What the COLDCARD Entropy Bug Teaches Us About Institutional Custody

31 Jul 2026Custody5 min read

Coldcard Blog


A random number generator failed. Roughly $38 million in Bitcoin walked out the door. And thousands of hardware wallet owners are now staring at a migration checklist, hoping they act faster than whoever is scanning the blockchain for the next weak seed.

This is the kind of story that should make every institution holding its own crypto keys stop and ask a harder question: not “is my hardware wallet good,” but “should an institution be relying on a hardware wallet in the first place?”

Coinkite, the maker of the COLDCARD hardware wallet, disclosed a defect in how certain firmware versions generated wallet seeds. In simple terms: the device was supposed to pull randomness from a dedicated hardware chip built for exactly that purpose. Instead, due to a mismatched software import and a misconfigured build flag, it silently fell back to a much weaker, predictable random number generator for most of that work. The hardware security was sitting right there in the binary: it just wasn’t the code path actually being used.

The impact varied by device generation. Older Mk3 units running certain firmware were left with an estimated 40 bits of effective randomness, instead of the intended 128, a gap large enough that a well-resourced attacker could plausibly guess a private key rather than needing to steal it. Later models (Mk4, Mk5, Q) added a second layer of entropy that reduced, but didn’t eliminate, the exposure, landing around 72 bits. 

Bitcoin researchers, including a team at Block, traced the root cause to a years-old open-source dependency that quietly entered the COLDCARD build path back in 2021. Coinkite has released hot-fixed firmware and is telling affected users to generate a brand-new seed, verify it carefully, and migrate funds because updating the firmware does nothing to repair a seed that was already generated under the flawed conditions.

Coinkite has been transparent and moved fast once the issue surfaced. That’s not really the point. The point is that a defect like this can live in open-source firmware, unnoticed, for years, and the people holding the keys have no way to know until funds start moving.

This isn’t a story about one vendor’s bug. It’s a story about concentration risk. A single device, a single seed, a single point of failure. When that one thing breaks, whether it’s a firmware bug, a lost device, a compromised backup, or a person who simply makes a mistake, there’s often no second line of defense standing between the failure and the funds.

That’s an acceptable trade-off for an individual managing their own savings. It is not an acceptable operating model for an institution managing client assets, LP capital, or a balance sheet that regulators, auditors, and counterparties expect to be resilient by design.

sFOX® exists because institutions need more than a device and a seed phrase. We’re the engine that unifies trading, custody, liquidity, and connectivity into a single institutional-grade infrastructure layer, built to mitigate single points of failure through layered governance and technical controls. 

Custody through SAFE® is architected around institutional controls from the ground up: multi-party governance instead of a single seed, segregated qualified custody instead of self-custody, and — critically — the ability to trade directly from custody, so assets never have to leave the safety of custody to be put to work. Clients are not responsible for managing or safeguarding seed phrases, no firmware to patch, no single device that becomes the entire perimeter. Security is distributed across process, infrastructure, and independent oversight, not concentrated in one artifact that a bug or a bad actor only has to compromise once.

Hardware wallets have a place. It’s a real and useful place for personal holdings. But the COLDCARD entropy issue is a clean case study in why institutional capital needs institutional infrastructure, custody built to withstand the failure of any single component, not custody that depends on one working perfectly.

Every institution holding digital assets should be asking its custody provider the same question this incident raises: what happens when one thing fails? If the honest answer involves a single seed, a single device, or a single point of trust, it’s worth a second look.

SAFE® Custody was built to make that a much easier question to answer.

Talk to our team about SAFE® Custody and how sFOX secures institutional digital assets at scale.