Share
Subscribe to the AlphaWire Newsletter
Coldcard maker Coinkite has warned that a seed-generation bug affecting several hardware wallet models may have left users’ Bitcoin funds vulnerable to theft.
In a July 30 security advisory, the Canadian manufacturer said every Coldcard Mk3 firmware release from version 4.0.1 onward is affected. The problem also covers seeds generated on Mk4 and Mk5 devices before firmware 5.6.0 and Coldcard Q devices before version 1.5.0Q.
Coinkite’s early analysis suggests affected Mk4, Mk5 and Q seeds contained approximately 72 bits of entropy instead of the expected 128 bits. Although the issue is less severe on these devices than on the Mk3, the company still described it as serious.
TAPSIGNER, OPENDIME and SATSCARD products are unaffected because they use different codebases.
Coinkite urged affected users to migrate their Bitcoin to a new seed generated on updated or unaffected hardware. Mk4 and Mk5 owners should install firmware 5.6.0 or later, while Q users need version 1.5.0Q or later before generating a replacement.
Updating the firmware cannot strengthen a seed that has already been created.
COLDCARD Mk3 Security Advisory
If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk.
Mk4, Q and Mk5 are not affected based on our early analysis.
Read the advisory and migrate carefully:https://t.co/3vgPHOjMS7
— COLDCARD (@COLDCARDwallet) July 30, 2026
Users who added at least 50 fair, independent and private dice rolls during seed generation may have supplied enough additional entropy to mitigate the flaw. Anyone unsure how many rolls they entered should migrate.
A strong and unique BIP-39 passphrase also provides an independent security barrier. However, Coinkite stressed that this is not the device PIN and that short, predictable or reused passphrases may still be guessed.
The advisory arrived as researchers investigated a coordinated sweep of 594.48 BTC, worth approximately $38 million at the time.
AnchorWatch CEO Rob Hamilton said 1,324 unspent transaction outputs were moved through 500 transactions within three blocks.
— Rob Hamilton (@Rob1Ham) July 31, 2026
Wizardsardine CEO Kevin Loaec suggested that weak wallet randomness may have allowed an attacker to brute-force vulnerable seeds.
However, both assessments remain preliminary. No definitive public evidence has connected the Coldcard bug to the 594 BTC sweep.
Affected users should proceed carefully rather than rushing the migration. Some recommended steps include:
THE COLDCARD BITCOIN HARDWARE WALLET SECURITY DEBACLE, WHAT REALLY HAPPENED?
The best AI report -Claude Opus 5 Max- on what actually happened with @COLDCARDwallet. To verify, but seems quite likely, and that means Trezor and Ledger should be fine:
"The Coldcard failure was… https://t.co/VB7lzEOnyi
— Joseph Hurtado – Founder Granata Consulting (@josephfounder) July 31, 2026
Seed words, dice rolls and passphrases should never be photographed, stored digitally or entered into websites or untrusted devices.
Coinkite is exploring a final Mk3 firmware release, but warned users not to wait. Its investigation is continuing, with a formal technical review expected later.
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share