Intelligence Brief
Bitcoin users have accelerated wallet migration following disclosure of a seed-generation weakness affecting several Coldcard hardware-wallet models and firmware versions. The Block reported that new Bitcoin addresses increased from roughly 260,000 to more than 330,000 over one week, although the data does not prove that every new address resulted from the incident.
Blockchain investigators have associated approximately 1,816 BTC across more than 5,200 addresses with several theft waves. The total remains an attribution estimate rather than a confirmed victim ledger.
Coinkite said a build-configuration error caused affected devices to use weaker software-derived randomness when generating some wallet seeds. The affected seed remains vulnerable after a firmware update because the weakness is embedded in the original recovery phrase. Moving that phrase to another device does not repair it.
Coinkite has released fixed firmware and advised exposed users to generate a new seed and transfer their funds. Its advisory covers Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9, alongside reduced-entropy conditions affecting Mk4, Q and Mk5 devices before their respective fixes.
Strategic Assessment
The security boundary failed before funds ever reached the blockchain. Cold storage protected the private keys from online extraction, but predictable seed generation gave the attacker another route.
Users who installed the patch but retained an old seed remain exposed. That distinction creates the main residual threat: a device may appear updated while its wallet credentials are still vulnerable.
The increase in new addresses is consistent with migration, but it should not be treated as a precise measure of affected users. Ordinary wallet creation and unrelated activity are part of the same dataset.