Coinkite warns Coldcard Mk3 users of firmware flaw that may have compromised wallet seeds

1 hour ago 14

If you have a Coldcard Mk3 sitting in a drawer, this is the week to dig it out. Coinkite has issued a security advisory warning that seeds generated on Mk3 devices running firmware versions 4.0.1 through 5.0.3 may be compromised, pointing to a possible flaw in the device’s random number generator.

The advisory is prominently displayed on Coinkite’s firmware downloads page, which signals this is not a quiet disclosure buried in a changelog.

What the flaw actually means

When you set up a hardware wallet, the device generates a seed, a string of words that is the master key to everything in your wallet. That seed is supposed to be random, truly random, so nobody can guess or recreate it. If the RNG has a flaw, the seeds it produces may not be as random as they appear, and potentially reproducible by someone who knows about the flaw.

The affected firmware range spans from version 4.0.1, released in March 2021, through version 5.0.3. Any Mk3 device that generated a seed while running any of those versions could be affected. Coinkite’s initial analysis confirms that the Mk4, Q, and Mk5 models are not impacted by this issue.

Coinkite has not disclosed whether the flaw has been actively exploited.

What you should do right now

Coinkite is giving affected users two paths forward.

The first option is applying a strong, unique BIP-39 passphrase to your existing seed. BIP-39 is a standard that allows you to add a custom word or phrase on top of your existing seed words, essentially creating a separate wallet that requires both the seed and the passphrase to access.

The second option is migrating entirely. That means generating a fresh seed on a Mk4, Q, or Mk5 device, which uses an RNG that is not affected by this flaw, and moving your funds there. The company suggests conducting test transactions before moving larger amounts.

For users who want to stay on the Mk3 and bypass its RNG altogether, Coinkite has introduced an advanced dice-roll seed generation option.

Regardless of which path you take, Coinkite recommends verifying the eight-digit XFP fingerprint on your device each time you interact with a wallet. The XFP is a short identifier derived from your master public key. Keeping old backups until the migration is fully confirmed is also advised.

Why this matters beyond one wallet model

Coinkite’s transparency here is worth noting. The advisory is visible, specific, and actionable. The company is naming the affected versions, recommending concrete remediation steps, and keeping the warning on its active downloads page rather than quietly patching and moving on.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article