Berardi and Associates, LLC
Attorneys at Law | Homer Glen, Illinois | (708) 831-0781
IN RE: COLDCARD WALLET SEED VULNERABILITY | CLASS ACTION INVESTIGATIONOPENED 08.2026
Coldcard owner? The firmware defect that let thieves take $88 million may give you a legal claim.
We are investigating class action claims against Coinkite Inc. for owners of Coldcard Mk3, Mk4, Mk5, and Q devices. You may have a claim even if your bitcoin was never touched. The review is free and confidential, and there is no fee unless there is a recovery.
✓ No cost to talk ✓ Confidential ✓ We never ask for seed words
I. Protect yourself first
Before you talk to any lawyer, secure your coins.
Do this now, whether or not you ever contact us.
Follow Coinkite's advisory. If your seed was generated on an affected device and firmware, treat it as compromised.
Update the firmware, then generate a brand new seed on the patched version, or use dice rolls. Never reuse or re-import the old seed.
Move your funds to addresses from the new seed.
Preserve everything: the device, box, receipts, order emails, screenshots of your setup, and the transaction IDs of any theft. Evidence wins cases.
SECURITY NOTICE: We will never ask for your seed words, private keys, or remote access to any device, and we will never contact you first by DM. Anyone who does is trying to rob you. Our only intake channels are this form and (708) 831-0781.
II. What happened
The product's one job was random. It wasn't.
On July 30, 2026, attackers swept more than 1,000 BTC from thousands of bitcoin addresses in under an hour. Coinkite, the maker of the Coldcard hardware wallet, has acknowledged that a firmware defect introduced in 2021 caused affected devices to generate wallet seeds without the hardware random number generator the product advertised, leaving those seeds weak enough to be guessed.
Coinkite has published advisories identifying the affected models and firmware and has shipped emergency updates. But updating firmware does not repair a seed created under affected versions, and Coinkite has offered no refunds and no compensation while continuing to sell the devices.
III. Who may have claims
Two groups. One of them is every purchaser.
Theft victims
Your bitcoin was moved without authorization on or after July 30, 2026 from a wallet whose seed was generated on an affected Coldcard. Potential claims include fraud, negligence, breach of warranty, and consumer protection violations.
All purchasers of affected devices
You paid a premium for a hardware security feature the device did not deliver. Even if your funds were never touched, you may have overpayment and warranty claims for the device itself.
We are especially seeking purchasers in the states below who may be willing to stand up for other owners as class representatives:
CaliforniaIllinoisFloridaNew YorkAll other states welcome
IV. What to gather
Helpful for your review (don't worry if you're missing items)
Device model and, if known, the firmware version when you created your seed
Where and when you bought it (Coinkite store, Amazon, another reseller) and any receipt or order email
If coins were taken: affected addresses, transaction IDs, and approximate amounts
Whether you used dice rolls or a passphrase when creating the seed
Anything you remember seeing before you bought: the Coldcard website, comparison pages, a podcast or YouTube sponsorship
V. Confidential case review
Tell us what happened.
Takes about two minutes. A short call follows if your situation fits the investigation. Submitting this form does not create an attorney-client relationship, and please do not include seed words or private keys.