Coinkite disclosed Thursday that its Coldcard MK3 hardware wallet contains a critical vulnerability allowing attackers to extract users’ seed phrases without any user action. By Friday, the company expanded the warning to cover every subsequent generation: the MK4, MK5, and Q models. The disclosure follows a $70 million Bitcoin theft in which 1,196 addresses were drained.
The flaw centers on how the wallet generates randomness during seed creation. Attackers can derive the seed phrase if the device relied on insufficient entropy during setup. Coinkite said only wallets created using the dice roll method with at least 50 rolls are safe. Anything else, factory-generated seeds, shorter dice rolls, or default setup flows, is compromised.
Thursday’s MK3 Warning Became Friday’s Four-Model Crisis
Coinkite initially scoped the issue to the MK3, the oldest model still widely in circulation. That changed within 24 hours. The company’s Friday update confirmed the same vulnerability exists in the MK4, introduced in 2020, the MK5 from 2022, and the Q, the touchscreen flagship launched last year. Users across the entire product line now face the same question: was my seed generated with enough randomness to resist extraction?
The 1,196 drained addresses represent a cross-section of Coldcard users who thought air-gapped hardware offered the highest security tier. It didn’t. If you can’t recall rolling dice during setup, or rolled fewer than 50 times, the seed is presumed vulnerable. Coinkite advised immediate fund movement to wallets generated outside the affected hardware.
Dice Rolls or Bust
The dice roll method forces users to manually introduce entropy by recording physical dice outcomes, which the device then hashes into a seed. It’s tedious. Most users skip it, trusting the device’s internal random number generator. That trust is now the liability. The company hasn’t detailed the exact mechanism attackers use to reverse-engineer seeds from insufficient entropy, but the pattern is familiar: predictable randomness, exploitable inputs, seeds that look secure until someone calculates them.
This isn’t the first time hardware wallet makers faced entropy flaws. Ledger patched a similar issue in 2018; Trezor devices were scrutinized for their use of STM32 microcontrollers with imperfect RNG implementations. Coldcard positioned itself as the paranoid choice, the wallet for users who wanted no Bluetooth, no USB data transfer during signing, no compromise. That brand is now answering for a flaw that spans four hardware generations and seven years of devices in the wild.
Coinkite’s official announcement is live on its site. The company hasn’t disclosed how many total devices are affected or whether it will offer hardware replacements. For now, the directive is simple: if you don’t know your seed’s origin story, treat it as compromised and move everything. The $70 million already gone proves someone else figured out the math.
