Go to app

Technical Root Cause

Published 7/31/2026, 12:27:01 PM

The Coldcard Mk3 seed vulnerability is classified as critical, following a coordinated exploit on July 30, 2026, that drained 594.48 BTC (approximately $38.3 million) from roughly 500 single-signature wallets [Source: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/]. The attack was highly efficient, occurring within a 25-minute window across Bitcoin blocks 960188–960191 [Source: https://www.reddit.com/r/Bitcoin/comments/1vb91uc/wallet_drain_megathread_check_your_balances/].

Technical Root Cause

The vulnerability originated from a firmware configuration error introduced in March 2021 (Firmware 4.0.0). A build setting caused the device to bypass its hardware random number generator (RNG), falling back to a predictable software-based method using the chip's serial number and clock registers [Source: https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware]. This reduced the entropy of generated seeds from the standard 128 bits to approximately 72 bits, making them vulnerable to brute-force attacks [Source: https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware].

Risk Assessment by Device and Firmware

The risk is determined by the firmware version active at the time the wallet seed was initially generated.

Device ModelRisk LevelAffected Firmware VersionsStatus
Coldcard Mk3Critical4.0.1 through 5.0.3Confirmed exploited [Source: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/]
Coldcard Mk2High4.0.0 and laterLikely vulnerable due to shared codebase
Mk4, Q, Mk5ModeratePre-fixed versionsReduced entropy (72-bit); no confirmed drains
Mk1SafeN/ADoes not run the affected codebase
TapsignerSafeN/AEntirely different codebase

Severity and Real-World Impact

Mitigation and Current Status

Coinkite has released updated firmware to address the RNG fallback issue. However, updating the firmware does not fix a seed that was already generated under the vulnerable versions.

  1. Immediate Migration: Users who generated seeds on affected Mk3/Mk2 devices must migrate funds to a newly generated seed on a patched device (Mk4/Mk5 v5.6.0+ or Q v1.5.0Q+) [Source: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/].
  2. Dice-Roll Method: To ensure maximum security regardless of firmware, users are encouraged to use the physical dice-roll method (99+ rolls) to generate seeds, which bypasses the internal RNG entirely [Source: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/].
  3. Multisig: Moving funds to a multisig setup (e.g., 2-of-3) using hardware from different vendors is the most robust defense against single-device vulnerabilities.

The vulnerability is considered "resolved" in terms of software patches, but the "unresolved" risk remains for any user still holding funds in a seed generated on vulnerable Mk3 firmware between 2021 and mid-2026.