Coinkite has issued an urgent warning that Bitcoin funds stored on certain Coldcard hardware wallets may be at risk due to a firmware bug that weakened the entropy of generated seed phrases. The issue affects every Mk3 firmware release since version 4.0.1, released in March 2021, as well as Mk4 and Mk5 units running firmware before version 5.6.0, and Q devices before version 1.5.0Q. Seeds generated on those devices have roughly 72 bits of entropy instead of the expected 128 bits — a gap that makes them vulnerable to brute-force attacks.
The vulnerability
The problem stems from a flaw in the random number generation used during wallet creation. Coinkite said the reduced entropy means an attacker with enough computing power could reconstruct a seed and drain funds. The company stressed that TAPSIGNER, OPENDIME, and SATSCARD are not affected because they use different codebases. The advisory came after reports on July 30 that Bitcoin had been drained from Coldcard wallets.
The Atlas21 sweep
On July 30, Atlas21 reported that an automated operation swept 500 single-signature addresses across four consecutive blocks (960188 to 960191). The operation moved 1,324 UTXOs totaling 594.5 BTC — worth roughly $38 million at current prices. Evidence pointed to weak private keys generated when the wallets were created. No multisig or Taproot wallets were among the victims. The median loss was 0.41 BTC; 110 victims lost more than one Bitcoin; the largest single loss was 29.9 BTC. The operation cost the attacker about 0.044 BTC in transaction fees.
The first public warning came from a victim on Reddit, who said their Coldcard had generated the 24-word seed phrase in 2021 and that the seed had never been entered on a computer. That detail ruled out the usual phishing or malware vectors, pointing squarely at the hardware itself.
What users should do
Coinkite urged users with affected seeds to migrate funds to a newly generated seed on an unaffected device. For Mk4 and Mk5 users, the first step is to upgrade to firmware version 5.6.0 or later. Q users should install version 1.5.0Q or later before generating a replacement seed. The company advised users to back up and verify the new seed, confirm a new receive address on the device, and send a small test transaction before moving the remaining funds.
If an Mk3 is the only option available, Coinkite recommends using a strong, unique BIP-39 passphrase and carefully verifying the wallet fingerprint and receive address. That workaround doesn't fix the underlying entropy issue but adds an extra layer of protection.
Bitcoin's price remained unfazed, continuing to trade near $64,000.
Next steps
Coinkite has not announced a timeline for a permanent fix for the Mk3 line, but the company is urging all affected users to act now. Anyone who generated a seed on a Coldcard Mk3 since March 2021, or on an Mk4, Mk5, or Q before the patched firmware versions, should treat those funds as compromised and move them immediately. The Atlas21 sweep shows the window for safe migration may already be closing.


