Coldcard account hacked? Here’s what to do
Move fast and in the right order: reclaim the account through Coldcard’s official flow, kick the attacker out of every session, then close the door they came through — usually a password that leaked in a breach and was reused.
If your Coldcard account was hacked: start recovery at the official page (blog.coinkite.com/coldcard-mk3-seed-generation-warning/), change the password to a unique one, sign out all other sessions, and re-check the recovery email and phone on the account. Then find out how the attacker got in — check whether your password appears in known breach data — and turn on two-factor authentication so it can’t happen again.
Recover your Coldcard account, step by step
These steps follow Coldcard’s official process — expect it to take funds moved to a new seed the same day; stolen coins are not recoverable. Official links only: account recovery · password reset.
Treat the seed as compromised until proven otherwise, and move any remaining balance first - install the fixed firmware for your model, generate a brand-new seed on it, and send funds to the new wallet before doing anything else.
Write down and verify the new backup, check a receive address on the device screen, and send one small test transaction before migrating the rest.
Never reuse the old seed words, and do not import them into a phone or desktop wallet 'just to check' - anything that can hold them can leak them.
Document what left the wallet: transaction hashes, addresses and timestamps. Report to ic3.gov and reportfraud.ftc.gov; those reports are what blockchain-tracing and any later legal process work from.
Assume your details will circulate among scammers next: check whether your email appears in known breach data, and remove your name, address and phone from people-search sites so the follow-up calls have nothing to work with.
What trips people up with Coldcard
- In late July 2026 Coinkite published a security advisory about seed generation on Coldcard: because of a build error dating back to 2021, devices produced wallet words with far less randomness than intended, which makes those seeds guessable by someone with enough computing power. Press reporting through early August described large sweeps of affected wallets. Your device does not have to have been touched, lost or plugged into anything - the weakness is in the words themselves.
- Installing the fixed firmware does not repair a seed that was already created on the flawed version. That is the part people get wrong: they update, see a clean device, and leave the coins where they are. The advisory is explicit that an affected seed has to be replaced with a newly generated one and the funds moved across.
- Coinkite's advisory names the affected builds: Mk2/Mk3 on 4.0.1 through 4.1.9, Mk4/Mk5 before 5.6.0, Q before 1.5.0Q, and the Edge builds before 6.6.0X and 6.6.0QX. It also states that a seed is not considered at risk from this issue alone if you added at least 50 fair, private dice rolls during setup, or if a strong unique BIP-39 passphrase sits on top of it.
- Nobody can reverse a Bitcoin transaction, so anyone messaging you as a 'recovery service', a 'Coinkite support agent' or a class-action contact is running the second scam. Real support never opens a chat with you and never asks for seed words - typing them into anything that asks is how the remaining balance goes too.
- Public wallet-drain incidents are followed by lists of victim addresses, and those get matched to real names using data bought from people-search sites. Expect the phone calls and the very specific phishing emails weeks after the money is gone.
Still logged in? Lock the account down now
If you can still get in, you're racing the attacker. In this order: change the password to a long, unique one; sign out all other sessions/devices (the setting exists in Coldcard's security settings); confirm the recovery email and phone number are yours (attackers quietly add their own so they can "recover" the account later); remove unfamiliar linked apps or API access; and turn on two-factor authentication. Only then deal with anything the attacker posted, sent or bought.
Got a "new login" alert from Coldcard?
Treat it as real but verify it the safe way: never tap the link in the message itself (fake login alerts are a top phishing template for Coldcard). Open the app or type the address yourself, check the active-sessions list in security settings, and if you see a device or location you don't recognize, sign it out and change your password immediately. If the alert was genuine, that password is burned — assume it's circulating and change it everywhere else you reused it.
The attacker spent, moved or stole money
Report the unauthorized transactions to Coldcard through the official flow the moment you're back in (or even before — fraud reports don't require account access). U.S. consumer protections for electronic transfers generally limit your liability the faster you report, so speed matters more than completeness. Also call the bank or card issuer behind the funding source — they can dispute, reverse or block further charges — and file at reportfraud.ftc.gov so the pattern is on record.
Why this happened — and how to make sure it can’t again
About a third of account takeovers are credential stuffing: a password you used on Coldcard (or the email behind it) leaked in some other company’s breach, and attackers replayed it here automatically. The FBI’s IC3 logged over 5,100 account-takeover complaints with $262M in losses in 2025 alone (IC3). Even when Coldcard itself was never breached, your reused password from another site opens it.
So after recovery, check what’s already out there: our free scanner shows which known breaches and dark-web dumps include your email — and whether passwords were exposed with it.
Check my exposure — free →After you recover: three doors to close
- Unique password + 2FA. A password manager plus app-based two-factor stops both stuffing and phishing replays.
- Reset everywhere you reused that password — email first (it’s the master key), then bank, then the rest.
- Shrink your public footprint. Attackers research targets on data-broker sites (your address, phone, relatives — enough to social-engineer support lines). Our free opt-out guide covers 190 of them, step by step.
Hacked Coldcard account, answered
How did my Coldcard account get hacked?
The most common cause isn't a hack of Coldcard itself — it's credential stuffing: a password you used on Coldcard leaked from some other site's breach, and attackers tried it here automatically. Roughly a third of account takeovers happen this way, with phishing (fake Coldcard login pages and alerts) close behind. That's why the first fix is a unique password, not just a new one.
Can I get my Coldcard account back?
Usually yes. Use the official recovery flow (https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/) — it can verify you even when the attacker changed the email and password. Expect it to take funds moved to a new seed the same day; stolen coins are not recoverable; respond quickly to follow-ups so the case stays open.
Should I just make a new Coldcard account instead?
Not until you've tried recovery. The old account keeps your history and contacts — and while the attacker controls it, it will be used to scam people who trust you. Recover it, or at minimum report it as compromised so Coldcard can lock it, before you start over.
Will I get money back that was stolen through my Coldcard account?
Often, if you move fast. Report the unauthorized activity to Coldcard and to the bank or card behind it — U.S. protections for unauthorized electronic transfers generally limit your losses the sooner you report. Peer-to-peer payments you were tricked into sending yourself are much harder to recover than transactions the attacker made — another reason to report the takeover itself, with evidence.
How do I stop my Coldcard account being hacked again?
Three things close most of the doors: a unique password (a manager makes this painless), app-based two-factor authentication, and shrinking your exposed footprint — checking your email against known breach databases and removing your personal data from data-broker sites that attackers use to research targets.