Coinkite has issued an urgent security advisory covering several generations of its Coldcard hardware wallets after discovering that affected firmware could generate Bitcoin recovery seeds with substantially less randomness than intended. The risk is tied to the firmware used when a seed was created, not simply the model currently holding it. Fixed software can protect future seed generation, but it cannot repair an existing vulnerable recovery phrase.
The most severe exposure affects Coldcard Mk2 and Mk3 seeds generated on firmware versions 4.0.1 through 4.1.9. Coinkite’s updated Mk3 range does not extend through version 5.0.3, and the warning also includes Mk4, Mk5 and Q devices running releases issued before their respective security fixes. Later models retained more entropy than the Mk3 path, but Coinkite still classifies the weakness as serious.
Firmware Used a Predictable Software Fallback
Coinkite said a 2021 integration change redirected wallet seed generation from its intended hardware random-number generator to a MicroPython software fallback. The incorrect code path reduced the effective search space for Mk2 and Mk3 seeds to an estimated 40 bits, potentially allowing attackers to reconstruct private keys by testing candidate seeds against publicly visible Bitcoin addresses.
Block’s Bitcoin engineering team independently traced the problem to the same random-number implementation. Its analysis found that Mk2 and Mk3 firmware added no cryptographic reseed to the fallback, while Mk4, Q and Mk5 mixed in only a limited secure-element contribution. Coinkite estimates the later models retained about 72 bits of entropy instead of the expected 128 bits, making their exposure less acute but not negligible.
A Galaxy Research on-chain analysis identified three suspected sweep waves totaling 1,367.05 BTC across 4,585 source addresses, valued at approximately $88.6 million at the cited market price. Those figures remain an analytical attribution rather than a loss total formally confirmed by Coinkite, whose investigation is continuing.
The vulnerability affects seed creation rather than transaction signing or physical device extraction. An attacker who reconstructs a weak seed does not need possession of the Coldcard, because the same phrase can reproduce the wallet’s private keys on other compatible software or hardware.
Updating Firmware Is Not Enough
Coinkite has released firmware 4.2.0 for Mk2 and Mk3, version 5.6.0 for standard Mk4 and Mk5 devices, and version 1.5.0Q for the standard Q track, with separate fixed Edge releases. Users must install the correct update before generating a replacement seed, then verify the new backup and receive address before transferring their remaining Bitcoin.
The company advises users to send a small test transaction first and keep the old backup until the complete balance arrives. Rushing the migration can introduce address, backup or passphrase errors, creating a more immediate operational loss than the firmware defect itself.
Seeds supplemented at creation with at least 50 private, independent dice rolls are not considered exposed by this flaw alone. A strong, unique BIP-39 passphrase also creates an additional barrier, although Coinkite still recommends migration. A Coldcard PIN is not equivalent to a BIP-39 passphrase and does not protect a reconstructable seed outside the device.
The incident broadens the original MK3-focused warning into a multi-model remediation effort. The central security action is seed replacement, not only firmware installation, while the eventual scale of theft will depend on further address analysis and confirmation of which observed sweeps were directly connected to the entropy failure.
