Coldcard Mk3 Firmware Flaw Drains Up to $70M in Bitcoin via Weak RNG
A critical firmware flaw in Coldcard Mk3 hardware wallets has exposed a weak random number generator used during seed generation, enabling attackers to drain between $38 million and $70 million in Bitcoin. Coinkite has urged affected users to migrate funds immediately.
Coldcard Mk3 Firmware Flaw Drains Up to $70M in Bitcoin via Weak RNG
A critical vulnerability in the Coldcard Mk3 hardware wallet has exposed a flawed random number generator (RNG) used during seed generation, enabling attackers to drain between $38 million and $70 million in Bitcoin from affected wallets. On-chain data confirms at least 594 BTC was swept in a single 25-minute window, indicating rapid systematic exploitation.
The flaw does not represent a direct breach of the Coldcard device itself. Rather, the weakness lies in how the Mk3 firmware generated entropy during wallet seed creation. A predictable or insufficiently random seed means an attacker who can reconstruct the RNG output can derive private keys without ever touching the hardware. That distinction matters architecturally, but it offers cold comfort to affected users: the result is identical to a full compromise.
Coinkite, the Toronto-based company behind Coldcard, issued a security advisory urging immediate action. The company's guidance is unambiguous.
"Migrate your funds now."
The advisory covers all Mk3 users who generated wallet seeds under vulnerable firmware versions. Users who created seeds after the patch was released are not affected, though Coinkite has not yet published a definitive list of affected firmware version numbers as of July 31, 2026. Anyone uncertain about their device's firmware history should treat their wallet as compromised and move funds to a freshly generated address on patched or alternative hardware.
RNG failures occupy a specific and particularly dangerous category of cryptographic vulnerability. Unlike a software bug that crashes an application, a weak RNG is silent. Wallets generated under a flawed entropy source appear to function normally, pass all standard checks, and hold funds without issue until an attacker systematically reconstructs the seed space and sweeps every vulnerable address at once. The 25-minute drain window is consistent with that attack pattern: automated, methodical, and complete before most users could react.
The scale of this incident places it among the largest hardware wallet-related thefts on record. The 2015 Blockchain.info vulnerability, which also stemmed from weak key generation rather than a server breach, affected a significant number of wallets before patching. The Coldcard incident is more striking because Mk3 devices are air-gapped, meaning they never connect to the internet directly. That design is specifically intended to eliminate the attack surface that compromised hot wallets and exchange-custodied funds in earlier years. An RNG flaw undermines that architecture at its foundation, not by defeating the air gap, but by making the keys the air gap protects trivially guessable.
"The firmware flaw highlights the critical importance of robust RNGs in hardware wallets, emphasizing the need for vigilant security practices."
Coinkite's rapid public disclosure and clear migration guidance represent responsible handling of a severe vulnerability. The company did not wait for losses to mount before alerting users. That transparency may limit further damage and, over time, preserve the brand's credibility with a Bitcoin-native user base that values auditability above most other qualities in a security product.
For the broader hardware wallet market, the incident will accelerate two trends already gaining traction: multi-signature custody setups, where no single device holds unilateral control over funds, and hardware wallet diversity, where users split holdings across devices from different manufacturers using different firmware stacks. Neither approach would have prevented losses for Mk3 users who generated seeds before the patch, but both significantly raise the bar for any future single-point-of-failure attack.
Coldcard Mk3 owners who have not yet moved their funds should do so immediately, using a new seed generated on patched firmware or a separate device. Holding funds on any wallet whose seed generation provenance is uncertain is not a recoverable risk posture.



