If your recovery words were generated on affected Coldcard firmware, create an entirely new wallet on a BitBox and transfer your bitcoin to an address generated by that new wallet. Do not use the affected Coldcard recovery words as the destination wallet. Restoring the same recovery words on any device recreates the same potentially vulnerable wallet; it does not create new keys.

Wallets originally generated on a BitBox are not affected by this specific Coldcard vulnerability and do not need to be migrated. The exception is a wallet whose recovery words were originally generated on an affected Coldcard and later restored on a BitBox. For more background, read why BitBox is not affected by the Coldcard RNG vulnerability.

This guide covers a standard single-signature Bitcoin wallet when you can still authorize transactions from the affected Coldcard wallet. If you use multisig or cannot access the old signing device, follow the guidance under Special migration situations before changing or resetting any device.

Check whether your Coldcard wallet is affected

The relevant detail is where and when the recovery words were generated, not which hardware wallet currently stores them. Updating a Coldcard fixes future wallet generation but does not repair recovery words that were already generated by affected firmware.

As of August 1, 2026, CoinKite identifies the following wallet seeds as affected:

  • Coldcard Mk3 seeds generated on firmware 4.0.1 through 4.1.9.
  • Coldcard Mk4 and Mk5 seeds generated before standard firmware 5.6.0 or Edge firmware 6.6.0X.
  • Coldcard Q seeds generated before standard firmware 1.5.0Q or Edge firmware 6.6.0QX.

Check the current CoinKite Coldcard Security Advisory before you begin because its investigation and guidance may change.

The public assessment broadened from older Coldcard devices to additional models as the incident developed. Because further technical details may still emerge, use a conservative rule: if your recovery words were generated on a Coldcard and you cannot establish with confidence that they fall outside the potentially affected conditions, treat the wallet as potentially affected and migrate it. In practice, this means that most Coldcard users whose recovery words were created by the device should take the incident seriously unless they can establish that their wallet is outside the affected scope. This is a precautionary recommendation; it is not a claim that every Coldcard wallet has been exploited.

Do not use a partial dice-roll count as proof that an uncertain Coldcard wallet is safe. If you cannot independently verify that the complete wallet-generation method produced sufficient, private entropy, migrate to a new wallet. If you deliberately want to generate the replacement wallet with physical randomness, follow the complete BitBox method in Roll your own Bitcoin seed instead of adapting individual steps or thresholds from another process. Normal BitBox wallet generation already combines five independent entropy sources and is the recommended path for most users.


Before you begin

Prepare everything before moving funds so you can complete and verify the migration without unnecessary interruptions.

Create a new destination wallet instead of reusing the old recovery words

The destination must be a newly generated BitBox wallet with new recovery information. In the one-BitBox workflow, you may temporarily restore the affected wallet on the same physical device to authorize the transfer, but never use the affected recovery words as the destination wallet.

 

You need:

  • Access to the affected Coldcard wallet and the wallet software you normally use with it.
  • A BitBox for the new destination wallet. A separate device is the simpler option if the affected wallet is currently restored on a BitBox. If you have only one BitBox, use the dedicated one-device workflow under Special migration situations.
  • The latest BitBoxApp downloaded from the official BitBox website.
  • The microSD card included with the BitBox, or the materials required for your chosen BitBox backup method.
  • A private place where nobody can observe device passwords, passphrases, recovery information, or backup handling.

For the standard workflow, confirm that you can open the affected wallet and authorize a transaction before resetting or erasing any device. If you cannot, do not reset the BitBox destination; first read the relevant branch under Special migration situations.

Verify the required backup before every reset

Resetting a BitBox removes the wallet currently stored on the device. Before each reset, confirm that you have the complete backup and any optional passphrase required to restore the wallet you will need next. A separate signing device is simpler. If only one BitBox is available, follow the repeated-reset workflow below and stop if any backup or passphrase is uncertain.

 

Migrate your bitcoin to a new BitBox wallet

When there are no signs of active unauthorized spending, a small test transaction verifies the new wallet and receiving address before you transfer the remaining balance. The immediate priority changes if the old wallet is already being drained.

Active unauthorized spending changes the priority

If you see an outgoing transaction you did not create or other signs that bitcoin is actively being moved, waiting for a test confirmation may increase the risk. After creating and backing up the new BitBox wallet, verify the complete destination address on the BitBox display and consider transferring the full remaining balance immediately with an appropriate network fee. No single response is correct for every situation, but urgency never removes the need to verify the destination on the BitBox.

 
  1. Install or update the BitBoxApp from the official BitBox website.
  2. Create new recovery information for the destination wallet. Connect the new or safely reset BitBox, select Create wallet in the BitBoxApp, and follow the instructions to set up a BitBox with a microSD card backup. Advanced users who deliberately want to generate the first 23 recovery words with physical randomness should stop and follow Roll your own Bitcoin seed exactly. Never use the affected Coldcard recovery words for the destination wallet.
  3. Verify the new BitBox backup using the method required by the wallet-creation path you selected. For the normal setup, confirm that the microSD card backup completes, then remove the card and store it separately from the BitBox. For the BitBox dice method, complete the recovery-word validation described in the guide before receiving funds.
  4. Open the Bitcoin account in the BitBoxApp and select Receive.
  5. Verify the complete receiving address on the BitBox display. Continue only when the address on the BitBox matches the address in the BitBoxApp. The receiving guide explains how to receive bitcoin and verify the address on your BitBox.
  6. Open the affected Coldcard wallet in the wallet software you normally use with it. Confirm that you selected the correct account and, if applicable, the correct passphrase-protected wallet.
  7. Decide whether the situation allows a test transaction. If there are no signs of unauthorized spending, continue with the test. If bitcoin appears to be moving without your authorization, skip the test and use the already verified address from step 5 for the remaining balance.
  8. Send a small test amount of bitcoin from the affected Coldcard wallet to the verified BitBox receiving address. Review the address and network fee before authorizing the transaction on the Coldcard.
  9. Wait until the test transaction appears in the BitBoxApp and receives a Bitcoin network confirmation. This confirms that the new BitBox wallet received the test amount at the verified address.
  10. Generate another receiving address in the BitBoxApp and verify the complete address on the BitBox display.
  11. Send the remaining bitcoin from the affected Coldcard wallet to the verified BitBox address. If you skipped the test because of active unauthorized spending, use the address verified in step 5. Otherwise, use the new address verified in step 10. Apply an appropriate network fee and verify every transaction detail before authorizing the transfer.
  12. Repeat the transfer for every affected account and every passphrase-protected wallet that holds bitcoin. A passphrase creates a separate wallet, so its balance will not appear in the standard wallet or under a different passphrase.
  13. Wait until all final transactions show as confirmed in the BitBoxApp.
  14. Review the accounts and passphrase wallets you used with the affected Coldcard recovery words. Confirm that no intended bitcoin remains in any migrated wallet.
  15. Label the old Coldcard recovery words and device backup as retired — do not use for new deposits. Keep them until you have verified the full migration and considered whether an old address could still receive a delayed payment.

The migration is complete when all intended bitcoin appears as confirmed in the newly generated BitBox wallet and every migrated wallet controlled by the affected recovery words shows no intended balance remaining. Keep the new BitBox backup private, offline, and separate from the BitBox.

Protect both sets of recovery information during the migration

Keep both sets of recovery information offline during the normal hardware-wallet migration. The higher-risk emergency software-wallet branch below is the only exception described in this article; if you choose it, follow its exposure warning and permanently retire the affected recovery words afterward. Never enter recovery words into a website, browser extension, password manager, cloud service, support form, or AI chatbot. BitBox Support will never ask for your recovery words, passphrase, wallet backup, device password, or private keys.

 

Special migration situations

The standard workflow above assumes that you can sign from the affected single-signature Coldcard wallet while a separate BitBox holds the new destination wallet. This is the simplest arrangement because both wallets remain available throughout the transfer. The following branches cover other setups. If you are uncertain about a backup, passphrase, wallet account, or reset sequence, stop before changing a device and contact BitBox Support through the official contact form. BitBox Support can help plan the BitBox side of the migration, but cannot access the old wallet or handle the transfer for you.

The affected recovery words are already restored on a BitBox

The wallet is still potentially vulnerable because its recovery words originated on the affected Coldcard. When possible, use the original Coldcard or another trusted hardware wallet to keep access to the old wallet while a separate BitBox holds the new destination wallet.

If only one BitBox is available, you can migrate by resetting and restoring the device multiple times. This takes longer and creates more opportunities to restore the wrong wallet, so prepare the full sequence before starting:

  1. While the affected wallet is still open, confirm that you have its complete Coldcard recovery words and the exact optional passphrase, if one is used. Confirm that you are viewing the wallet and accounts that hold the bitcoin you intend to migrate. Do not reset the BitBox if this recovery information is incomplete or uncertain.
  2. Reset the BitBox and create a completely new wallet. Complete and verify the new wallet backup before continuing, and give it a distinct name so it cannot be confused with the affected wallet backup. Never use the affected Coldcard recovery words for this wallet.
  3. Generate the receiving address or addresses you will need in the new wallet. Verify each complete address on the BitBox display and save it accurately for the transfer. Do not rely on an address that was copied but not verified on the BitBox.
  4. Decide whether to make a test transaction. A test provides additional confirmation but requires extra reset-and-restore cycles with one device. If there is no urgent sign of unauthorized spending and you choose a test, restore the affected wallet from its recovery words, compare the transaction destination with the address previously verified on the BitBox, send the test, restore the new wallet to confirm it, then restore the affected wallet again for the remaining balance. If urgency makes waiting or repeated switching inappropriate, restore the affected wallet, compare the complete transaction destination with the previously verified address, and send the intended balance.
  5. Each time you switch wallets, confirm that you have the complete backup and any optional passphrase for the wallet you are leaving, reset the BitBox, and restore the wallet required for the next action.
  6. After the transfer, reset the BitBox once more and restore the new wallet from its verified backup. Use the applicable guide to restore from recovery words or restore from a microSD card backup. Confirm in the BitBoxApp that all intended bitcoin has arrived and received the required network confirmation.
  7. Keep the new wallet on the BitBox. Mark the affected Coldcard recovery words as retired and do not use their addresses for new deposits.

This method is workable, but a backup mistake during any reset can remove the only convenient signing access to a wallet. If the sequence or either backup is uncertain, use a separate trusted hardware wallet or contact BitBox Support through the official contact form before resetting the device. Never include recovery words, a passphrase, wallet backup files, device passwords, or private keys in a support request.

You no longer have a working Coldcard

The preferred option is to restore the affected recovery words on another trusted hardware wallet while the new BitBox wallet remains available as the destination. This keeps the old recovery words away from a general-purpose computer or phone.

If no compatible hardware wallet is available and the migration is urgent, restoring the affected wallet in a reputable compatible software wallet can provide faster signing access. This is a context-dependent emergency tradeoff, not the default recommendation. The decision depends on factors such as signs of active unauthorized spending, the amount at risk, the security of the available computer or phone, and how quickly another hardware wallet can be obtained.

Software-wallet recovery exposes the old recovery words

Entering recovery words into a computer or phone can expose them to malware, backups, screenshots, or other software. Treat the affected recovery words as permanently compromised after software-wallet recovery, even if the wallet app is later removed. Never enter them into a website, browser extension, support form, cloud service, or AI chatbot.

 

Before using this emergency option, create and back up the new BitBox wallet and verify the complete destination address on the BitBox display. Obtain a software wallet that supports the account type used by the affected wallet from its official source, restore the affected recovery words and exact optional passphrase only inside that wallet application, and transfer the intended balance to the verified BitBox address. If the expected accounts or balance do not appear, stop and recheck the passphrase, account type, and recovery details instead of assuming the wallet is empty. Once the transfer is confirmed, retire the affected recovery words permanently. Removing the software wallet afterward reduces ongoing local exposure but cannot reverse the fact that the recovery words were entered on a networked device.

If there are no signs of active unauthorized spending and the amount is significant, waiting for a trusted hardware-wallet recovery path may provide a safer balance of risks. If you are unsure how to prepare the BitBox destination, contact BitBox Support without sharing any wallet secrets.

You use a passphrase

A strong, unique BIP39 passphrase can add an independent barrier, but it does not change the recovery words or prove that an uncertain Coldcard wallet is unaffected. Each passphrase creates a separate wallet, so identify and migrate every passphrase-protected wallet that holds bitcoin. Contact BitBox Support before migrating if you are uncertain how the passphrase affects your BitBox setup; never share the passphrase.

You use multisig

Do not apply the single-signature steps directly to a multisig setup. Replacing one affected signer can require a new multisig wallet policy, verified cosigner information, a new descriptor backup, and coordinated address verification. Contact BitBox Support before migrating a multisig wallet to BitBox, and prepare a setup-specific plan before moving funds or resetting any signer.


Why a newly generated BitBox wallet is not affected

The Coldcard advisory concerns how affected Coldcard firmware generated the random value used to create wallet recovery words. BitBox uses a different wallet-generation design and combines five independent entropy sources:

  • A true random number generator in the secure chip.
  • A true random number generator in the microcontroller.
  • A unique random value installed during factory setup.
  • Randomness supplied by the host device running the BitBoxApp.
  • A cryptographic value derived from the BitBox device password.

Combining independent sources provides defense in depth: the wallet remains unpredictable as long as at least one independent source remains unpredictable to an attacker. BitBox also publishes open-source firmware, supports reproducible builds, operates a bug bounty program, and continuously audits its products, including research with frontier AI models.

For further technical context, see the BitBox security features and the incident-specific explanation of why BitBox is not affected by the Coldcard RNG vulnerability.


Frequently asked questions

Can I restore my Coldcard recovery words on a BitBox and continue using the wallet?

No. Restoring the affected Coldcard recovery words on a BitBox recreates the same wallet and the same keys. You may temporarily restore that wallet to authorize the migration when no other signing device is available, but the destination must be a newly generated BitBox wallet with new recovery information.

Does updating the Coldcard firmware make my existing wallet safe?

No. Fixed firmware corrects future wallet generation but does not change recovery words created by affected firmware. If the recovery words were generated under potentially affected conditions or their status is uncertain, migrate to new recovery information.

Do I need to migrate a wallet originally generated on a BitBox?

No. A wallet originally generated on a BitBox is not affected by this specific Coldcard vulnerability. Migration is relevant only when the recovery words originated on an affected Coldcard, even if those words were later restored on a BitBox.

Can I complete the migration with only one BitBox?

Yes, provided you have complete, confidently identified recovery information for the affected wallet and a verified backup of the new wallet. You must repeatedly reset the BitBox, restore the wallet needed for the next action, and finish with the newly generated wallet restored on the device. A separate signing device is simpler and reduces the risk of a backup or wallet-selection mistake.

Can I use a software wallet if my Coldcard no longer works?

A compatible software wallet can provide emergency signing access when no hardware wallet is available, but entering the recovery words on a computer or phone adds another exposure risk. Prefer a trusted hardware wallet when time permits. If urgency justifies software recovery, prepare and verify the new BitBox destination first, transfer the intended balance promptly, and permanently retire the affected recovery words.

What if my Coldcard model or firmware is not listed?

If you cannot establish confidently that the recovery words were generated outside the potentially affected conditions, treat the wallet as potentially affected and migrate it as a precaution. This does not mean that every unlisted Coldcard wallet is proven vulnerable or has been exploited; it avoids relying on uncertainty when the recovery words protect funds.

What if I added dice when creating the Coldcard wallet?

Do not rely on an isolated dice-roll count as proof that the wallet is unaffected. If you cannot independently verify the complete generation method and the privacy and quality of its entropy, treat the wallet as potentially affected and migrate it. To create a new wallet with physical randomness, follow the complete BitBox guide Roll your own Bitcoin seed rather than combining instructions from different methods.

What should I do if bitcoin is already moving without my authorization?

Prioritize a newly generated and backed-up BitBox wallet, a destination address verified on the BitBox display, and a prompt transfer of the remaining balance with an appropriate network fee. In this situation, waiting for a small test transaction to confirm may add risk. There is no universal response for every wallet state, but never skip verification of the destination address.

Can BitBox Support migrate the wallet for me?

No. BitBox Support cannot access your wallet, authorize transactions, or recover secrets. Support can clarify the BitBox workflow, but you remain in control of the devices, backups, and transactions. BitBox Support will never ask for recovery words, a passphrase, wallet backup files, device passwords, private keys, remote access, or funds.