Insights Crypto How to migrate Coldcard seed safely to multisig
post

Crypto

15 Aug 2026

Read 14 min

How to migrate Coldcard seed safely to multisig *

how to migrate Coldcard seed into a multisig setup and secure your BTC after the firmware breach now

Here’s how to migrate Coldcard seed safely to multisig in plain steps: set up a brand-new multisig wallet with fresh keys on updated, mixed-vendor hardware, verify addresses on-device, test with a small send, then sweep all funds from your old wallet using PSBT. Back up every seed and descriptor, confirm receipts, and retire old backups. A serious Coldcard firmware bug exposed many wallets made between 2021 and mid-2026. Attackers drained thousands of addresses, stealing roughly 2,100 BTC. At the same time, long-term holders moved about 233,000 BTC—over $15 billion—to safer setups, often multisig. If your seed came from affected firmware, it’s time to move. The guide below explains how to migrate Coldcard seed to a safer multisig wallet without reusing a possibly weak key.

What changed—and why speed matters

A bug in certain Coldcard firmware versions (4.0.1 through 4.1.9) weakened key generation. The device used a poor software random number generator instead of the secure chip. That made some private keys guessable. While only about 2,100 BTC was stolen, on-chain data shows long-term holders shifted about 233,000 BTC to safety within days. This split outcome shows a key lesson: self-custody can adapt fast—if you act. If your seed was generated on those firmware versions, treat it as compromised. Even if you used a strong passphrase, move to a new wallet now. Your goal is simple: build a fresh, robust destination (ideally multisig), then send every coin from the old wallet to the new one.

how to migrate Coldcard seed: a safe plan that works

This is not about importing the old seed into a new wallet. Do not reuse a possibly weak seed. This step-by-step shows how to migrate Coldcard seed by spending funds from the old wallet into a brand-new multisig built with strong entropy.

Step 1: Decide your target

Pick your end state before you move anything:
  • Single-sig on updated hardware (better than staying put, but less robust), or
  • Multisig (best for most long-term holders). A common choice is 2-of-3 or 3-of-5.
  • Multisig spreads risk across independent devices. No single compromised key can drain your wallet.

    Step 2: Choose a multisig layout and tools

    Pick:
  • Threshold: 2-of-3 is simple and strong for most people. Use 3-of-5 for higher redundancy.
  • Devices: Mix vendors. For example, pair an updated Coldcard (new seed only), plus a Ledger/Keystone/Trezor/SeedSigner. Diversity reduces single points of failure.
  • Coordinator: Use reliable software like Sparrow or Specter, or a trusted service like Casa if you want guided setup and health checks.
  • Step 3: Prepare your new keys the right way

    On each device you plan to use in your new wallet:
  • Update to the latest firmware.
  • Generate a brand-new seed on-device. If your device supports adding dice rolls, use them to boost entropy.
  • Optionally set a strong BIP39 passphrase (over 8 random words or 20+ characters). Write it down and store it apart from your seed words.
  • Back up each seed to durable media (steel or archival paper). Label each backup clearly (Key A, Key B, etc.).
  • Export the xpub or output descriptor by air-gap (QR or microSD), not by typing seed words anywhere.
  • Important: Do not bring the old seed into this multisig. You are building a totally fresh destination.

    Step 4: Assemble the multisig

    Use your coordinator to import the public data (xpubs or descriptors) from each device:
  • Verify device fingerprints and key labels match what’s shown on each hardware wallet’s screen.
  • Save and print an output descriptor/backup file for the multisig. Store it with your seed backups in separate, safe places.
  • Generate a receive address and verify that exact address on at least two devices’ screens. If they don’t match, stop and troubleshoot.
  • Step 5: Build a watch-only view of your old wallet

    On a clean computer:
  • Create a watch-only wallet for your old Coldcard by importing its public data (not the seed). This lets you see balances and build transactions without exposing keys.
  • If you cannot build watch-only, you can still proceed with caution by using your normal flow, but keep the device air-gapped and minimize connections.
  • Step 6: Test with a small send

    Before sweeping everything:
  • Send a small amount (for example, $20) from the old wallet to the new multisig address.
  • Confirm it arrives. Verify the receiving address on-device again and check at least one confirmation on-chain.
  • This quick test proves your destination is set up right and your signing flow works.

    Step 7: Sweep the rest with PSBT

    Now move everything:
  • Use coin control to pick all UTXOs in your old wallet. Build a PSBT (partially signed Bitcoin transaction) that sends them to your new multisig address or to a few new addresses for privacy.
  • Set a reasonable fee with RBF (Replace-By-Fee) enabled so you can bump it if the mempool gets busy.
  • Air-gap the PSBT to your old device, sign, then finalize on your coordinator.
  • Broadcast and monitor confirmations. For large balances, you can split the move into several transactions to reduce attention and risk.
  • Note: Signing a transaction from a weakly generated key does not leak more data. The risk is that attackers might already be able to guess the key. Moving fast to a secure destination limits your exposure window.

    Step 8: Retire the old wallet

    After all funds confirm in your new multisig:
  • Label the old wallet “retired.”
  • Wipe or repurpose the old device only after you are sure no funds remain. If you keep it, keep it offline with zero value.
  • Destroy old seed backups so they cannot be recovered by someone else. If you must keep them for records, mark “compromised—zero funds.”
  • Smart safety practices that make this stick

    These tips reduce mistakes and make recovery easier:
  • Verify on-device every time: Never trust the computer screen alone. Check receiving addresses and transaction details on hardware screens.
  • Use diverse hardware: Spread your keys across different vendors and models. Avoid keeping all keys from the same maker.
  • Back up like a pro: For each key, back up seed words and (if used) the passphrase. Store in separate, secure locations. Also back up the multisig descriptor/QR and coordinator file.
  • Label everything: Name each key (Key A/B/C), record fingerprints, and note where each backup lives. Clear labels save you in a stressful day.
  • Practice a recovery drill: On a spare coordinator or offline machine, load your descriptor and ensure you can recreate the watch-only wallet. You don’t need to move coins—just prove you can reconstruct.
  • Mind fees and timing: If fees spike, use RBF and patient scheduling, but don’t delay for days when a seed could be at risk.
  • Keep software clean: Use a dedicated, well-maintained computer for wallet work. Consider a live OS or a separate user profile.
  • Avoid address reuse: Generate a new address for each receive. It protects privacy and reduces linkages.
  • What if you used a passphrase on the old wallet?

    A long, unique BIP39 passphrase can help protect a weak seed, but it is not a free pass. If your seed was created on affected firmware, move anyway. The right path for how to migrate Coldcard seed is still to spend to a brand-new wallet with fresh, high-entropy keys. You can keep using strong passphrases on the new setup for defense in depth.

    Timing, signals, and staying calm

    The Coldcard breach did not drain funds all at once. Attackers had to hit addresses one by one. That gave the network time to react. It also gave you time to plan. You do not need to panic, but you should act with purpose:
  • Get your new multisig built correctly before you move big balances.
  • Test with a small send, then sweep the rest.
  • Confirm, back up, and retire the old wallet.
  • This is the same measured playbook large holders followed when 233,000 BTC moved to safety within days. Incremental steps, strong verification, and fresh keys win. Moving your Bitcoin from a risky key to a secure, redundant setup is one of the highest-value actions you can take. With a clear destination, verified steps, and steady checks, you can complete the job in an afternoon—and sleep better that night. Finishing the job means committing to good habits. Keep firmware current. Rotate new receiving addresses. Run a recovery drill once or twice a year. Store backups in separate places and keep a written recovery plan where your trusted people can find it if needed. When friends ask how to migrate Coldcard seed after this incident, point them to this simple path: fresh keys, verified multisig, small test, full sweep, and clean retirement of the old setup. It is clear, it is fast, and it works.

    (Source: https://decrypt.co/375450/coldcard-hack-15-billion-bitcoin-moved-safety)

    For more news: Click Here

    FAQ

    Q: How to migrate Coldcard seed if it was generated on affected firmware versions 4.0.1–4.1.9? A: If your seed was generated on Coldcard firmware 4.0.1 through 4.1.9, treat it as compromised and migrate immediately. The recommended path explains how to migrate Coldcard seed by creating fresh, mixed-vendor keys on updated devices, verifying addresses on-device, testing with a small send, then sweeping all funds using PSBT and retiring old backups. Q: Why is multisig recommended rather than reusing an old Coldcard seed? A: Multisig spreads risk across independent keys so a single compromised device or weak seed cannot drain the wallet. The article recommends common setups like 2-of-3 for simplicity or 3-of-5 for higher redundancy and advises mixing vendors to reduce single points of failure. Q: What devices and coordinator tools should I use when migrating to multisig? A: Update each hardware wallet to the latest firmware and generate brand-new seeds on-device, preferably mixing vendors such as an updated Coldcard plus Ledger, Trezor, Keystone, or SeedSigner. Use a coordinator like Sparrow or Specter (or a guided service if you prefer) to import xpubs/descriptors by air-gap and to save the multisig descriptor backup. Q: How should I verify a receive address before moving large amounts? A: Generate the receive address in your coordinator and verify that exact address on at least two hardware devices’ screens; if they don’t match, stop and troubleshoot. After verification, perform a small test send and wait for at least one on-chain confirmation before sweeping the remainder. Q: What small-test procedure does the guide recommend before sweeping funds? A: The guide suggests sending a small amount (for example, the $20 example) from the old wallet to the new multisig address to confirm the destination and signing flow. Verify the receiving address on-device and confirm at least one on-chain confirmation before proceeding with a full sweep. Q: How do I sweep the rest of my funds from the old Coldcard safely? A: Use coin control to select all UTXOs and build a PSBT with RBF enabled, then air-gap the PSBT to the old device for signing and finalize it on your coordinator before broadcasting. For very large balances you can split the move into multiple transactions and monitor confirmations as you go. Q: If I used a BIP39 passphrase on the old Coldcard seed, is it safe to keep using that seed? A: A long, unique BIP39 passphrase can add protection but it is not a free pass if the seed was generated on affected firmware, so you should still move your funds. The correct approach is to spend to a brand-new wallet with fresh, high-entropy keys and then optionally use strong passphrases on the new setup for layered defense. Q: After the migration, what should I do with the old Coldcard device and its backups? A: Label the old wallet “retired,” ensure no funds remain, then wipe or repurpose the device and destroy old seed backups or mark them “compromised—zero funds.” Also save the multisig output descriptor and coordinator backup in separate secure locations and run a recovery drill to confirm you can reconstruct your watch-only view if needed.

    * The information provided on this website is based solely on my personal experience, research and technical knowledge. This content should not be construed as investment advice or a recommendation. Any investment decision must be made on the basis of your own independent judgement.

    Contents