Coinkite Warns Coldcard Mk3 Owners: Every Seed Since March 2021 May Be Predictable

Weak wallet seeds put Coldcard users at risk after 594.5 BTC was swept from 500 addresses. (Image: Shutterstock)
Weak wallet seeds put Coldcard users at risk after 594.5 BTC was swept from 500 addresses. (Image: Shutterstock)

Coinkite warned Coldcard Mk3 users to move funds following a 594.5 Bitcoin (BTC) sweep from 500 addresses and evidence of weak seed generation.

Key Points:

  • Every Mk3 firmware release since version 4.0.1 may have generated vulnerable seeds.
  • Mk4, Mk5 and Q users with older firmware must update their devices, generate new seeds and migrate funds.
  • No multisig or Taproot wallets appeared among the reported victims.

Coldcard Seed Risk

Coinkite said in a security advisory that every Mk3 firmware version since 4.0.1, released in Mar. 2021, is affected by an entropy problem tied to device-generated wallet seeds. Seeds created on Mk4 and Mk5 before version 5.6.0, or on Q before 1.5.0Q, also face serious risk.

The company said affected seeds contained about 72 bits of entropy instead of the expected 128 bits, although the impact differs by model. TAPSIGNER, OPENDIME and SATSCARD are not affected because they use separate codebases. A firmware update cannot repair an existing seed.

Users should install fixed firmware before generating a replacement seed, then back it up, verify a receive address on the device and send a small test transaction.

Mk3 owners without another device can temporarily use a strong, unique BIP-39 passphrase, but Coinkite still recommends moving to a newly generated seed.

Also Read: Bitcoin ETFs Absorb $233.1M As A Single Fund Supplies Most Of It

Bitcoin Theft Impact

Atlas21 reported that an automated operation swept 500 single-signature addresses across blocks 960188 through 960191 on Jul. 30. The transactions consumed 1,324 UTXOs and moved 594.5 BTC, valued near $38 million, while costing about 0.044 BTC in fees. No multisig or Taproot addresses were identified.

The median victim lost 0.41 BTC, while 110 addresses lost more than one Bitcoin and the largest loss reached 29.9 BTC. Atlas21 said the transaction pattern pointed to weak private keys generated when the wallets were created. The first public report came from a user whose 24-word seed was generated on a Coldcard in 2021 and never entered on a computer.

The incident matters because offline storage cannot protect funds when the underlying seed lacks sufficient randomness. Coinkite’s warning covers wallets created over more than five years, leaving owners exposed until they migrate, while Bitcoin’s market price remained near $64,000 after the sweep.

Read Next: Polymarket Traders Give Spider-Man A 91% Shot At A Historic Debut

Murtuza Merchant profile photo

Murtuza Merchant

Murtuza is a seasoned finance journalist with extensive experience covering cryptocurrencies and blockchain technology. He has contributed to Benzinga and Cointelegraph, among other publications, reporting on emerging trends, the regulatory landscape, and more. Find him at @murtuza_merc on Twitter and mmerchant001 on Telegram. Disclosure: Murtuza holds ATOM, AKT, TIA, INJ, and OSMO.

Disclaimer and Risk Warning: The information provided in this article is for educational and informational purposes only and is based on the author's opinion. It does not constitute financial, investment, legal, or tax advice. Cryptocurrency assets are highly volatile and subject to high risk, including the risk of losing all or a substantial amount of your investment. Trading or holding crypto assets may not be suitable for all investors. The views expressed in this article are solely those of the author(s) and do not represent the official policy or position of Yellow, its founders, or its executives. Always conduct your own thorough research (D.Y.O.R.) and consult a licensed financial professional before making any investment decision.
Coinkite Warns Coldcard Mk3 Owners: Every Seed Since March 2021 May Be Predictable | Yellow