Coldcard Seed Bug Drains 1,082 BTC (~$70M), Warning Widens Past Mk3
A weak-entropy flaw in Coldcard firmware let attackers rebuild private keys, draining over 1,082 BTC as Coinkite widens its alert to every model.

More than 1,082 BTC — worth roughly $70 million at current prices — has drained out of Coldcard hardware wallets since Thursday, after a firmware bug left private keys generated with far less randomness than intended. Coinkite, the maker of Coldcard, has now widened its security warning from the older Mk3 model to include the Mk4, Mk5 and Q devices as well.
The theft unfolded fast. Early on, roughly 594 BTC (about $38 million) had already been swept from around 500 dormant single-signature addresses in a single 25-minute window, according to Protos. As investigators dug deeper, the tally climbed: data cited by Bitcoin Magazine from Galaxy Research and engineers at payments firm Block later put the total at 1,082.65 BTC pulled from 1,196 addresses, with drains reportedly still ongoing at the time of reporting.
A ~40-bit entropy problem where 128 bits were promised
Coinkite traced the root cause to a firmware defect in Coldcard Mk3 devices running versions starting at 4.0.1, released back in March 2021. Instead of drawing on the wallet’s hardware-based true random number generator, seed creation silently fell back to a weaker software pseudo-random number generator.
The result was seeds carrying only about 40 bits of entropy rather than the 128 bits Coldcard’s design promised. That gap is enormous in cryptographic terms — low enough that an attacker with sufficient compute could feasibly reconstruct private keys for affected single-sig wallets, particularly those set up without dice-roll entropy or a strong BIP-39 passphrase.
Coindesk reported that the drained coins had been sitting untouched since as far back as 2021, meaning users who followed standard “cold storage, don’t touch it” practice were among those exposed — years of dormant holdings became reachable the moment the flaw was exploited.
Coinkite’s warning grows from Mk3 to the entire product line
Coinkite’s first advisory on Thursday flagged only the Mk3 line, initially stating the newer Mk4, Q and Mk5 models were “not affected based on our early analysis.” By Friday, that assessment had changed: the company published a follow-up detailing what it called the technical specifics of “what actually went wrong, why our reviews missed it,” and extended precautionary guidance to owners of Mk4, Mk5 and Q devices too.
Block, the payments company formerly known as Square, ran its own independent analysis and reached a similar but distinct conclusion. Engineer Max Guise found related flaws spanning Mk2 through Mk5 hardware, tracing the underlying issue to a mis-written compile-time check. Block’s findings suggest the newer devices carry a smaller — but still real — version of the same entropy weakness.
Coinkite says AI helped the attackers, not the defenders
Because Coldcard’s source code is open and public, Coinkite believes the bug was likely surfaced through AI-assisted code review by whoever carried out the theft. The company said that in the weeks before the attack, it had tested its own code with “the best available AI models” and still failed to catch the flaw.
“Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys,” Coinkite said. Cobra, the pseudonymous operator of Bitcoin.org, separately described the situation as “very bad.”
For Coldcard holders, the practical takeaway is urgency: funds sitting in wallets seeded on the affected firmware since 2021 remain exposed until moved to freshly generated, verified-entropy addresses. Coinkite’s expanding advisory — from a single model to its entire hardware lineup within 24 hours — underscores that the scope of the exposure was still being mapped even as coins kept moving.
Read more: Coldcard Mk3 Alert: Coinkite Flags Risk After 594 BTC ($38M) Sweep
Sources
Related articles
BIP-110 Bitcoin Fork Stalls at Block 961,633 as Gap Widens to 88 Blocks
Only 2.53% of hashpower backed the anti-spam fork; it mined just two blocks before stalling while Bitcoin's main chain kept moving.
BTCPay Lightning Nodes Drained, BTC at $64,968; Emergency Patch to v2.4.2
Attackers stole LND ".macaroon" credentials to sweep Lightning channels; BTCPay urges v2.4.2 update as Foundation, Citadel21 confirm losses.
MARA’s BTC Treasury Falls to 35,577 Coins After $46M Sale, Q2 Loss Hits $611M
MARA Holdings sold 726 BTC worth $46M and posted a $611.3M Q2 loss as revenue fell 27% and Bitcoin's average price dropped…