Green Bitcoin Crash road sign with an upward arrow against a cloudy blue sky.
TECHNOLOGY

Coldcard Warns Users After Bitcoin Seed Flaw

Image credit: Shutterstock

Coldcard has warned users to replace wallets generated on affected firmware after a random-number flaw left some Bitcoin seeds with far less entropy than intended. The advisory followed a coordinated July 29 sweep initially linked to 594.48 BTC, worth about $38 million.

Bitcoin Optech later said estimated losses tied to the wider incident had exceeded 1,000 BTC as analysis continued. Coinkite has released fixed firmware for Mk3, Mk4, Mk5 and Q devices, but existing seeds created on vulnerable versions remain exposed.

Mk3 Seeds Had 40 Bits of Entropy Instead of 128 

The flaw entered Coldcard firmware in March 2021 when seed generation was moved to a software random-number function. That function unexpectedly resolved to MicroPython’s deterministic fallback generator instead of the device’s hardware random-number generator.

Coinkite estimates affected Mk3 seeds had about 40 bits of effective entropy rather than the intended 128 bits. Block’s Bitcoin engineering team independently traced the issue to the same software fallback and said active exploitation should be assumed.

Affected Mk3 firmware runs from version 4.0.1 through 4.1.9. Coinkite also warned that seeds generated on Mk4, Mk5 and Q devices before newly released fixes had reduced entropy, although it said additional secure-element randomness made those wallets harder to attack.

July 29 Sweep Moved 594.48 BTC in About 500 Transactions 

Security researchers began investigating after hundreds of single-signature wallets were emptied within a narrow block window on July 29. Early analysis identified about 594.48 BTC moving through roughly 500 transactions before much of the balance was consolidated.

Initial reporting valued that sweep near $38 million. By July 31, Bitcoin Optech said estimated losses tied to the broader incident had risen above 1,000 BTC as more affected wallets were identified.

Researchers have reproduced the weakness, but attribution of every stolen wallet to the same attacker remains under investigation.

Firmware Updates Cannot Protect Previously Generated Seeds 

Coinkite released Mk3 firmware 4.2.0, Mk4 and Mk5 version 5.6.0, and Q version 1.5.0Q, alongside separate fixed releases for Edge firmware.

Updating prevents vulnerable seed generation but does not strengthen a seed created earlier. Users are being told to generate a new seed on fixed firmware, verify the backup and receiving address, send a small test transaction, and then migrate the remaining balance.

Seeds created with at least 50 independent private dice rolls are not considered exposed to this RNG issue alone. Strong BIP-39 passphrases add another barrier, but Coinkite still recommends migrating affected wallets.

More For You

Explore More News