Coinkite's Coldcard Mk3 security advisory, published on July 30–31, 2026, warns that seeds generated on the hardware wallet after firmware version 4.0.1 may carry far less randomness than promised.

The warning came right after a fast theft. Around 594 BTC, worth about $38 million, moved out of roughly 500 wallets in minutes.
The Coldcard Mk3 vulnerability bug sat inside a small piece of code called libngu. It was supposed to pull randomness (random numbers) from the device's hardware chip, STM32. Instead, it quietly used a weaker, software-based method called Yasmarang.
That weaker method built its randomness from things like the device's serial number, internal clock, and button presses. Those things are not very random at all.

Coinkite security advisory describes this seed generation vulnerability as capable of shrinking Mk3 entropy down to roughly 40 bits, far below the 128-bit target for a secure 12-word phrase.
Newer devices did a bit better. The Mk4, Q, and early Mk5 models mixed in some extra hardware randomness, landing around 72 bits. Still not perfect, but far safer than the the vulnerable device.
Older wallets took the biggest hit of this Coldcard Mk3 vulnerability. Many of the drained wallets had sat untouched since 2021. The stolen coins were moved fast, then mostly gathered into one address.
Risk depends a lot on how the wallet was first set up:
Owners with no passphrase and no dice rolls face the highest risk.
Rolling real dice 50 times or more during setup makes a seed much harder to guess.
A strong BIP-39 passphrase builds a whole new wallet on top of the old seed, out of reach of the bug.
TAPSIGNER, OPENDIME, and SATSCARD use different code and are not affected.
Coinkite admitted its own past reviews, even ones that used AI tools, missed this bug for years. That points to a hard truth: any AI code review exploit that helps a company find bugs can just as easily help someone else find them first.
This Coldcard migration guide starts with one rule: move carefully, not fast. Rushed transfers cause far more lost funds than patient ones.
The team recommended recovery steps include:
Reviewing exactly how the original seed was created and on what firmware version.
Upgrading to fixed firmware where Coinkite has released one.
Generating a fresh seed on a secure, updated device rather than reusing the old one.
Verifying the new backup and XFP fingerprint on-screen before trusting it.
Sending a small test transaction first, then migrating the remaining balance in stages.
Keep the old backup safe until the new wallet is fully working.
BIP-39 passphrase protection remains the single fastest mitigation available today. Adding a strong, unique passphrase on-device creates an entirely new wallet path that sidesteps the flawed seed.
This Bitcoin hardware wallet security incident also reinforces older self-custody advice that often gets skipped in practice. Multisig setups across different vendors, external entropy sources, and periodic seed reviews all reduce dependence on any single device's random number generator.
Coinkite's investigation continues , and further technical detail is expected as the review progresses. For now, the Coldcard Mk3 vulnerability lesson holds steady: hardware wallets are only as strong as the randomness behind them, and that randomness deserves regular scrutiny, not blind trust.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Crypto markets carry significant risk. Always do your own research before making any investment decisions.
4 hours ago
I responded to an advertisement involving a Dutch model, and shortly afterward I was contacted by Mark Grams, who claimed to be a professional investment adviser. After six weeks of building trust with me, he convinced me to convert both my investment and my father's portfolio into crypto. In total, I transferred €1.6 million worth of crypto to what I believed was a legitimate investment platform. When I later asked to access my funds, I was told that my account had been blocked and that I needed to transfer more money to unlock it. That was when I realized I had been scammed. After filing a police report with little progress, I hired a legal team, who then contacted Morphohack Cyber Service via email (MORPHOHACK@CYBERSERVICES.COM). They used blockchain analysis to trace the stolen crypto, and the trail led to several crypto exchanges, including HTX. However, Morphohack was able to recover all the crypto that had been funnelled through their network. Recovering my funds also helped uncover a broader network of alleged crypto-related crimes. After I lost my funds, I felt like the ground beneath me was about to explode, Morphohack brought me back to life with their professional help. I highly recommend Morphohack and their incredibly helpful team.