Loading market data...

Coinkite Warns Coldcard Mk3 Users of Firmware Flaw Affecting Wallet Seeds

Coinkite Warns Coldcard Mk3 Users of Firmware Flaw Affecting Wallet Seeds

Coinkite has issued a warning to users of its Coldcard Mk3 hardware wallet about a firmware flaw that could compromise wallet seeds. The issue lies in the random number generator (RNG) used during seed generation, which may have produced predictable outputs. Anyone who created a seed on a Mk3 device running certain firmware versions is potentially at risk.

Why the RNG matters

Hardware wallets rely on strong random number generators to create wallet seeds — the master keys that control cryptocurrency funds. If the RNG is flawed, the seeds it produces can be guessed or brute-forced by an attacker. Coinkite's advisory didn't specify the exact firmware versions affected, but the company urged all Mk3 owners to treat their existing seeds as compromised.

What users should do now

Coinkite recommends updating the Coldcard Mk3 to the latest firmware immediately. After the update, users should generate a new wallet seed and transfer their funds to the new wallet. The old seed should be discarded and never reused. The company also suggests that users who relied on the Mk3's RNG for other cryptographic operations should review those as well.

The warning applies only to the Mk3 model. Coinkite's newer Mk4 device is not affected. The company has not disclosed how many users might be impacted or whether any funds have been lost as a result of the flaw.

Coinkite said it is investigating the root cause of the RNG weakness and will provide more details once the analysis is complete. In the meantime, Mk3 users are left with a clear but inconvenient task: update, regenerate, and move their coins. The company has not set a deadline for the firmware update, but given the severity, acting quickly is the only safe move.