All insights
Self-Custody1 Aug 2026 3 min read

Coldcard Mk3 Seed Vulnerability: What Bitcoin Holders Should Do Now

Coinkite has warned that seeds created on a Coldcard Mk3 running firmware 4.0.1 to 5.0.3 may be reproducible. Here is who is affected and how to migrate safely.

Coinkite Inc. issued a security advisory on 30 July 2026 that a lot of Bitcoin holders still have not seen. If you generated a seed on a Coldcard Mk3, it deserves ten minutes of your attention today.

What the Coldcard advisory actually says

Seeds generated on a Coldcard Mk3 running firmware 4.0.1 (March 2021) or any later version, up to and including 5.0.3, may be at risk. The issue sits in how the device produced randomness when it created your seed phrase. If that randomness was weaker than it should have been, the seed may be reproducible by someone who understands the flaw.

Based on Coinkite's early analysis, Mk4, Mk5 and Q are not affected.

The part that is easy to miss: the risk follows the seed, not the device

The flaw is in seed creation, not in the device's day to day operation. That means the exposure travels with the seed, not the hardware.

A seed generated on an affected Mk3 is still an affected seed if it has since been:

  • imported into a different software or hardware wallet
  • restored onto a newer Coldcard or another vendor's device
  • used as one key inside a multisig quorum
  • stamped into steel and locked in a safe, untouched for years

Updating firmware does not retroactively fix a seed that has already been generated. There is no patch for randomness that was already consumed.

If you used a BIP-39 passphrase

Coinkite's early analysis indicates that where the affected seed was used together with a BIP-39 passphrase, the risk is minimal.

To be precise about the terminology, because this is where holders get caught out: this means a BIP-39 passphrase (sometimes called a 25th word), not your device PIN. A PIN protects the device. A passphrase changes the wallet that the seed derives.

Coinkite's recommended migration path

The advisory's guidance is deliberately unglamorous, and that is the point:

  1. Generate a new seed on an unaffected device.
  2. Verify the backup - write it down, then confirm it restores.
  3. Confirm a receive address on the device screen, not just in software.
  4. Send a small test transaction and confirm it arrives.
  5. Only then move the remaining balance.
  6. Keep the old backup until the migration is fully confirmed on chain.

Coinkite's own warning is worth repeating: rushing a wallet migration can create a more immediate risk than the issue you are trying to address. In practice, most self-custody losses come from botched migrations, not from attackers.

What this means for Australian holders and their advisers

Two groups should treat this as a live action item.

Holders. If any part of your stack traces back to an Mk3-generated seed, treat it as affected until you can prove otherwise. That includes cold storage you have not touched since 2021, and any multisig where one signer's key came from an Mk3.

Estate planners and accountants. If you advise clients who self-custody, a seed migration changes the recovery documentation your client's executor is relying on. Any executor briefing, beneficiary instruction or SMSF custody record that references the old wallet is now out of date. Migrating the coins without migrating the paperwork simply moves the single point of failure.

Do not migrate alone if the stakes are meaningful

This is exactly the work we do at BlockByte. If you are sitting on an Mk3-generated seed, or you advise clients who might be, we handle the technical side end to end:

  • new device selection and setup
  • multisig configuration across multiple vendors
  • backup creation and verified restore testing
  • test transactions before any balance moves
  • updated executor and beneficiary documentation, so the wallet is actually recoverable by someone other than you

A migration done properly takes one careful session. A migration done badly can take everything.

Source: Coinkite Coldcard Mk3 security advisory

This article is general information only and is not financial, legal or tax advice. Verify all advisory details directly with Coinkite before acting.

Knowledge check

How well do you know this?

5 quick questions on Bitcoin estate planning essentials. Answer them all and we'll email you your score with a full answer breakdown.

Protect what you've built

Talk to us about your Bitcoin estate plan.

Book a 30-minute consultation to map your holdings into a structure your family can actually inherit.

Book a Consultation
The Digital Inheritance Newsletter

Get our research delivered fortnightly.

Subscribe to The Digital Inheritance Newsletter for research and market commentary on Bitcoin estate planning and self-custody.