Coldcard Seed Warning

Block's Bitcoin Engineering and Security teams published an advisory on a Coldcard firmware bug that could make wallet seeds easier to reproduce than intended, after reports of active exploitation against users.

CoinDesk reported that roughly 594 BTC, worth about $38 million at the time, was swept from around 500 single-signature wallets in a 25-minute window on Friday. The affected wallets were described as older Coldcard-generated wallets, with funds later consolidated into one address.

The technical issue centers on random-number generation during secret creation. Block said affected firmware could route key generation through MicroPython's deterministic Yasmarang fallback instead of the STM32 hardware random-number generator. For Mk2 and Mk3 firmware in the v4 series, Block assessed that no cryptographic entropy was added to that path. It also said current Mk4, Q and Mk5 firmware used a fallback construction with a limited 32-bit reseed.

Coinkite's advisory is narrower in user guidance. It warned anyone who generated a seed on a Coldcard Mk3 running firmware 4.0.1 or later that funds may be at risk. It also said seeds generated on Mk4 and Mk5 before version 5.6.0, and Q before version 1.5.0Q, are affected with reduced entropy.

Both companies framed their analyses as early. The practical takeaway is immediate migration, not a firmware-only fix: Coinkite said updating cannot repair a seed already generated by affected firmware.