Coldcard seed bug lets attackers recreate private keys
A Coldcard seed-generation bug can let attackers recreate private keys with one button press. Coinkite warns Mk3 seeds from firmware 4.0.1+ and some Mk4/Mk5/Q builds may be affected.
A flaw in Coldcard seed generation can allow an attacker to recreate a device’s private keys with a single button press on the vulnerable wallet. The problem affects seeds produced on certain Coldcard models and firmware versions, and Coinkite has issued an advisory and user guidance.
Coinkite identifies Mk3 devices producing seeds on firmware 4.0.1 or later as at risk. Mk4 and Mk5 devices are affected on firmware releases before 5.6.0. Q-series devices are affected on firmware before 1.5.0Q; the company describes the Q-series impact as less severe but still serious. A Bitcoin contributor, using the name instagibbs, reproduced a vulnerable seed on a newly initialized Mk3, prompting the advisory.
The flaw is in the seed-generation step that creates the mnemonic phrase used to derive all private keys. Seed generation happens before the wallet’s usual protections, so weaknesses at that step cannot be fixed by later firmware updates. If the randomness used to produce a seed is narrow or predictable, an attacker can generate likely mnemonic phrases, derive the associated addresses, and monitor the blockchain for deposits. When funds appear at an address that matches a recreated seed, those funds can be spent by the attacker.
Coinkite’s advisory covers Mk3 seeds created from March 2021 onward. The vendor’s final Mk3 firmware was released in June 2023, and the advisory was published in July 2026. Coinkite plans a formal technical review to determine the root cause of the defect.
The highest risk scenario is a single-signature wallet whose seed was generated on an affected Mk3 with no BIP-39 passphrase, no multisig and no user-supplied dice entropy. In that case, the device’s seed generator is the sole cryptographic root protecting funds. A strong, unique BIP-39 passphrase derives a different wallet from the same mnemonic and raises the attacker’s burden, but Coinkite still recommends migrating funds to a new seed even when a passphrase is in use.
Multisignature setups reduce exposure because one weak seed becomes only one signer among several required to spend. Adding user-supplied randomness, such as fair dice rolls, can increase entropy; Coinkite’s advanced import path calls for at least 99 fair dice rolls to add entropy. These mitigation methods require careful record-keeping and tested recovery procedures, because losing a passphrase or misdocumenting a multisig can prevent recovery.
Coinkite’s remediation advice asks users to verify their backup and device fingerprint, confirm the receive address on the hardware screen, send a small test payment to that address, and then move the full balance to a newly generated wallet on an unaffected device or firmware. The vendor warns against quick transfers to unverified wallets or addresses, noting that haste can create new losses from mistyped addresses, weak temporary wallets, or incomplete backups.
The advisory highlights a maintenance issue for long-term cold storage. Seeds can outlive the devices and firmware that created them, and owners who power devices infrequently may miss security notices and continue to receive funds to vulnerable addresses. Coinkite points to reproducible builds and open-source code as tools for inspection but notes defects can remain until someone inspects the exact code path used to create a dormant seed.
Coinkite has asked users to rotate keys carefully and pledged a technical review of the flaw. The company also recommends durable alerting and long-term guidance from manufacturers so device-specific advisories and key-rotation playbooks remain accessible after a product’s final sale.








