Newsroom
31 July, 2026 / News / AI / Tags: firmware, coinkite, seed, seeds, advisory

Coinkite issues urgent advisory for Mk3 and other models after attacker swept 594 BTC from roughly 500 wallets in under half an hour
An attacker drained approximately 594 bitcoin, valued at around $38 million, from nearly 500 Coldcard hardware wallets in a rapid series of transactions lasting between 15 and 25 minutes on July 30. The Canadian manufacturer Coinkite has issued a security advisory linking the incident to a long-standing flaw in how certain devices generated recovery seeds.
On-chain data showed the attacker moving funds from 500 single-signature addresses across four consecutive blocks. The operation involved 1,324 unspent transaction outputs totaling about 594.5 BTC. Median losses stood near 0.41 BTC, with 110 wallets losing more than one bitcoin and the largest single loss reaching nearly 30 BTC. Transaction fees for the entire sweep amounted to roughly 0.044 BTC. No multisignature or Taproot wallets appeared among the affected addresses. After the initial transfers, a substantial portion of the bitcoin was consolidated into one address.
The first public report came from a user whose Coldcard had generated a 24-word seed in 2021. The seed had never been entered on a networked computer. Security researchers noted patterns consistent with weak private keys produced at wallet creation.
Coinkite determined that a build error caused seed generation on affected firmware to draw randomness from a software fallback inherited from MicroPython rather than the intended hardware random-number generator. Two functions with identical signatures existed in the codebase: one for the hardware source and one for the software alternative. A preprocessor check verified only that a setting was defined, not its value, so the build used the weaker source without raising an error. The problem began with a March 2021 firmware change.
Affected Mk3 seeds carried far less entropy than the expected 128 bits. Coinkite estimated the effective search space for those seeds at roughly 40 bits. Seeds created on Mk4, Mk5 and Q devices before fixed firmware versions retained about 72 bits of entropy because of additional contributions from secure elements. That level remains below the design target and still presents serious risk.
The company stated that TAPSIGNER, OPENDIME and SATSCARD products use different codebases and are not affected. Firmware updates cannot repair an existing seed. Any seed created on vulnerable firmware remains weak even if later restored to a different device.
The advisory covers every Mk3 firmware release from version 4.0.1 through 4.1.9. Seeds generated on Mk4 and Mk5 before version 5.6.0, and on the Q model before version 1.5.0Q, are also impacted, though less severely. Coinkite released fixed firmware: version 4.2.0 or later for Mk3, 5.6.0 or later for Mk4 and Mk5, and 1.5.0Q or later for Q. Users must install the update before generating any new seed.
Coinkite said it believes an attacker likely used artificial intelligence to examine earlier versions of its open-source firmware and locate the bug. The company itself had run a leading AI model over the same code weeks earlier and the review did not identify the issue or any other serious problems.
Coinkite instructed owners of affected seeds to migrate funds to a newly generated seed on a device running fixed firmware. The recommended sequence includes confirming the firmware version, creating and verifying a new seed and its backup, checking a receive address on the device screen, sending a small test transaction, and only then transferring the remaining balance. The old backup should be retained until the full migration is confirmed.
Users who added at least 50 independent dice rolls when creating the original seed are not considered at risk from this specific randomness issue, provided the rolls remained private. Those who used a strong, unique BIP-39 passphrase face reduced risk, though migration is still advised. A device PIN does not provide the same protection.
Owners whose only hardware is an Mk3 can update to version 4.2.0 and generate a replacement seed on the same unit, carefully alternating between the old and new seeds during the transfer process. An optional dice-only path requiring at least 99 independent rolls is also available after the update.
Rival manufacturers confirmed their products are unaffected. Independent analysis by Block’s engineering team supported the assessment that the flaw originated in the Coldcard firmware’s handling of randomness. Bitcoin’s market price remained near $64,000 during and after the incident.
Coinkite continues to investigate and plans further technical details. Until a complete root-cause analysis is published, the timing of the advisory and the large-scale sweep remain closely associated but not formally proven to share a single cause in every reported case.









