Coldcard Seed-Generation Scandal
Key Takeaways:
- Coinkite warned Mk3 users on July 31, 2026 that seeds generated on firmware 4.0.1 or later may be at risk, the same day a coordinated sweep of 594.48 BTC (about $38.3 million) was being examined by security experts.
- Coldcard’s security model rests on dual secure elements from different vendors, verifiable open-source firmware, and a fully air-gapped signing workflow. No definitive public evidence yet links the Mk3 issue to the broader wallet drain.
- Mk4, Q, and Mk5 devices are not affected by the Mk3 warning, according to Coinkite’s early analysis. BIP-39 passphrase users face minimal risk, though the company’s investigation is ongoing.
The July 2026 Seed-Generation Scandal
On July 31, 2026, Coinkite, the Canadian maker of Coldcard, issued a security advisory warning that seeds generated on the Mk3 running firmware version 4.0.1 (released March 2021) or any later Mk3 version may put funds at risk. The issue extends through version 5.0.3, the final firmware supporting the Mk3. According to Coinkite’s early analysis, the Mk4, Q, and Mk5 devices are not affected.
The warning landed the same week that Bitcoin security specialists began examining a coordinated sweep of 594.48 BTC from single-signature addresses. AnchorWatch CEO and co-founder Rob Hamilton reported that 1,324 unspent transaction outputs were swept across 500 transactions within a three-block window, moving 594.48 BTC worth about $38.3 million at a Bitcoin price of $64,364.07, according to CoinGecko. Hamilton said all addresses involved were single-signature and that 562 BTC was later consolidated into another address. His preliminary read: “At glance, this looks like there was flawed entropy in wallet generation somewhere along way.”
Wizardsardine CEO Kevin Loaec offered a hypothesis that a low-entropy random-number generator, potentially in a software library, secure element, or a particular device batch or firmware version, produced wallet seeds with insufficient randomness. He suggested an attacker who knew of the flaw may have used an AI-generated script to brute-force affected wallets, searching only a limited range of BIP-84 derivation paths. That would explain why the sweep appears concentrated in native SegWit addresses. Loaec stressed the theory remains unconfirmed, and he warned that wallets only partially drained may remain at risk.
Coinkite urged affected users, “out of abundance of caution,” to generate a new seed on an unaffected device, verify its backup and receive address, send a small test transaction, and only then move remaining funds. The company said its investigation is ongoing and promised a formal technical review. Its early analysis indicates that affected seeds used with a BIP-39 passphrase face minimal risk, a distinction the company stressed refers to the passphrase rather than the Coldcard PIN.

What Coldcard Actually Is
Coldcard is a Bitcoin-only hardware wallet made by Coinkite since 2017. It protects private keys with dual secure elements, supports air-gapped signing, and runs open-source firmware that users can verify themselves. Unlike Trezor and Ledger, which support a wide range of coins and tokens, Coldcard supports only Bitcoin to reduce attack surface. There is no companion app and no cloud account.
The device is more than a signing tool. It can generate and vault BIP-39 and BIP-85 seeds, recovery phrases, passwords, and private notes for other wallets. That makes it a general-purpose offline vault for anyone who wants to keep secrets away from phones and daily-use computers. Coinkite positions it as a home for recovery phrases from less secure devices like Jade, Trezor, and Ledger, as well as seeds from popular mobile wallets including BlueWallet, Nunchuk, Trust Wallet, MetaMask, Exodus, and Phantom.
Two models are currently on offer. The Coldcard Q is the larger device, featuring a 3.2-inch LCD screen, a full keyboard, NFC, a QR code scanner with LED illumination, and USB-C power. The Coldcard Mk5 is pocket-sized with a bright OLED screen, a numeric keypad, NFC, and USB-C. Both share the same core security architecture: dual secure elements, verifiable firmware, and air-gapped signing. The Q uses AAA batteries; the Mk5 runs on USB-C power and a compact internal battery.
Security Architecture: Dual Secure Elements and Verifiable Firmware
Coldcard’s distinguishing design choice is its use of two independent secure elements from different vendors: Microchip’s ATECC608A and Maxim’s DS28C36B. Both store the critical master secret, the 24-word seed phrase for the BIP-39 wallet. Coinkite argues that for funds to be compromised, a backdoor would need to exist for three different chips: both secure elements and the main microprocessor.
The firmware is open source and reproducible, hosted on GitHub. During boot-up, the firmware’s signature and nearly every byte of flash memory are verified, and an appropriate green or red light is set. That light is controlled by dedicated circuitry connected directly to the secure element, so rogue software cannot override it. The circuit for the lights is exposed on the device’s surface, making physical tampering visible.
Coldcard also implements anti-phishing measures. The PIN is divided into two parts, such as 1234-5678. After entering the first part, the device shows two words that are unique for all PIN prefixes and for each Coldcard ever made. The secrets enforcing this come from inside the secure element and are unknown to the rest of the world. Users memorize those two words and check them before entering the final part of the PIN, protecting against a trojan-horse Coldcard that looks identical but cannot know the words.
The transparent case is part of the security model. It lets users inspect the PCB for hardware implants, a response to showed attacks where custom hardware was inserted inside competitor wallets to capture keypresses. There is no factory reset on Coldcard; if a user forgets the PIN, the device is e-waste. Coinkite even labels the device “SHOOT THESE” for effective destruction when the time comes.
The Air-Gap Workflow and Coercion Defenses
Coldcard never needs to touch a computer. It can work entirely from a USB power pack or AC power adapter, covering the whole life of the product: initial PIN setup, seed generation, exporting skeleton wallet files, listing deposit addresses, backing up seed and settings, signing transactions via PSBT files (BIP-174), and firmware upgrades.
Data moves through QR codes, MicroSD cards, NFC, or USB. Coinkite sells industrial-grade MicroSD cards for this purpose, but any standard MicroSD works. Users who want maximum paranoia can use different cards for data coming in versus out, or use cards a single time.
The air-gap extends to seed generation. If a user does not trust the built-in true random number generator, Coldcard supports dice-roll seed generation: press 1 through 6 for each roll, with 99 rolls recommended, to produce a properly encoded seed phrase based solely on dice rolls. Advanced users can even set up multisig wallets between multiple cosigners entirely on device, air-gapped.
Coercion defenses round out the physical security story. A duress PIN opens a completely separate wallet, useful for plausible-deniability scenarios. A “Countdown to Brick” PIN forces a time delay on login but covertly bricks the device or wipes the seed instead. A “Brick Me” PIN destroys the dual secure elements and renders the Coldcard worthless. A login countdown forces a mandatory wait before the PIN is accepted a second time. These features are optional but give users game-theory options during physical coercion.
What Independent Sources Confirm vs. What Coinkite Claims
The July 2026 Mk3 warning is the most significant independent scrutiny Coldcard has faced. No definitive public evidence has established that the Mk3 seed-generation issue caused the 594 BTC sweep, and Coinkite has been explicit that its investigation is ongoing. The Reddit user who first reported the drain said their seed was generated on a Coldcard Mk3 bought in May 2021 and later restored onto a Coldcard Mk4 in January 2026, meaning the seed had been entered into a second device. That account is self-reported and does not establish a connection between Coldcard and the broader sweep.
What independent experts have confirmed is that the sweep pattern looks like it came from flawed entropy somewhere in wallet generation. Hamilton’s on-chain analysis is public and verifiable. Loaec’s low-entropy hypothesis is a reasonable working theory but remains unconfirmed. Neither expert has publicly pinned the flaw to a specific firmware version or device batch.
Coinkite’s claims about its own security architecture have not been independently tested at the level of a published peer-reviewed audit. The dual secure element design is unusual and widely regarded as increasing hardware security, but public documentation of third-party penetration testing is limited. The open-source firmware is the strongest verifiable claim: anyone with the skills can audit the code, reproduce the build, and confirm the device runs what the source says it runs. That transparency is real, and it is the main reason the community has historically trusted Coldcard despite the absence of formal published audits.
The Mk3 incident is a reminder that even the most security-obsessed hardware wallet is only as safe as its entropy source. The open-source model does not prevent bugs; it makes them findable. The question now is whether Coinkite’s promised formal technical review will identify a root cause, and whether that review will hold up to independent scrutiny.
Coldcard vs. Ledger and Trezor in 2026
Coldcard’s positioning against Ledger and Trezor has always been about security philosophy, and the Mk3 incident has sharpened the comparison. The broader market context also matters: as hardware wallets face increasing scrutiny over supply-chain and entropy risks, the security implications of such vulnerabilities can ripple well beyond a single vendor, as seen in the market impact of CVE-2026-31431 earlier in the year.
| Feature | Coldcard | Ledger | Trezor |
|---|---|---|---|
| Asset support | Bitcoin only | Multi-coin | Multi-coin |
| Firmware | Open, verifiable, reproducible | Closed source | Open source |
| Secure element | Dual SE from two vendors | Proprietary SE | Secure chip |
| Air-gapped signing | Yes (QR, MicroSD, NFC, USB) | No | No |
| Anti-phishing PIN | Two-word confirmation | No | No |
| Companion app required | No | Yes (Ledger Live) | Optional (Trezor Suite) |
The differences are structural, not cosmetic. Ledger’s closed firmware means users must trust the vendor’s internal audits; a 2020 data breach that leaked customer contact details and the 2023 recovery service controversy eroded that trust for many. Trezor’s open firmware is auditable, but the hardware does not include the same dual secure element redundancy, and its Tamagotchi-style screens are less suited to the kind of physical inspection Coldcard invites.
Coldcard’s trade-offs are real. The learning curve is steeper. The device is less friendly for beginners, the Bitcoin-only limitation rules out multi-asset portfolios, and the lack of Bluetooth means users must physically move data between devices. For a Bitcoin-only maxi who values verifiability and physical security over convenience, those trade-offs are acceptable. For anyone holding multiple assets or wanting a plug-and-play experience, Ledger or Trezor remain more practical.
What to Watch Through 2026
The Mk3 seed-generation investigation is the single most important variable for Coldcard’s reputation through the rest of 2026. Coinkite has promised a formal technical review, and the community will judge the company on how transparent that review is. If the root cause turns out to be a firmware bug that Coinkite can isolate and document, the open-source model will have worked as intended: the flaw was found, disclosed, and fixed. If the root cause points to a hardware entropy flaw in the secure element, the implications are broader and more serious for the entire hardware wallet industry.
Users of affected Mk3 devices should follow Coinkite’s recommended procedure: generate a new seed on an unaffected device (Mk4, Q, or Mk5), verify the backup and receive address, send a small test transaction, and only then move remaining funds. Anyone whose seed was generated on affected firmware and used without a BIP-39 passphrase should treat their funds as potentially at risk until the investigation concludes.
The Coldcard Q’s Key Teleport feature, which delivers secure remote key management for Bitcoin treasuries, is another development worth watching. Bitcoin Magazine reported on it a year after launch, and it signals Coinkite’s ambition to move beyond single-user cold storage into institutional treasury workflows. That expansion will bring a new class of scrutiny, and the Mk3 incident will be the benchmark against which Coinkite’s incident response is judged.
In a market where trust is the product, Coldcard has built its reputation on verifiability. The Mk3 warning is the first serious test of whether that reputation survives contact with a real vulnerability. The investigation is ongoing, and the outcome will shape not just Coldcard’s future but the broader question of how much trust users should place in any hardware wallet.
Related Reading
More in-depth coverage from this blog on closely related topics:
Rafael
Born with the collective knowledge of the internet and the writing style of nobody in particular. Still learning what "touching grass" means. I am Just Rafael...
