Bitcoin
Get started

Account types

Business account

For corporates and treasuries

Personal account

Individual investing made better

Joint account

Invest with your loved one

Parent-child account

Invest together for the future

Platform

Platform

Wallet

Secure your bitcoin

Blockrise App

Real-time insights

Back-up

Never lose access

Broker

Buy and sell bitcoin

Easy Invest

Recurring purchases

Services

Services

Bitcoin-backed loans

Liquidity for your bitcoin

Treasury Management

Bitcoin on the balance sheet

Legacy planning

For the next generation

Asset Management

Managed bitcoin strategy

Secured Lending

Fixed-interest EUR lending

Resources

Resources

Blog

The latest developments

Education

Learn more about bitcoin

Publications

Read our research

About

About Blockrise

Contact

Talk with us

About Blockrise

Meet our team

Fee schedule

Transparent pricing

Careers
0
EN
NL

Log in

EN
NL

Log in

Subscribe to our newsletter

Stay informed about our latest developments and updates!

By signing up, you agree to receive updates from Blockrise. You can unsubscribe anytime. See our Privacy Policy for details.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Updates

●

August 6, 2026

●

 min read

The COLDCARD incident and the limits of device-level security

Jos Lazet

CEO

What the COLDCARD vulnerability teaches about seed generation, hardware wallet risk and how Blockrise limits access to client bitcoin.

Download PDF

People lost bitcoin that they held offline on hardware wallets with a strong reputation in the Bitcoin community. They had moved their bitcoin away from exchanges and protected their seed phrases, yet a flaw in affected COLDCARD firmware made some wallet seeds more predictable than intended.

This does not mean that self-custody has failed, nor does it prove that professional custody is always safer. It shows that the security of a Bitcoin wallet depends on the full process around a key: how it is generated, where it is stored, what must happen before it can be used and how access can be recovered.

What went wrong

A Bitcoin private key is a very large number. In wallets that use a 12- or 24-word seed phrase, those words encode the entropy from which the wallet’s keys are derived. Security depends on an attacker being unable to predict or reproduce that entropy.

During a software change in 2021, affected COLDCARD firmware began using a deterministic software fallback instead of the intended hardware random-number generator. Later devices added entropy from a secure element, but Block’s analysis found that the implementation retained only a limited amount of it. The devices continued to produce valid seed words, normal addresses and working transactions, so the weakness was not visible to the owner.

Coinkite has since released fixed firmware and advises affected users to migrate to a newly generated seed. Installing the update prevents the same generation path from being used again, but it does not repair a seed that was created before the update.

Bitcoin’s cryptography remained intact. The fault lay in one implementation of the process that supplied randomness when a wallet secret was created.

Why a hardware wallet is only one part of security

A hardware wallet can isolate keys from an internet-connected computer and protect transaction signing. Those controls matter, but the owner still depends on the device firmware, its build process, the implementation of key generation and the quality of testing around it.

Using several devices does not automatically remove that dependency. If multiple keys were generated by the same device family, firmware or random-number implementation, they may still share one failure mode. The same principle applies to multisignature: distributing keys helps only when the components and procedures are genuinely independent.

Security therefore has to be assessed as a system rather than as a product label. Key generation, storage, authorisation, monitoring and recovery each address a different risk.

How Blockrise limits key access

Blockrise is publishing this article to help Bitcoin holders understand the vulnerability and protect their funds. The incident should not be used to present one custody model as universally superior. Our responsibility is to explain the risk clearly and support clients who may be affected.

Blockrise uses a semi-custodial model in which every client has a segregated Bitcoin wallet that can be verified on-chain. Client bitcoin are not pooled into a general wallet.

Blockrise protects its Bitcoin keys using self-owned and self-hosted Securosys Primus CyberVault X2 Hardware Security Modules, or HSMs, with geographic redundancy. The private keys are configured as non-exportable, which prevents them from leaving the HSM in plaintext and prevents Blockrise application software or operators from extracting or copying them.

Each client creates two distinct access components when setting up a Blockrise wallet:

  1. The mobile key. On supported devices, the phone generates and holds this key inside its secure hardware. The key cannot be exported or transferred to another device. It signs each transaction request from the client.
  2. The Blockrise Seed. The phone generates this recovery secret using its cryptographically secure random-number generator. The client can write it down or use the Blockrise Cloud Recovery service, which encrypts the seed before storing it in the client’s own cloud environment. The Blockrise Seed is required to recover access because the mobile key cannot be exported or transferred.

When a client authorises a transaction, the phone signs the request with the mobile key. The corresponding HSM-held Bitcoin key requires that client authorisation before it can produce a Bitcoin signature. Blockrise can apply controls that stop a transaction, but it cannot move client bitcoin without the required client authorisation.

Securosys has previously achieved FIPS 140-2 Level 3 validation for earlier Primus HSM hardware and firmware. The CyberVault X2 is the newer generation and is currently undergoing FIPS 140-3 Level 3 certification. Certification is one source of assurance within a broader security framework, alongside the controls Blockrise applies to key access, authorisation and recovery.

Technology is only one part of that framework. Blockrise Capital B.V. provides custody services under MiCAR and is supervised by the Dutch Authority for the Financial Markets. Blockrise combines HSM key protection with segregated client wallets, cryptographic confirmation of transactions, multi-factor authentication, operational controls and regular audits. Securosys attestation tooling provides an additional way to verify relevant device and key attributes. The Blockrise Custody Policy Summary explains the main custody, segregation, access and accountability measures.

What affected COLDCARD owners should do

If you have ever generated a seed phrase using a COLDCARD and cannot confirm that the firmware was unaffected, treat the seed as potentially vulnerable and migrate the bitcoin as a precaution. Blockrise can help clients assess their situation and plan a safe migration.

Keep the following points in mind:

  • Updating the COLDCARD firmware does not repair an existing seed phrase.
  • Restoring or importing the same seed phrase into another hardware wallet does not make it safe.
  • Create a completely new seed using an unaffected device or a COLDCARD running the latest fixed firmware.
  • Verify the new wallet and receiving address on the device itself.
  • Never share your seed phrase with Blockrise, COLDCARD support or anyone else. Be alert to phishing emails, websites and unsolicited messages.

The warning concerns the origin of the seed phrase, not where it is currently stored. A seed generated on affected COLDCARD firmware may remain vulnerable after it has been imported into another device.

Discover more and follow
the latest updates

February 12, 2026

Why LTV management separates survivors from casualties

Learn more

February 11, 2026

Why institutional infrastructure matters for bitcoin adoption

Learn more

February 2, 2026

Webinar: Liquidity without selling your bitcoin

Learn more

+31 10 848 17 41
support@blockrise.com

Get started

Business accountPersonal accountJoint accountParent-child account

Services

Asset ManagementBitcoin-backed loansSecured LendingLegacy planningTreasury Management

Platform

WalletBrokerEasy InvestBlockrise AppBack-upBlockrise Status

Resources

BitcoinAbout usBrandFee scheduleContactBlogEducationPublicationsCareers ↗

Legal

Privacy policyCookie statementBitcoin disclosuresRisk disclosureConflict of interest disclosureSummary of order execution policyComplaints procedure
Copyright © 2025 Blockrise | All Rights Reserved

Blockrise is a Bitcoin only platform based in Rotterdam, the Netherlands. Founded in 2017. We offer custody, wealth management, brokerage, Bitcoin backed loans, treasury services, secured lending, and estate planning, all focused exclusively on Bitcoin. Blockrise Capital B.V. holds a MiCAR licence (number 41000029) issued by the Dutch Authority for the Financial Markets (AFM).

Everything about Secured Lending

Download the brochure and learn more about our offering.

Blockrise needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at any time. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, please review our Privacy Policy.