A flaw in Coldcard seed generation lets attackers recreate private keys from the press of a button

Coldcard’s seed flaw is forcing affected users to replace their keys and exposing the maintenance risks of long-term Bitcoin storage.

Editorial collage of a cracked hardware-wallet padlock spilling paper seed fragments, with red surveillance beams and a cyan hooded figure suggesting remote attacks on predictable Bitcoin seeds.
Image by CryptoSlate
4 min read

Quick Take

  1. Coinkite told Mk3 owners with seeds generated on firmware 4.0.1 or later to create new keys and move their Bitcoin.
  2. A weak seed can undermine the wallet’s air gap, letting attackers derive candidate addresses and steal funds remotely.
  3. Coinkite has not published the root cause, and owners must verify backups, test transfers, and avoid losing recovery details.

Some Coldcard Mk3 owners may need to move their Bitcoin. Coinkite says funds tied to seeds generated on firmware 4.0.1 or a later Mk3 release may be at risk.

Bitcoin Core contributor instagibbs said he recreated the vulnerable seed on a newly initialized Mk3. Coinkite says Mk4 and Mk5 devices are also affected before firmware 5.6.0, while Q devices are affected before 1.5.0Q; the impact is less severe but still serious. The company plans a formal technical review of the root cause.

A hardware wallet protects an existing key through secure storage, offline signing, and on-device verification. Seed generation precedes those defenses and determines whether the device starts with strong key material.

A seed phrase draws security from entropy, the randomness that selects one combination from an immense field. Weak randomness narrows that field until an attacker can test candidate seeds, derive their addresses, and watch for deposits from another computer.

Predictable creation defeats the air gap at the starting point and turns theft into a remote search problem. An attacker can work from candidate seeds, monitor the corresponding addresses, and spend the funds once a match appears.

Because every existing address remains controlled by the original seed, remediation requires new keys and an on-chain transfer. Updated firmware can secure future setup flows, but it cannot change the key material controlling old addresses.

Security layerWhat it protectsWhy it failed to solve this case
Air gapPrevents the device from exposing keys over a live connectionDoes not help if the seed was predictable at creation
Secure storageKeeps an existing private key isolatedProtects the wrong thing if the original key material is weak
Offline signingLets users approve transactions without connecting the walletOnly protects spending after the seed already exists
On-device verificationLets users confirm addresses and amounts on the hardware screenDoes not prove the seed was generated with enough entropy
Firmware updateCan improve future device behaviorCannot replace old addresses controlled by an already-generated seed
New seed + transferCreates fresh key material and moves funds away from old addressesOnly complete remediation path for potentially weak seeds

The highest-risk custody profile

The clearest exposure profile begins when an affected Mk3 generated the seed and one signature controls the wallet. Zero dice entropy, zero BIP-39 passphrase, and zero multisig leave the device’s seed generator as the only cryptographic root.

Coinkite says a strong, unique BIP-39 passphrase adds an independent barrier, while short, common, patterned, quoted, or reused passphrases may be guessable. The passphrase differs from the device PIN and derives a separate wallet from the same mnemonic, so an attacker must recover both secrets. Even with a strong passphrase, Coinkite advises migrating to a newly generated seed.

A multisig can confine a single weak seed to a single signer when the spending threshold requires independent keys. User-supplied dice can add an external entropy source, and Coinkite’s advanced path specifies at least 99 fair rolls through its dice-only import flow.

Those protections demand careful records and tested recovery. A lost passphrase can lock out the owner, a poorly documented multisig wallet can complicate recovery, and exposed dice records can disclose the replacement seed.

Coinkite tells users to verify the backup, fingerprint, and receive address, send a small test payment, then move the balance. That sequence limits the chance that urgency causes a second failure due to a mistyped address, a weak temporary wallet, or an incomplete backup.

Custody setupRisk levelWhy it matters
Mk3-generated seed, single-sig, no passphrase, no dice, no multisigHighestThe affected seed is the only cryptographic root protecting the wallet
Mk3-generated seed with BIP-39 passphraseLower only with a strong, unique passphraseThe attacker would need both the mnemonic and the separate passphrase
Mk3-generated seed with multisigLower if other signers are independentOne weak seed is not enough to spend if the threshold requires other keys
Mk3-generated seed with user-supplied dice entropyLower if at least 50 fair, private rolls were addedFewer than 50 rolls, or uncertainty about the rolls, still requires migration
New seed on unaffected deviceRemediation pathFunds move to fresh key material outside the affected setup
Panic migration to unverified wallet or addressNew failure riskUrgency can create losses unrelated to the original flaw

Cold storage acquires a maintenance schedule

Coinkite released the final Mk3 firmware in June 2023, and its July 2026 advisory covers seeds that Mk3 devices created from March 2021 onward, placing a three-year gap between product support and an urgent custody action.

That gap turns cold storage into a legacy-maintenance problem. Dormant holders may power on a device once every few years, old product pages lose visibility, and owners may miss manufacturer notices for months.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

You’re subscribed. Welcome aboard.

A seed can outlive its device, firmware branch, and original support channel, so custody systems need durable alerts and repeatable migration procedures. Manufacturers can publish entropy architecture, device-specific advisories, and key-rotation playbooks that stay accessible for years beyond the final sale.

Coinkite’s security documentation describes open code and reproducible builds as inspection tools. Reviewers can compare the source with the released binaries, and defects can persist until someone studies the exact code path that generated a dormant seed.

That distinction makes independent entropy testing a core hardware-wallet practice. A reproducible binary tells a buyer which code ran, and assurance about every security assumption requires separate testing.

In the bull case, affected users rotate keys carefully, Coinkite publishes the root cause, and wallet makers adopt stronger entropy tests and durable alert channels. Passphrases, multisig, and independent randomness gain broader use, giving holders several cryptographic barriers around one balance.

What happens nextBull-case outcomeBear-case outcome
User migrationAffected users rotate keys carefully after test transactionsDormant users miss the advisory and keep receiving funds to old addresses
Root-cause reviewCoinkite publishes a clear technical explanationUncertainty widens around old firmware or device assumptions
Passphrase adoptionMore holders add a second secret to cold storageLost or poorly recorded passphrases create recovery failures
Multisig adoptionLarge balances move away from single-device failure pointsPoorly documented multisig setups create operational risk
Entropy testingManufacturers improve public testing of seed-generation pathsUsers continue assuming reproducible builds prove randomness quality
Alert systemsWallet makers build durable advisory channels for old devicesSecurity notices remain easy for long-term holders to miss
Market narrativeThe issue becomes a custody-process upgrade momentUnverified theft claims and panic transfers dominate the story

In the bear case, dormant Mk3 wallets continue to receive deposits using old seeds, and owners discover the advisory through theft reports or emergency outreach. Panic transfers create extra losses through unverified addresses, weak temporary wallets or misplaced backups, and unsupported claims tie unrelated on-chain movements to the flaw.

Hardware wallets made self-custody practical by protecting keys during storage and spending.

Now, the Coldcard warning extends that security model across setup, monitoring, and rotation, turning every seed into a long-term maintenance obligation that can outlive the device that created it.

$63,899.79 -0.95% 24 hour change
1H +0.35% 24H -0.95% 7D -1.57%
30D +8.99% 60D -12.08% 90D -18.37%

Bitcoin is -0.95% over the past 24 hours and currently sits at rank #1 by market cap.

Market cap $1.28T
Volume (24h) $27.01B -11.63%
Circ. supply 20.06M
FDV $1.34T
Crypto Market Summary

Where the broader market sits right now

Right now, the total crypto market is valued at $2.19T with $61.46B in 24-hour volume. Bitcoin dominance sits at 58.66%. Explore the market

Global market cap $2.19T
24H market volume $61.46B
Bitcoin dominance 58.66%