacyApp, a digital legacy app. Author and speaker at numerous events on digital inheritance, entrepreneur and lecturer. More about the team | LinkedIn


