A flaw in the seed generation process of Coldcard Mk3 hardware wallets allows attackers to recreate private keys due to weak randomness sourced from button presses. Bitcoin Core contributor instagibbs reproduced the vulnerable seed on a newly initialized Mk3, confirming the risk. The vulnerability undermines the air gap that hardware wallets are supposed to guarantee — if an attacker can predict the seed, they can derive addresses and monitor for deposits without ever touching the device.
How the flaw works
The Mk3 generates entropy by measuring the timing of user button presses during initialization. That randomness turned out to be far too predictable. The issue affects Mk3 devices running firmware 4.0.1 or later, as well as Mk4 and Mk5 units before firmware 5.6.0, and Q devices before version 1.5.0Q. Coinkite, the company behind Coldcard, published an advisory this week detailing the problem and urging users to migrate.
Who is affected
The highest-risk profile is a Mk3-generated seed used in a single-signature setup with no BIP-39 passphrase, no dice entropy, and no multisig. A strong passphrase adds an independent barrier, but Coinkite still recommends migration. Multisig setups confine the risk to one signer — if the other keys are independent, the overall wallet remains safe. User-supplied dice entropy can mitigate the flaw, but only if at least 50 fair rolls were used; fewer rolls or any uncertainty still requires a full migration.
What users need to do
There is no firmware fix that can change existing keys. The only remedy is to generate a new seed on an unaffected device and transfer all funds. Coinkite recommends verifying the backup, fingerprint, and receive address, then sending a test payment before moving the full balance. The advisory covers Mk3 devices manufactured from March 2021 onward, with the final Mk3 firmware released in June 2023 — meaning there is a roughly three-year window during which dormant holders may still be using vulnerable seeds.
The three-year gap
That gap is the real worry. Anyone who bought a Mk3 in 2021 or 2022, set it up, and then put it in a drawer may not have updated firmware or thought about seed generation. Coinkite's warning is clear: if you have a Mk3 seed generated during that period, assume it is compromised. The company advises moving funds to a new wallet generated on a Mk4, Mk5, or Q device with the latest firmware, or using a different hardware wallet entirely.




