Insights Crypto Coldcard seed migration guide: How to avoid theft
post

Crypto

06 Aug 2026

Read 15 min

Coldcard seed migration guide: How to avoid theft *

Coldcard seed migration guide helps you update devices and securely replace predictable seeds now.

Use this Coldcard seed migration guide to protect your Bitcoin after the recent wallet flaw. Update firmware, create a new high-entropy seed, add a passphrase, and move funds with an air‑gapped workflow. Follow the steps below to test, migrate, and safely retire your old backups. Hackers have stolen more than $130 million in Bitcoin by abusing a bug in certain Coldcard hardware wallets. Security teams at Galaxy Research and Elliptic say multiple groups may be involved. Researchers at Block found that a line of code from 2021 led to predictable seed generation on affected devices. Coinkite, the Coldcard maker, has told users to update firmware and move funds to a new seed. If you use a Coldcard and created your seed on a vulnerable version, you should act now. Offline wallets are meant to be safe. They keep your keys off the internet. But if the device made a weak or predictable seed, your coins are at risk even if you never shared the phrase. The fix is simple in idea but careful in practice: update, generate a new seed with strong randomness, test, and migrate. This guide shows you how.

What happened and why you must move

Coldcard devices store your secret recovery phrase (seed) offline and sign transactions without exposing keys. That model is sound. The problem here was seed creation. According to researchers at Block, a fallback in the random number system and a 32-bit reseed path made some seeds more predictable. Attackers learned how to guess these seeds and drained wallets. TRM Labs reports more than 200 crypto hacks this year, with losses near $1 billion. The Coldcard thefts stand out because victims did not act carelessly. Many kept seeds in safes and never put devices online. Still, the original seed was weak. If your seed was made on affected firmware, the only fix is to move funds to a brand-new, high-entropy seed that you generate after updating.

Coldcard seed migration guide

Before you start

– Who should migrate: Anyone who created their Coldcard seed on a firmware version flagged by Coinkite’s advisory. If you are unsure, migrate. – What you need:
  • Your Coldcard and a fresh microSD card
  • Access to a trusted computer for downloads and a watch‑only wallet
  • Pen and paper or a metal backup plate
  • Time and a quiet place. Do not rush.
  • If you suspect active theft, move a small amount first to confirm the workflow, then migrate the full balance as soon as you can.

    Step 1: Update your firmware safely

    – Download the latest firmware from Coinkite’s official website using a trusted internet connection. – Verify the download per the vendor’s instructions. Check hashes or signatures if provided. – Copy the firmware file to a clean microSD card. – Insert the card into your Coldcard and run the update from the device menu. – Confirm on-device that the version matches the latest release notes. Do not install files from forums, mirrors, or emails. Only use the official site.

    Step 2: Create a new seed with strong entropy

    – On the updated Coldcard, choose to create a new wallet/seed. – Add extra randomness with the built‑in dice roll method. Roll physical dice many times (for example, 50–100 rolls) and input the results. More rolls mean more entropy. – Write the 12 or 24 words clearly on paper or stamp them into metal. Store two to three copies in separate, secure places. – Optional but recommended: Add a BIP39 passphrase (often called the 25th word). This protects you if someone later finds your seed words. Memorize it and store a written hint in a separate location. Losing the passphrase means losing funds. Never photograph your seed or passphrase. Never type them on a phone or computer.

    Step 3: Set up a watch‑only wallet

    – Export a watch‑only file (like an xpub or descriptor) from the Coldcard to the microSD card. – Import that file into a trusted desktop wallet that supports watch‑only mode. – This lets you see your new receive addresses and balances without exposing private keys. Watch‑only mode helps you confirm addresses and transactions on a larger screen while keeping keys offline.

    Step 4: Run a small test

    – Use the watch‑only wallet to generate a new receive address. – Confirm the address on the Coldcard screen. The device display is the source of truth. – Send a small amount of BTC from your old wallet to this new address. – Wait for confirmations. Verify the deposit on at least two public block explorers. If the test works, you are ready for full migration.

    Step 5: Migrate your full balance with PSBT

    – Create a Partially Signed Bitcoin Transaction (PSBT) in your watch‑only wallet that spends from your old wallet to your new addresses. Use reasonable fees to confirm the same day. – Save the PSBT to the microSD card. – Insert the card into the Coldcard. Review the transaction details on the device screen: inputs, outputs, amounts, and change address. – Sign the PSBT on the Coldcard. It will write a signed version back to the card. – Bring the card to your computer and broadcast the signed transaction using your wallet software. – Verify on the device and on explorers that the funds arrive at your new addresses. PSBT keeps your keys offline the whole time. Do not plug your Coldcard into a networked computer if you can avoid it.

    Step 6: Retire the old seed

    – Move all funds off the old seed. Do not leave dust or small UTXOs behind. – Wipe the Coldcard wallet that held the old seed after you confirm the migration on-chain. – Destroy old paper backups. If you used metal, repurpose or securely store it after fully removing old data. – Keep monitoring the old addresses for at least 30 days to catch any stragglers or change outputs you may have missed. Once you migrate, never reuse the old seed or its passphrase.

    Extra protections after migration

    Use a BIP39 passphrase

    A passphrase adds a second lock to your wallet. An attacker would need both the 24 words and the passphrase to spend. Choose a memorable but strong phrase. Write it down in a different place than your seed. Practice entering it on the device before you fund the wallet.

    Consider multisig with diversity

    A 2-of-3 multisig can reduce single-device risk. Place keys on devices from different vendors and store them in different places. Keep a watch‑only descriptor so you can verify addresses. Multisig adds steps, so test your recovery process before moving large funds.

    Backup hygiene

    – Use archival‑grade paper or metal plates for seeds. – Seal backups in tamper‑evident bags and label them with date and wallet type. – Store copies in separate sites, like a safe at home and a bank box. – Keep an access plan for family or business partners if something happens to you.

    Supply chain and storage

    Buy devices from the maker or an approved reseller. Inspect packaging. Update firmware before creating a seed. Keep your device offline when possible and use microSD for PSBT. Do not disclose your wallet brand, balance, or storage details on social media.

    Monitoring and response

    Set up address tracking in your watch‑only wallet. Use block explorers that offer alerts. If you ever see strange activity, move funds to a fresh wallet at once. Treat any sign of tampering as a full compromise and migrate again.

    Common mistakes to avoid

  • Reusing the old seed after migration
  • Typing your seed or passphrase on a computer or phone
  • Skipping firmware verification and installing files from untrusted sources
  • Sending funds to an address that was not confirmed on the device screen
  • Keeping photos or cloud copies of seed words
  • Not testing with a small amount before moving everything
  • If you cannot access your device

    If your Coldcard is lost or broken, you can recover with your 12/24 words and passphrase on another trusted hardware wallet or an air‑gapped computer running reputable wallet software. Do this in a safe place. After you recover, create a new high‑entropy seed on a patched device and migrate again. Avoid entering your seed on an internet‑connected machine unless it is an emergency, and move funds to a new wallet as soon as possible.

    Final checks and timeline

    Within 24 hours: update firmware, create a new seed with dice entropy, set a passphrase, and run a small test transaction. Within 72 hours: complete the full migration using PSBT, confirm on chain, and wipe the old wallet. For the next 30 days: monitor both old and new addresses, back up labels and descriptors, and review your storage plan. The recent thefts show that “offline” does not always mean “safe.” Strong processes matter. Use the steps in this Coldcard seed migration guide to update, generate a truly random seed, test transfers, and move your Bitcoin without exposing keys. Stay alert, keep clean backups, and revisit your setup after each major firmware release. (p Source: https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/)

    For more news: Click Here

    FAQ

    Q: What caused the recent Coldcard wallet thefts and why must I migrate my seed? A: Researchers at Block found a flaw in how affected Coldcard devices generated seed phrases – a fallback in the random number system and a 32-bit reseed path – that made some seeds predictable and allowed attackers to brute-force keys, with firms estimating around $130 million stolen. Coinkite has urged users to update firmware and migrate to a new seed, so follow the Coldcard seed migration guide to update, generate a high-entropy seed, test the workflow, and move funds safely. Q: Who should migrate their Coldcard seed right away? A: Anyone who created their Coldcard seed on a firmware version flagged by Coinkite’s advisory should migrate. If you are unsure whether your device was affected, migrate to a new, high-entropy seed to eliminate the risk. Q: How do I safely update my Coldcard firmware? A: Download the latest firmware from Coinkite’s official website using a trusted internet connection and verify the download per the vendor’s instructions (check hashes or signatures if provided). Copy the firmware file to a clean microSD card, insert it into your Coldcard, run the update from the device menu, and confirm the on-device version matches the latest release notes. Do not install files from forums, mirrors, or emails; only use the official site. Q: What is the recommended process to create a new seed with strong entropy on an updated Coldcard? A: On the updated Coldcard, create a new wallet/seed and add extra randomness using the built-in dice-roll method, for example rolling physical dice many times (the guide suggests 50-100 rolls). Write the 12 or 24 words clearly on paper or stamp them into metal and store two to three copies in separate secure locations, and consider adding a BIP39 passphrase as an extra layer of protection. Never photograph your seed or type it on a phone or computer, and this step is part of the Coldcard seed migration guide. Q: Why set up a watch-only wallet and how is it used in the migration? A: Export a watch-only file (like an xpub or descriptor) from the Coldcard to the microSD card and import it into a trusted desktop wallet that supports watch-only mode. This lets you view new receive addresses and balances without exposing private keys and helps you confirm addresses and transactions on a larger screen while keeping keys offline. Q: How should I run a test transfer before moving my full balance? A: Use the watch-only wallet to generate a new receive address and confirm the address on the Coldcard screen, then send a small amount from your old wallet to that address and wait for confirmations. Verify the deposit on at least two public block explorers, and if the test works proceed to the full migration. Q: What is the recommended method to migrate the full balance while keeping private keys offline? A: Create a PSBT in your watch-only wallet that spends from your old wallet to your new addresses, save the PSBT to a microSD card, and insert it into the Coldcard to review inputs, outputs, amounts, and change on the device screen. Sign the PSBT on the Coldcard, bring the card to your computer to broadcast the signed transaction using your wallet software, and verify on-chain that the funds arrive at your new addresses while keeping keys offline. Q: After migration, how should I retire the old seed and what timeline should I follow? A: Move all funds off the old seed, wipe the Coldcard that held it after confirming the migration on-chain, destroy old paper backups or securely repurpose metal backups, and monitor the old addresses for at least 30 days to catch any stragglers. The Coldcard seed migration guide lays out a timeline: update firmware, create a new seed with dice entropy, set a passphrase and run a small test within 24 hours, complete the full PSBT migration within 72 hours, and monitor both old and new addresses for the following 30 days.

    * The information provided on this website is based solely on my personal experience, research and technical knowledge. This content should not be construed as investment advice or a recommendation. Any investment decision must be made on the basis of your own independent judgement.

    Contents