Coldcard Mk3 Seed Vulnerability: What Bitcoin Holders Should Do Now
Coinkite has warned that seeds created on a Coldcard Mk3 running firmware 4.0.1 to 5.0.3 may be reproducible. Here is who is affected and how to migrate safely.
Coinkite has warned that seeds created on a Coldcard Mk3 running firmware 4.0.1 to 5.0.3 may be reproducible. Here is who is affected and how to migrate safely.
Coinkite Inc. issued a security advisory on 30 July 2026 that a lot of Bitcoin holders still have not seen. If you generated a seed on a Coldcard Mk3, it deserves ten minutes of your attention today.
Seeds generated on a Coldcard Mk3 running firmware 4.0.1 (March 2021) or any later version, up to and including 5.0.3, may be at risk. The issue sits in how the device produced randomness when it created your seed phrase. If that randomness was weaker than it should have been, the seed may be reproducible by someone who understands the flaw.
Based on Coinkite's early analysis, Mk4, Mk5 and Q are not affected.
The flaw is in seed creation, not in the device's day to day operation. That means the exposure travels with the seed, not the hardware.
A seed generated on an affected Mk3 is still an affected seed if it has since been:
Updating firmware does not retroactively fix a seed that has already been generated. There is no patch for randomness that was already consumed.
Coinkite's early analysis indicates that where the affected seed was used together with a BIP-39 passphrase, the risk is minimal.
To be precise about the terminology, because this is where holders get caught out: this means a BIP-39 passphrase (sometimes called a 25th word), not your device PIN. A PIN protects the device. A passphrase changes the wallet that the seed derives.
The advisory's guidance is deliberately unglamorous, and that is the point:
Coinkite's own warning is worth repeating: rushing a wallet migration can create a more immediate risk than the issue you are trying to address. In practice, most self-custody losses come from botched migrations, not from attackers.
Two groups should treat this as a live action item.
Holders. If any part of your stack traces back to an Mk3-generated seed, treat it as affected until you can prove otherwise. That includes cold storage you have not touched since 2021, and any multisig where one signer's key came from an Mk3.
Estate planners and accountants. If you advise clients who self-custody, a seed migration changes the recovery documentation your client's executor is relying on. Any executor briefing, beneficiary instruction or SMSF custody record that references the old wallet is now out of date. Migrating the coins without migrating the paperwork simply moves the single point of failure.
This is exactly the work we do at BlockByte. If you are sitting on an Mk3-generated seed, or you advise clients who might be, we handle the technical side end to end:
A migration done properly takes one careful session. A migration done badly can take everything.
Source: Coinkite Coldcard Mk3 security advisory
This article is general information only and is not financial, legal or tax advice. Verify all advisory details directly with Coinkite before acting.
5 quick questions on Bitcoin estate planning essentials. Answer them all and we'll email you your score with a full answer breakdown.
Book a 30-minute consultation to map your holdings into a structure your family can actually inherit.
Book a ConsultationBillions in Bitcoin are permanently lost each year. The fix isn't a will - it's architecture.
What succession lawyers need to know before adding crypto clauses to a will.
Subscribe to The Digital Inheritance Newsletter for research and market commentary on Bitcoin estate planning and self-custody.