+1.10%
+0.80%
+2.50%
+2.20%
+2.50%
+0.80%
The Vulnerability: Weak Seeds for Over Five Years
Coinkite, the maker of Coldcard, issued a security advisory warning that every Mk3 firmware release since version 4.0.1 may have generated vulnerable seeds. The problem: these seeds contained only about 72 bits of entropy instead of the expected 128 bits.
That’s a critical shortfall. Less entropy means fewer possible private key combinations, making brute-force attacks feasible. The wallet seeds generated during this period are significantly weaker than they should be. Importantly, a firmware update alone cannot fix seeds that were already generated. If you created a wallet on a vulnerable device, that seed remains compromised even after you update the firmware.
Which Devices Are Affected
The vulnerability spans multiple Coldcard models and firmware versions:
- Coldcard Mk3: All firmware versions since 4.0.1 (March 2021)
- Coldcard Mk4 and Mk5: Firmware older than 5.6.0
- Coldcard Q: Firmware older than 1.5.0Q
TAPSIGNER, OPENDIME, and SATSCARD devices are not affected. They use separate codebases, according to Coinkite.
Attackers Already Exploited This
This is not a theoretical risk. On July 30, an automated operation swept 594.5 BTC (approximately $38 million) from 500 single-signature addresses across blocks 960188 through 960191.
Atlas21 reported the attack pattern showed no multisig or Taproot addresses among the victims. The median loss per address was 0.41 BTC, with the largest single victim losing 29.9 BTC. The sweep happened in minutes, indicating the attacker was using an automated process to target weak private keys.
The transaction timing and pattern strongly point to wallets created when the vulnerability was active. Attackers likely used the weak entropy to reproduce private keys or accelerate brute-force attacks against them.
What You Need to Do Right Now
If you own an affected Coldcard device, follow these steps:
- Update your Coldcard to the latest firmware
- Generate a completely new wallet seed on the updated device
- Back up your new seed phrase securely in a separate location
- Verify a new receive address directly on the device screen
- Send a small test transaction to this new address to confirm it works
- Migrate all remaining funds from old addresses to your new, verified address
For Mk3 owners without a second device: You can temporarily add a strong, unique BIP-39 passphrase to your existing seed for additional protection. However, Coinkite still recommends moving to a newly generated seed as the permanent solution.
Why Offline Storage Alone Isn’t Enough
This incident reveals a hard truth: keeping your hardware wallet offline does not protect you if the seed itself is weak. An air-gapped device provides no security if the underlying private keys can be recovered through brute force.
The vulnerability affects wallets created over more than five years. Users who generated seeds on vulnerable Mk3 firmware during that entire window remain exposed until they migrate their funds. At the time of the attack, Bitcoin was trading near $64,000, making each stolen BTC worth real money.
The urgency here is genuine. If you have Coldcard devices or believe your seeds may have been generated during this window, check your firmware version immediately. Don’t delay moving funds to a newly generated, verified seed.
Follow Hashlytics on Bluesky, LinkedIn, Telegram and X to Get Instant Updates



