Coldcard Warns RNG Bug May Put Bitcoin Funds at Risk Across Mk3, Mk4, Mk5 and Q Wallets

 

By Giuseppe Ciccomascolo // July 31, 2026 @ 11:18 AM Make AlphaWire Logo preferred on Google News
Coldcard Warns RNG Bug May Put Bitcoin Funds at Risk Across Mk3, Mk4, Mk5 and Q Wallets

Share

Point of Focus

  • Coldcard’s seed-generation bug affects Mk3 firmware from version 4.0.1 onward.
  • Users should generate a new seed on updated hardware.
  • No conclusive evidence currently links the vulnerability to the unexplained $38 million Bitcoin wallet sweep.

 

Coldcard maker Coinkite has warned that a seed-generation bug affecting several hardware wallet models may have left users’ Bitcoin funds vulnerable to theft.

In a July 30 security advisory, the Canadian manufacturer said every Coldcard Mk3 firmware release from version 4.0.1 onward is affected. The problem also covers seeds generated on Mk4 and Mk5 devices before firmware 5.6.0 and Coldcard Q devices before version 1.5.0Q.

Coinkite’s early analysis suggests affected Mk4, Mk5 and Q seeds contained approximately 72 bits of entropy instead of the expected 128 bits. Although the issue is less severe on these devices than on the Mk3, the company still described it as serious.

TAPSIGNER, OPENDIME and SATSCARD products are unaffected because they use different codebases.

 

Users told to replace affected seeds

Coinkite urged affected users to migrate their Bitcoin to a new seed generated on updated or unaffected hardware. Mk4 and Mk5 owners should install firmware 5.6.0 or later, while Q users need version 1.5.0Q or later before generating a replacement.

Updating the firmware cannot strengthen a seed that has already been created.

 

 

Users who added at least 50 fair, independent and private dice rolls during seed generation may have supplied enough additional entropy to mitigate the flaw. Anyone unsure how many rolls they entered should migrate.

A strong and unique BIP-39 passphrase also provides an independent security barrier. However, Coinkite stressed that this is not the device PIN and that short, predictable or reused passphrases may still be guessed.

 

Warning follows mysterious $38M Bitcoin sweep

The advisory arrived as researchers investigated a coordinated sweep of 594.48 BTC, worth approximately $38 million at the time.

AnchorWatch CEO Rob Hamilton said 1,324 unspent transaction outputs were moved through 500 transactions within three blocks.

 

 

Wizardsardine CEO Kevin Loaec suggested that weak wallet randomness may have allowed an attacker to brute-force vulnerable seeds.

However, both assessments remain preliminary. No definitive public evidence has connected the Coldcard bug to the 594 BTC sweep.

 

How users can stay secure

Affected users should proceed carefully rather than rushing the migration. Some recommended steps include:

  • Update an unaffected device to the fixed firmware.
  • Generate and securely record a completely new seed.
  • Verify the backup and receiving address on the Coldcard screen.
  • Send a small test transaction and confirm its arrival.
  • Move the remaining funds only after the test succeeds.
  • Keep the old backup until the transfer is fully confirmed.

 

 

Seed words, dice rolls and passphrases should never be photographed, stored digitally or entered into websites or untrusted devices.

Coinkite is exploring a final Mk3 firmware release, but warned users not to wait. Its investigation is continuing, with a formal technical review expected later.

Share

Default avatar

Giuseppe Ciccomascolo

After graduating with a Master’s in Advanced Journalism at the London School of Journalism Giuseppe worked as an analyst and Senior Reporter. In 2017, he transitioned to covering cryptocurrency-related news, producing documentaries and articles on Bitcoin and other emerging digital currencies and played a pivotal role in establishing the academy for a cryptocurrency exchange website.

Table of content

Ad

Related Articles