Key Takeaways
- Seeds generated on a Coldcard Mk3 running firmware 4.0.1 (March 2021) or later may be at risk, through the final Mk3 release, 5.0.3.
- Roughly 594.48 BTC left 500 single-signature addresses inside a three-block window; Coinkite has not linked the sweep to the flaw.
- Coinkite says Mk4, Mk5 and Q are unaffected and can be used to generate a replacement seed.
- Exposure depends on the firmware running when the seed was created, not on when the device was bought.
The company’s July 30 advisory tells users to treat a seed as potentially at risk if it was generated on an Mk3 running firmware 4.0.1, released in March 2021, or any version after it. The issue persists through 5.0.3, the last firmware to support the model.
Coinkite describes the notice as early analysis with a formal technical review to follow, and has published no explanation of the entropy failure, no count of affected devices and no figure for funds lost.


English (US)