Coinkite has issued a security advisory warning that cryptocurrency stored in certain Coldcard hardware wallets could be at risk because of a flaw affecting seed generation on multiple firmware versions.
The company said the issue affects seeds generated on the Coldcard Mk3 running firmware version 4.0.1, released in March 2021, or later. It also impacts seeds created on Mk4 and Mk5 devices before firmware version 5.6.0 and on Coldcard Q before version 1.5.0Q, although Coinkite said the impact on those newer models is less severe.
More than $38M has been stolen due to a Coldcard wallet vulnerability.⚠️
Funds from around 500 wallets were transferred to wallet bc1qnk, totaling 594.48 $BTC ($38.2M).
Stay safe.https://t.co/gUmUfQLvdbhttps://t.co/Bg2XS39mWh pic.twitter.com/XTmDa6lnev
— Lookonchain (@lookonchain) July 31, 2026
According to the company, the flaw reduced the amount of entropy used to generate recovery seeds. While users are expected to receive 128 bits of entropy, affected Mk4, Mk5, and Q devices generated about 72 bits. Coinkite urged affected users to migrate funds to a newly generated wallet instead of waiting for a firmware update, warning that software updates cannot repair seeds that have already been created.
Why seed generation is under the spotlight
Seed generation has become one of the most closely examined parts of hardware wallet security because it forms the foundation of every wallet. If the process that creates a recovery phrase is flawed, every private key and address derived from it inherits the same weakness. Unlike bugs that affect a wallet’s interface or connectivity, problems during seed generation cannot be corrected without creating an entirely new wallet.
The issue has received increased attention following several incidents involving random number generation in the crypto industry. In 2013, weak randomness in some Android wallets contributed to stolen Bitcoin after attackers were able to recover private keys. More recently, wallet manufacturers have expanded independent security audits and introduced features such as manual dice rolls, allowing users to add their own source of randomness during wallet creation. The Coldcard advisory adds to that focus, showing that the strength of a hardware wallet begins long before users make their first transaction.
The incident puts hardware wallet security under renewed scrutiny
The advisory also draws attention to a part of hardware wallet security that often receives less attention than physical device protection. Many users focus on keeping their recovery phrase offline and protecting their PIN, but the process that creates those recovery words is just as important. A weakness during wallet creation cannot be fixed by storing the device safely afterwards.
The disclosure is also a reminder that hardware wallet security depends on regular code reviews and independent testing, even for products that have been on the market for years. As more people use self-custody to hold digital assets, manufacturers are likely to face greater expectations to identify security issues quickly and provide clear guidance for users whose wallets may be affected.
In another development, a suspected exploit targeting Wanchain’s Cardano-to-BNB Chain bridge has resulted in the loss of about 515 million NIGHT tokens, triggering a sharp sell-off that pushed Midnight’s native token down more than 30% in 24 hours.
Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.


























































































