Coinkite urges Coldcard hardware wallet users to migrate funds over seed flaw

Coinkite urged Coldcard hardware wallet owners to transfer their Bitcoin to new seeds following a vulnerability in key generation. The flaw affects Mk3 devices running firmware 4.0.1 or later, as well as Mk4, Mk5, and Q devices on older firmware versions. Weak entropy allows attackers to predict private keys remotely and bypass air-gap protections. Users with single-signature setups without passphrases face the highest risk and must migrate their funds immediately.
Key takeaways
- 1Coinkite advised Coldcard Mk3 users with firmware 4.0.1 or later to generate new keys and move Bitcoin.
- 2Mk4, Mk5, and Q devices running older firmware versions are also impacted by the seed flaw.
- 3Firmware updates cannot fix existing wallet seeds, requiring users to perform complete on-chain migrations.
Coins in this story
Why it matters
Hardware wallet seed generation flaws undermine self-custody security assumptions, exposing cold storage funds to remote theft regardless of air gaps. Investors must monitor security advisories and promptly update firmware or rotate keys to mitigate systemic custody risks.
Discussion
Related stories

New York sues prediction market Kalshi over unlicensed gambling claims
New York State has sued prediction-market platform Kalshi, alleging it operates an unlicensed gambling platform offering illegal sports, election, and event wagers. The lawsuit filed in New York Supreme Court seeks triple Kalshi's financial gains and penalties of $100,000 per unauthorized offer. Regulators also accuse Kalshi of permitting underage betting. The enforcement action intensifies legal scrutiny on prediction markets nationwide, potentially threatening valuation targets and user growth across decentralized platforms.

Coldcard firmware flaw leads to $38 million bitcoin wallet drain
An attacker exploited a randomness vulnerability in certain Coldcard hardware wallets to drain 594 BTC, worth approximately $38 million, across 500 single-signature accounts in under 30 minutes. The flaw, introduced in March 2021 firmware, forced key generation to rely on predictable nonsecret chip data rather than true hardware randomness. Coinkite urged affected users to transfer funds, while market prices for bitcoin remained stable above $64,000 despite the swift, widespread theft.

US sanctions Iranian firms over bitcoin maritime insurance scheme
The U.S. Treasury sanctioned two Iranian entities, Persian Gulf Marine Insurance and HormuzSafe Marine Services, for running an extortion scheme. The platform accepted bitcoin and other digital assets to bypass sanctions, forcing commercial ships in the Strait of Hormuz to buy coverage linked to Iran's Revolutionary Guard. Iranian media claimed the initiative could generate $10 billion. Interacting with these entities now exposes global crypto users and entities to secondary U.S. sanctions.