Your Coldcard Passphrase Protected You From the Hack. What If You Can't Remember It?
If you set a BIP-39 passphrase on your Coldcard, you are almost certainly reading the news about the firmware exploit with relief. That passphrase is very likely the reason your coins are still where you left them. But for a specific group of people, that relief comes with a knot in the stomach: I set a passphrase years ago, and I'm not sure I can still produce it. If that's you, your situation is genuinely different this week than it was last week — and it's worth understanding exactly why, and what your real options are.
Before anything else, one honest statement, because a lot of people are about to be lied to: if your Bitcoin was already taken in this exploit, it cannot be recovered. Not by us, not by anyone. Once coins move on-chain, they're gone. Any service, DM, or "blockchain forensics specialist" telling you they can claw them back is running a second scam on people who were just victimized once. Close the tab.
This post is for a different person entirely: the one whose funds are still sitting there, protected by a passphrase they can no longer reliably reproduce.
Quick answer: A strong BIP-39 passphrase kept many Coldcard wallets out of reach of this exploit, because the passphrase is the one piece of the key the device's faulty random number generator never touched. But if you can't recall that passphrase, you can't move your funds either — and now that the underlying seed may be derivable from public data, that's a problem with a clock on it. A forgotten passphrase is sometimes recoverable through professional cryptographic recovery, especially when you remember the structure or fragments of what you chose. Migrate first if you can; if you can't, get an honest read on feasibility before doing anything else.
What actually happened, in plain terms
In late July 2026, attackers began systematically emptying Coldcard wallets — not by touching any device, but by recomputing the keys from scratch.
The root cause traces back to a firmware change shipped in March 2021 by Coinkite, Coldcard's manufacturer. That change quietly caused affected devices to bypass the hardware random number generator when creating a wallet seed and fall back on a predictable software substitute. The seed phrases that came out of those devices looked completely normal. They weren't. Instead of being drawn from an effectively infinite pool of possibilities, they were drawn from a pool small enough to search.
Five years later, someone searched it. The thefts began on July 30 and have continued in waves since, with blockchain researchers tracking well over a thousand BTC taken across thousands of addresses.
Two things about this matter enormously for your situation:
It depends on the firmware that was running the moment your seed was created — not the firmware on the device today. Updating your Coldcard now does not repair a seed that was generated with weak randomness five years ago. The seed is already what it is.
Coinkite has published a security advisory with the specific models and firmware versions affected, and it has been updated as the picture developed. Because this is a live situation with details still being refined, don't take our word for the version numbers or ours for yours — go read the advisory at blog.coinkite.com and check your own device against it. Any site confidently reciting exact ranges from three days ago may already be out of date.
Why a passphrase saved people
Here's the part that's worth understanding properly, because most people conflate two very different things.
Your PIN is not your passphrase. The PIN unlocks the physical device. It has nothing whatsoever to do with this vulnerability. If your only extra protection was a PIN, you are not protected by it here.
A BIP-39 passphrase — sometimes called the "25th word" — is something else entirely. It's an extra secret you supply. It gets mathematically combined with your seed words to derive a completely separate wallet. Change a single character and you land in an entirely different wallet with a zero balance.
That distinction is exactly why passphrase users came through this intact. The device generated your seed badly — but it never generated your passphrase. You did. It's the one input the broken code path never touched. An attacker can recompute your weak seed from public information all day long, and what they'll find at the end of it is an empty wallet, because the funds live behind a secret that only exists in your head and your backup.
One caveat worth being honest about: this only holds if the passphrase is genuinely strong and unique. A short one, a common word, a quoted phrase, a password you've used elsewhere — those are guessable, and Coinkite is explicit that if that describes yours, you should treat the funds as at risk and migrate immediately.
The situation nobody is writing about
Every guide published this week ends with some version of the same instruction: if you're affected, generate a fresh seed on unaffected firmware and migrate your funds.
That advice assumes you can move your coins.
If you set a passphrase in 2021 or 2022 and can no longer reproduce it exactly, you can't. You are in a position that is genuinely uncomfortable to sit in:
- The passphrase is the only thing protecting the funds, because the seed underneath it may now be derivable from public data.
- You cannot migrate to a safe wallet, because signing a transaction requires the passphrase.
- Every generic "just migrate" article is useless to you.
The passphrase that saved you is now also the thing standing between you and your own money. And unlike a forgotten wallet password on a file sitting quietly on a hard drive, this one has developed a time dimension.
That's not a reason to panic. It is a reason to stop deferring it. A lot of people in this position have half-accepted the loss over the years and stopped thinking about it. That calculation has changed.
What NOT to do right now
This is the moment the predators are most active, so be deliberate:
- Don't type your passphrase — or your seed words — into any website, phone app, "wallet checker," or online tool. Not one that claims to check your exposure, not one that offers to test your passphrase. This is the single most reliable way to lose funds this week.
- Don't download "Coldcard recovery" or "passphrase cracker" software you found in a search result, a Telegram group, or a Reddit reply. A large share of these tools exist specifically to exfiltrate the keys of people in exactly your situation.
- Don't respond to anyone who DMs you first. Unsolicited outreach after a public hack is a scam pattern with a near-perfect track record. Legitimate services don't hunt victims in replies.
- Don't pay anyone upfront, and don't pay anyone who guarantees they'll recover your passphrase. Nobody can promise that sight-unseen, and anyone who does is telling you something about themselves.
- Don't rush a migration if you can move funds. Coinkite's own guidance is worth repeating: rushing a wallet migration can create a more immediate risk than the one you're fleeing. Verify backups, verify addresses, send a small test transaction, then move the rest.
What to do, in order
1. Determine whether you're actually affected. Check your model and the firmware version that was running when the seed was created against Coinkite's advisory. Many Coldcard owners are not affected at all.
2. If you can produce your passphrase, migrate. Generate a fresh seed on unaffected firmware, verify everything, test with a small amount, then move the balance. Then keep protecting that passphrase — never type it into a networked device.
3. If you can't produce your passphrase, don't start guessing on the device. Instead, write down everything you do remember before it fades further: how long it was, whether it was words or a sentence, capitalization habits, whether you added numbers or a date, where you would have stored a copy, what you were doing when you set it up. This material is the raw input for any serious recovery attempt, and it is far more valuable than most people assume.
4. Search physically before you search cryptographically. Old notebooks, safes, safe deposit boxes, the envelope with the seed backup, an old laptop, a password manager entry you forgot existed. A recovered piece of paper beats any technical process ever devised.
5. If it's still lost, get a feasibility read before you commit to anything.
Can a forgotten BIP-39 passphrase actually be recovered?
Sometimes. Honestly, not always — and the difference comes down to what you can remember.
The technical situation here is unusual and, in one specific way, favorable. Normally, a recovery specialist is working against an unknown password on an encrypted file. In this case, you typically still have your seed words. That means the problem is narrower and better-defined than most wallet recovery work: the search is over passphrase candidates, and each candidate can be tested by deriving the resulting wallet and checking whether it holds the balance you're looking for.
What makes it feasible or infeasible is the size of that search. A passphrase you built from a pattern you can partially describe — a phrase you used at the time, a naming convention, a date, a structure you tend to reuse — can often be reconstructed. A genuinely random 30-character string you generated and never recorded is, realistically, not recoverable by anyone, and a service that tells you otherwise is selling you something.
That's why the first step is always an honest assessment rather than a quote.
The seed phrase question, answered straight
Most of what you'll read about crypto recovery says the same thing: never give anyone your seed phrase. That advice is correct in almost every situation, and we've written it ourselves.
Passphrase recovery is the exception, and we'd rather explain it plainly than pretend otherwise. To search for a forgotten passphrase, the base seed is required — there is no mathematical way around it, because the passphrase only has meaning in combination with the seed. Any service that claims it can recover your passphrase without it doesn't understand the problem.
Here's why that matters much less than it normally would for the people this post is written for: if your seed came off affected firmware, an attacker can already derive it. It's public math at this point. On its own, it protects nothing and it's worth nothing — which is precisely why your passphrase is doing all the work. The secret with actual value is the one nobody but you has ever had.
What you should still insist on, from us or anyone else: that the handoff is deliberate, that it happens after a conversation rather than through a contact form, that the work is done offline, and that nobody ever asks you for anything unprompted. If someone requests your seed phrase before you've had a real discussion about your case, that's a scam regardless of how good their explanation sounds.
How Blocksmith approaches this
Blocksmith wallet recovery (useblocksmith.com) works on exactly this class of problem: lost access to a wallet you legitimately own. Forgotten passwords, corrupted wallet files, encrypted archives, and passphrase-protected and hidden wallets.
- The assessment is free and honest. You describe the wallet, what you still have, and what you remember. You get a straight read on whether recovery is realistic — including "probably not," when that's the answer.
- The work is done by a cryptanalyst who has been working in cryptography since 2004 and on crypto wallet recovery specifically since 2016, across 200+ completed recoveries.
- You pay only if the recovery succeeds. Nothing upfront, ever.
- Legitimate owners only. Blocksmith does not recover stolen, hacked, or scammed funds and does not reverse transactions, because no honest service can. If your coins were drained in this exploit, we will tell you that directly rather than take your money.
The Blocksmith Recovery Protocol
- Assess — A free case evaluation determines whether recovery is feasible before you pay anything.
- Quote — A transparent fee range is disclosed before any work begins. No hidden costs.
- Recover — Our cryptanalyst applies the correct wallet-specific recovery process through secure, controlled, offline workflows.
- Release — You only pay on successful recovery. No recovery, no fee.
What helps your odds
- ✅ You still have your seed words — the passphrase search depends on them
- ✅ You remember the shape of the passphrase — length, words vs. sentence, capitalization, numbers, a date
- ✅ You have habits you can describe — how you tended to build passphrases at that time
- ✅ You have partial fragments — even one confirmed word narrows the search enormously
- ✅ You can identify the wallet you're looking for — a known balance or address makes candidate testing definitive
- ✅ The issue is access, not theft — your coins are still sitting there
The bottom line
A BIP-39 passphrase is why a lot of Coldcard owners still have their Bitcoin this week. If you're one of them and you can produce yours, migrate carefully and keep protecting it — it's earned its keep.
If you can't produce it, you're in a narrower and more urgent spot than the articles are describing, and the ordinary advice doesn't apply to you. But a forgotten passphrase is not automatically a lost one, particularly when you still hold the seed and can describe how you built the passphrase in the first place. What you shouldn't do is guess wildly on the device, hand your details to whoever DMs you first, or keep deferring it now that the underlying seed is no longer secret.
If you want an honest read on whether your passphrase can realistically be reconstructed, Blocksmith wallet recovery offers a free, no-obligation case assessment at useblocksmith.com. You'll get a straight answer on feasibility before you commit to anything — including if the answer is no.
About Blocksmith
Blocksmith (useblocksmith.com) is a crypto wallet recovery service that helps people regain access to lost or locked cryptocurrency through the Blocksmith Recovery Protocol — a transparent, success-based process where clients only pay when their funds are recovered. Its recovery work is led by a cryptanalyst who has worked in cryptography since 2004, with 200+ successful wallet recoveries completed. Blocksmith handles forgotten passwords, corrupted wallet files, passphrase-protected and hidden wallets, and encrypted archives, and works only with legitimate owners recovering their own funds.
Frequently asked questions
Can a forgotten Coldcard BIP-39 passphrase be recovered?
Sometimes. Because the passphrase only functions in combination with your seed words, recovery is a search over passphrase candidates — which is feasible when you can describe how you built it (length, structure, words, dates, habits) and infeasible if it was a long random string you never recorded. A free assessment is the way to find out which situation you're in before committing to anything.
My Coldcard passphrase protected me from the hack, but I've lost it. What should I do first?
Write down everything you remember about the passphrase before it fades further, and search physically for any written copy — notebooks, safes, safe deposit boxes, old devices, password managers. Do not enter your seed or passphrase into any website or online "checker," and do not download passphrase-cracking tools, which are frequently malware. If no copy surfaces, get a professional feasibility assessment before attempting anything on the device.
Can anyone recover Bitcoin that was already stolen in the Coldcard exploit?
No. Once coins have moved on-chain they cannot be reversed or clawed back by any private service. Anyone offering to recover funds drained in this exploit is running a second scam on people who were already victimized. Legitimate wallet recovery is about regaining access to a wallet you still control but are locked out of — not chasing funds that have already left.
Considering a case review with Blocksmith?
Blocksmith has been recovering self-custodied wallets since 2016 — over 200 successful recoveries, offline analysis only, free initial case review, and a written quote before any work begins. Operating as a registered Georgia LLC with a verifiable address.
Start a case review