Bitcoin hardware maker Coinkite issued a direct warning to Coldcard Mk3 users on Saturday, telling anyone who generated a seed on firmware 4.0.1 or any subsequent version that their funds may be at risk. The advisory follows on-chain reports of roughly 594.5 BTC drained from approximately 500 wallet addresses in a pattern cryptographers have tied to a flawed random-number generator on the affected firmware versions.
Why it matters
Coldcard is one of the longest-running air-gapped hardware wallets in the Bitcoin market, popular with self-custody maximalists and institutional treasuries that demand strict isolation from online environments. A seed-generation flaw on a device in that category is the worst-case failure mode: cold storage is only as strong as the entropy that produced the private key, and deterministic or biased randomness means an attacker who understands the bias can reconstruct the key without ever touching the device. Coinkite urged users to move funds to a seed generated on a different, uncompromised device immediately.
Market impact
At roughly $60,000 per BTC, the 594 BTC haul puts the theft north of $35 million, making it one of the largest cold-storage compromises of the year. The episode is a reminder that hardware wallets are not a single monolithic trust boundary: the chip, the firmware, and the supply chain are all separate attack surfaces. Watch for downstream pressure on cold-storage competitors, including Ledger and Trezor, and for renewed scrutiny of how vendors attest to firmware integrity updates.
Frequently asked questions
-
Which Coldcard devices are affected by the seed-generation flaw?
Coinkite warned that any Coldcard Mk3 used to generate a seed on firmware 4.0.1 or any subsequent version may have funds at risk. Users are urged to move funds to a seed generated on a different, uncompromised device.
-
How much Bitcoin was stolen in the Coldcard drain?
Roughly 594.5 BTC was drained from approximately 500 wallet addresses in a pattern tied to the flawed firmware. At around $60,000 per BTC, the haul is north of $35 million.
-
How does the flaw let attackers drain wallets without the device?
Cold storage is only as strong as the entropy that produced the private key. A biased random-number generator on firmware 4.0.1 onward means an attacker who understands the bias can reconstruct the private key without ever physically touching the device.
-
What should Coldcard Mk3 users do right now?
Coinkite urged users to move funds to a seed generated on a different, uncompromised hardware device immediately, and to treat any seed created on the affected firmware as potentially compromised.
-
Could this affect other hardware wallet brands like Ledger or Trezor?
The flaw is specific to Coinkite's Coldcard Mk3 firmware, but the episode is likely to draw fresh scrutiny of how all hardware-wallet vendors attest to firmware integrity, and may pressure competing cold-storage vendors to publish independent audits.
TheBlock