Coinkite Confirms Coldcard Firmware Bug Silently Weakened Seed Generation Since 2021

Coinkite disclosed on July 30 that a firmware bug had silently weakened the random number generator on Coldcard hardware wallets since March 2021. Devices running the affected firmware fell back to predictable entropy derived from device details instead of true randomness when generating a new seed.
WHAT COINKITE DISCLOSED
The bug lived in Mk3 firmware versions 4.0.1 through 4.1.9, going back to March 2021. It also affected seeds generated on Mk4, Mk5, and Q devices running firmware before the fixed release for each model. Coinkite says the flaw cut effective entropy on Mk4, Mk5, and Q seeds to roughly 72 bits instead of the intended 128. The company has not published a specific bit-strength estimate for Mk3 seeds in its public advisory.
Coinkite calls this an early analysis. The investigation is ongoing, and a formal technical review is still coming.
WHICH DEVICES ARE AT RISK
Affected: Mk3 on firmware 4.0.1 through 4.1.9. Mk4 and Mk5 on Standard firmware before 5.6.0, or Edge firmware before 6.6.0X. Q on Standard firmware before 1.5.0Q, or Edge firmware before 6.6.0QX. Standard and Edge are separate release tracks, and Coinkite warns not to assume an older Edge build is safe just because its version number looks newer than a Standard release.
The risk applies only to seeds generated using the device's own random number generator. Updating the firmware does not repair a seed that already exists. It only protects a seed generated after the update.
WHO IS NOT AT RISK
Coinkite lays out two exceptions. Users who entered at least 50 independent, private dice rolls when creating their seed picked up at least 128 bits of entropy from the dice alone, hashed together with the device output. At 99 rolls or more, the dice contribute close to 256 bits. Fewer than 50 rolls, or an owner who cannot remember the count, means Coinkite treats the seed as affected.
A strong, unique BIP-39 passphrase adds a separate barrier, but Coinkite is explicit that the protection depends on the passphrase's strength. A short, common, patterned, or reused passphrase should not be treated as safe. Even with a strong passphrase, Coinkite recommends migrating to a new seed when practical.
TAPSIGNER, OPENDIME, and SATSCARD run different codebases and are not affected.
WHAT TO DO NOW
Update first. Fixed firmware is out for every affected track: Mk3 version 4.2.0, Mk4/Mk5 Standard version 5.6.0, Q Standard version 1.5.0Q, Mk4/Mk5 Edge version 6.6.0X, and Q Edge version 6.6.0QX. Do not generate a new seed until the update is installed.
If an existing seed falls in the affected range and neither exception applies, generate a fresh seed on the updated device, verify the backup and wallet fingerprint, send a small test transaction, and only then move the rest of the funds. Keep the old backup until the new wallet is confirmed working. Coinkite's advisory includes a full walkthrough for migrating with a single Mk3 device, since that requires carefully alternating between the old and new seed on the same hardware.
Move calmly. Coinkite's own advisory warns that rushing a migration can create more risk than the bug itself.
Read Coinkite's full advisory here: blog.coinkite.com/coldcard-mk3-seed-generation-warning
If you have been affected by this, we want to hear your story. Reach out at hello@simplybitcoin.com.
THE THEFT REPORTS
Social media reports tied to this disclosure describe a sweep of roughly 594 BTC from several hundred wallets in a short window. Coinkite's published advisory does not confirm this figure, name a specific loss total, or link any theft to the entropy bug directly. Treat the circulating numbers as unverified until Coinkite's promised technical review lands, and act on the firmware fix regardless of whether that specific figure holds up.
THE LESSON
A single closed loop, even one that has been open source and reviewed for years, can carry a silent failure for half a decade before anyone notices. The setups least exposed to this bug were the ones that never depended on one device's random number generator working correctly: an independently rolled dice seed, a passphrase strong enough to matter, or a seed checked against a second tool before funds arrived.
Coinkite says its investigation continues and more details are coming. Check the model and firmware version against the ranges above, and migrate if it falls in them.


