If you use a Coldcard hardware wallet, please pay attention. If you know someone who uses one, call them. Text them.
This appears to be one of the most serious wallet security incidents Bitcoin has seen.
If you're affected, don't wait. If you need help, reach out.
The Coldcard bug explained in simple terms:
Normally, a hardware wallet generates your 12 word seed phrase using true randomness.
Think of it like a lottery with roughly 340 undecillion possible tickets (that’s a 340 followed by 36 zeros). Every ticket has an equal chance of being picked, making the odds of guessing your seed essentially zero.
The bug didn’t shorten the 2,048-word BIP-39 word list. It changed how the wallet picked the words.
Instead of choosing from the entire lottery, the wallet kept picking from the same tiny corner because the “random” numbers were partially predictable from things like the device’s ID and timing.
Imagine that instead of 340 undecillion possible combinations, your wallet accidentally chose from only a few billion. That’s still a huge number, but astronomically smaller than what Bitcoin’s security is designed to provide.
Your seed phrase still looked completely normal. The words came from the same 2,048-word list. Nothing looked suspicious.
But for an attacker, the search space became millions of trillions of trillions of times smaller.