Coinkite disclosed that seeds generated on Coldcard Mk3 firmware 4.0.1 or later can be reconstructed by an attacker, with Bitcoin Core contributor instagibbs reproducing a vulnerable seed on a freshly initialized device. Mk4 and Mk5 hardware are also affected on firmware earlier than 5.6.0, while Q devices are exposed before firmware 1.5.0Q, though the company describes that impact as less severe. Funds tied to any seed generated inside that window are at risk, and remediation requires generating a fresh seed and moving balances on-chain, since existing addresses remain controlled by the original key material no matter what firmware ships later.
Why it matters
A hardware wallet's threat model assumes the device starts with unpredictable entropy and then protects those keys from extraction. The Coldcard flaw breaks the assumption one step earlier, at creation rather than at storage or signing, which means the air gap, secure element, and offline transaction flow are protecting the wrong thing. Because seeds can outlive the firmware that made them, the advisory exposes a structural problem in how cold storage is maintained: a wallet created in 2021 on hardware that received its last update in June 2023 is now flagged in July 2026, with no automatic channel to reach a holder who powers the device on once every few years. Independent entropy testing of seed-generation paths, not just reproducible builds, becomes the only durable check that the randomness pool was sufficient at the moment of creation.
Market impact
The highest-risk custody profile is a single-signature wallet whose seed was generated on an affected Mk3 with no BIP-39 passphrase, no dice entropy, and no multisig co-signer. Coinkite notes that a strong, unique passphrase adds an independent barrier the attacker must also recover, and that multisig can confine a single weak seed to one signer if the spending threshold requires other independent keys. User-supplied dice entropy of at least 99 fair rolls is the company-specified threshold for the dice-only import flow, though Coinkite still advises migration even with extra entropy in place. The bear case is straightforward: dormant wallets continue to receive deposits to the old addresses, owners discover the advisory through theft reports, and panic transfers to unverified addresses or temporary wallets compound the original flaw with operational losses. The bull case is a measured rotation cycle, a published root cause, and broader adoption of passphrases, multisig, and reproducible entropy audits as standard custody hygiene.
Frequently asked questions
-
Which Coldcard devices are affected by the seed-generation flaw?
Mk3 devices are affected on firmware 4.0.1 or later. Mk4 and Mk5 are exposed on firmware earlier than 5.6.0, and Q devices on firmware earlier than 1.5.0Q, with Coinkite describing the Q impact as less severe.
-
Can a firmware update fix an already-generated vulnerable seed?
No. Updated firmware secures future setup flows but cannot change the key material controlling addresses already created. Remediation requires generating a new seed and moving funds on-chain to fresh addresses.
-
What is the highest-risk custody profile for this flaw?
A single-signature wallet whose seed was generated on an affected Mk3 with no BIP-39 passphrase, no dice entropy, and no multisig co-signer. In that setup the affected seed is the only cryptographic root protecting the balance.
-
Do passphrases, multisig, or dice entropy reduce the risk?
Coinkite says a strong unique BIP-39 passphrase adds an independent barrier the attacker must also recover, multisig confines a weak seed to one signer if the spending threshold requires other keys, and user-supplied dice entropy of at least 99 fair rolls is the company-specified threshold for the dice-only import…
-
Why is the timing of the Coldcard advisory significant?
Coinkite's final Mk3 firmware shipped in June 2023 and the July 2026 advisory covers seeds generated from March 2021 onward, leaving a roughly three-year gap between product support and an urgent custody action that dormant holders may miss.
CryptoSlate