{"id":7014,"date":"2026-07-31T11:07:27","date_gmt":"2026-07-31T11:07:27","guid":{"rendered":"https:\/\/cryptolinks.com\/news\/?p=7014"},"modified":"2026-07-31T11:07:27","modified_gmt":"2026-07-31T11:07:27","slug":"coldcard-mk3-entropy-bug-594-btc-sweptwho-must-migrate-now","status":"publish","type":"post","link":"https:\/\/cryptolinks.com\/news\/coldcard-mk3-entropy-bug-594-btc-sweptwho-must-migrate-now","title":{"rendered":"Coldcard Mk3 Entropy Bug: 594 BTC Swept\u2014Who Must Migrate Now"},"content":{"rendered":"<p><strong>A coordinated sweep removed approximately 594.5 BTC from around 500 single-signature addresses. Coinkite has now confirmed a seed-generation entropy defect affecting Mk3 and pre-hotfix Mk4, Mk5 and Q seeds\u2014and installing new firmware alone does not repair keys that already exist.<\/strong><\/p>\n<p>On July 30, 2026, roughly 594.5 BTC moved from about 500 single-signature addresses in a tightly coordinated sweep. Exposure depends on the model and firmware that <strong>generated the secret<\/strong>: Mk3 seeds created on 4.0.1 or later face the most severe official warning, while Mk4 and Mk5 seeds created before 5.6.0 and Q seeds created before 1.5.0Q also require action. A verified original contribution of at least 50 private dice rolls or a strong, unique BIP-39 passphrase changes the risk, but nobody should ever enter seed words into a website or \u201cchecker.\u201d<\/p>\n<div>\n<h3>Check these four things first<\/h3>\n<ol type=\"1\">\n<li>Which model generated the seed?<\/li>\n<li>Which firmware was active <strong>when the seed was created<\/strong>?<\/li>\n<li>Were at least 50 fair, private dice rolls added before the final words appeared?<\/li>\n<li>Has the wallet always used a strong, unique BIP-39 passphrase?<\/li>\n<\/ol>\n<p><strong>Move promptly, but verify every step.<\/strong> A wrong address, mistyped passphrase, bad backup or fake migration site can produce a faster and more certain loss than the entropy issue.<\/p>\n<\/div>\n<div>\n<h3>Seed-safety rule<\/h3>\n<p><strong>Seed words must only ever be displayed or entered on trusted hardware during an intentional recovery. No website, browser extension, phone app, support representative or \u201centropy checker\u201d needs them.<\/strong><\/p>\n<\/div>\n<h2>Key takeaways<\/h2>\n<ul>\n<li>The entropy defect is real, but every swept address has <strong>not<\/strong> been independently attributed to COLDCARD.<\/li>\n<li>Mk3 device-generated seeds on 4.0.1+ are the highest-priority group in Coinkite\u2019s advisory.<\/li>\n<li>Mk4\/Mk5 seeds created before 5.6.0 and Q seeds created before 1.5.0Q are also in scope.<\/li>\n<li>Updating prevents future weak generation; it does not add entropy to an old seed.<\/li>\n<li>At least 50 original, fair and private D6 rolls change Coinkite\u2019s classification; fewer or uncertain rolls do not.<\/li>\n<li>A PIN is not a BIP-39 passphrase, and even a strong passphrase is not a substitute for permanent migration.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7020\" src=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/What-happened-in-the-594-BTC-sweep.png\" alt=\"What happened in the 594 BTC sweep\" width=\"1024\" height=\"1024\" srcset=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/What-happened-in-the-594-BTC-sweep.png 1024w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/What-happened-in-the-594-BTC-sweep-300x300.png 300w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/What-happened-in-the-594-BTC-sweep-150x150.png 150w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/What-happened-in-the-594-BTC-sweep-768x768.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<h2>What happened in the 594 BTC sweep<\/h2>\n<p>The blockchain shows a coordinated operation: about 500 transactions consumed 1,324 UTXOs from roughly 500 single-signature addresses, moving approximately 594.5 BTC. Confirmations appeared across <a href=\"https:\/\/mempool.space\/block\/960188\" rel=\"noopener\">blocks 960188<\/a>, <a href=\"https:\/\/mempool.space\/block\/960189\" rel=\"noopener\">960189<\/a>, <a href=\"https:\/\/mempool.space\/block\/960190\" rel=\"noopener\">960190<\/a> and <a href=\"https:\/\/mempool.space\/block\/960191\" rel=\"noopener\">960191<\/a>.<\/p>\n<p>The confirmation span was about 01:36\u201301:51 UTC, or 15 minutes. <a href=\"https:\/\/www.coindesk.com\/tech\/2026\/07\/31\/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep\" rel=\"noopener\">CoinDesk\u2019s broader reconstruction<\/a> uses approximately 01:31\u201301:56 UTC, including broadcast activity. State the measurement before calling it a 15- or 25-minute sweep.<\/p>\n<p><a href=\"https:\/\/atlas21.com\/594-bitcoin-drained-15-minutes-theft\/\" rel=\"noopener\">Atlas21<\/a> reported roughly 0.044 BTC in fees, a 0.41 BTC median source balance, a 29.9 BTC maximum and no analyzed source below about 0.15 BTC. About 562 BTC was consolidated into one output and was still reported as unmoved when the cited reports appeared. At $63,757\/BTC, checked at 10:31 UTC July 31, the sweep was worth about $37.9 million; refresh that conversion before publication.<\/p>\n<h2>Is the theft conclusively tied to COLDCARD?<\/h2>\n<p>Not address by address. The defect is confirmed, <a href=\"https:\/\/blog.coinkite.com\/coldcard-mk3-seed-generation-warning\/\" rel=\"noopener\">Coinkite has issued migration guidance<\/a>, and <a href=\"https:\/\/engineering.block.xyz\/blog\/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware\" rel=\"noopener\">Block\u2019s code analysis<\/a> says active exploitation was underway. Public victim accounts include COLDCARD-generated seeds, and dormant-UTXO dates overlap the vulnerable period. Weakly generated keys are therefore a strong explanation.<\/p>\n<p>I would not call this \u201c500 confirmed COLDCARD users.\u201d Evidence does not prove that every address came from one model, that every complete seed was recovered or that every affected model has a confirmed victim. Partial drains could reflect limited wallet-path scanning or recovery of individual keys. Coinkite\u2019s suggestion that automated or AI-assisted review may have found the bug is speculation, not attacker attribution.<\/p>\n<table>\n<thead>\n<tr>\n<th>Claim<\/th>\n<th>Status<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Entropy bug exists; 594.5 BTC sweep occurred<\/td>\n<td>Confirmed<\/td>\n<\/tr>\n<tr>\n<td>Mk3 4.0.1+ and pre-hotfix Mk4\/Mk5\/Q are exposed<\/td>\n<td>Confirmed advisory<\/td>\n<\/tr>\n<tr>\n<td>Every victim used COLDCARD<\/td>\n<td>Unconfirmed<\/td>\n<\/tr>\n<tr>\n<td>Attacker recovered full seeds or used AI<\/td>\n<td>Unconfirmed\/speculation<\/td>\n<\/tr>\n<tr>\n<td>Taproot prevents weak-entropy attacks<\/td>\n<td>Unsupported<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7021\" src=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/Which-COLDCARD-devices-and-firmware-versions-are-affected.png\" alt=\"Which COLDCARD devices and firmware versions are affected\" width=\"1024\" height=\"1024\" srcset=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/Which-COLDCARD-devices-and-firmware-versions-are-affected.png 1024w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/Which-COLDCARD-devices-and-firmware-versions-are-affected-300x300.png 300w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/Which-COLDCARD-devices-and-firmware-versions-are-affected-150x150.png 150w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/Which-COLDCARD-devices-and-firmware-versions-are-affected-768x768.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<h2>Which COLDCARD devices and firmware versions are affected?<\/h2>\n<p>The first thing I would establish is how and when the seed was created.<\/p>\n<table>\n<thead>\n<tr>\n<th>Device<\/th>\n<th>Firmware at creation<\/th>\n<th>Assessment<\/th>\n<th>Response<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Mk1<\/td>\n<td>Any<\/td>\n<td>Outside this regression<\/td>\n<td>No action solely for this bug<\/td>\n<\/tr>\n<tr>\n<td>Mk2\/Mk3<\/td>\n<td>Through 3.2.2<\/td>\n<td>Outside this regression in Block\u2019s analysis<\/td>\n<td>No action solely for this bug<\/td>\n<\/tr>\n<tr>\n<td>Mk2<\/td>\n<td>4.0.0\u20134.1.9<\/td>\n<td>Vulnerable path per Block; not clearly classified in Coinkite\u2019s headline advisory<\/td>\n<td>Treat as potentially affected; seek clarification<\/td>\n<\/tr>\n<tr>\n<td>Mk3<\/td>\n<td>4.0.0<\/td>\n<td>In Block\u2019s technical timeline<\/td>\n<td>Treat conservatively as affected<\/td>\n<\/tr>\n<tr>\n<td>Mk3<\/td>\n<td>4.0.1\u20134.1.9<\/td>\n<td>At risk under Coinkite\u2019s advisory<\/td>\n<td>Migrate promptly<\/td>\n<\/tr>\n<tr>\n<td>Mk4\/Mk5<\/td>\n<td>Before 5.6.0<\/td>\n<td>Affected<\/td>\n<td>Upgrade first, then create a new seed and migrate<\/td>\n<\/tr>\n<tr>\n<td>Q<\/td>\n<td>Before 1.5.0Q<\/td>\n<td>Affected<\/td>\n<td>Upgrade first, then create a new seed and migrate<\/td>\n<\/tr>\n<tr>\n<td>TAPSIGNER \/ OPENDIME \/ SATSCARD<\/td>\n<td>Any<\/td>\n<td>Outside this issue per Coinkite<\/td>\n<td>No action solely for this bug<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Block starts the Mk2\/Mk3 defective path at 4.0.0; Coinkite\u2019s public action threshold starts at 4.0.1. No public explanation for that difference was found, so 4.0.0 is not a basis for reassurance. The official <a href=\"https:\/\/coldcard.com\/downloads\/all\" rel=\"noopener\">archive<\/a> lists 4.1.9 as final Mk3\/Mk2 firmware; 5.0.3 belongs to Mk4.<\/p>\n<h2>Why your seed\u2019s origin matters more than your device\u2019s age<\/h2>\n<p>A weak seed remains weak after restoration to another wallet. A securely generated external seed does not become weak merely because it is imported into an affected COLDCARD. Model, firmware at generation, entropy source, dice, passphrase and auxiliary functions matter; purchase date, current firmware and air-gapped storage do not retroactively change the secret.<\/p>\n<h3>Quick risk classifier<\/h3>\n<table>\n<thead>\n<tr>\n<th>Secret origin<\/th>\n<th>Classification<\/th>\n<th>Response<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Mk3 4.0.1+ device-generated, no\/weak passphrase<\/td>\n<td><strong>Migrate promptly<\/strong><\/td>\n<td>New seed and on-chain transfer<\/td>\n<\/tr>\n<tr>\n<td>Same with a strong, unique passphrase<\/td>\n<td><strong>Interim barrier<\/strong><\/td>\n<td>Preserve it exactly, then migrate<\/td>\n<\/tr>\n<tr>\n<td>Mk3 with 50+ verified private rolls before final words<\/td>\n<td><strong>Outside this issue under Coinkite\u2019s position<\/strong><\/td>\n<td>Verify procedure<\/td>\n<\/tr>\n<tr>\n<td>Mk4\/Mk5 before 5.6.0; Q before 1.5.0Q<\/td>\n<td><strong>Migrate promptly<\/strong><\/td>\n<td>Install fixed firmware before generation<\/td>\n<\/tr>\n<tr>\n<td>New seed after fixed firmware<\/td>\n<td><strong>Fixed-generation scope<\/strong><\/td>\n<td>Verify backup, XFP and address<\/td>\n<\/tr>\n<tr>\n<td>Independently generated imported seed<\/td>\n<td><strong>Outside primary scope<\/strong><\/td>\n<td>Review auxiliary secrets<\/td>\n<\/tr>\n<tr>\n<td>Affected seed restored elsewhere<\/td>\n<td><strong>Still affected<\/strong><\/td>\n<td>Migrate<\/td>\n<\/tr>\n<tr>\n<td>Origin\/firmware unknown<\/td>\n<td><strong>Treat as affected<\/strong><\/td>\n<td>Migrate carefully<\/td>\n<\/tr>\n<tr>\n<td>Random Seed XOR mask or paper key on affected firmware<\/td>\n<td><strong>Specialist review<\/strong><\/td>\n<td>Replace affected secret<\/td>\n<\/tr>\n<tr>\n<td>Multisig with enough vulnerable keys to meet threshold<\/td>\n<td><strong>Quorum exposed<\/strong><\/td>\n<td>Specialist migration<\/td>\n<\/tr>\n<tr>\n<td>One vulnerable key below threshold<\/td>\n<td><strong>No threshold failure by itself<\/strong><\/td>\n<td>Replace the key carefully<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>The RNG integration error explained without code<\/h2>\n<p>During a 2021 migration, secret generation moved to a random-byte function whose library check asked whether a hardware-RNG macro existed, not whether it was enabled. The macro existed but was zero, so calls fell through to MicroPython\u2019s Yasmarang software generator, initialized from device and timing data rather than a cryptographically secure source.<\/p>\n<p>Block says affected Mk2\/Mk3 version-4 firmware received no cryptographic reseed through this path. Mk4, Mk5 and Q mixed secure-element data, but only four bytes changed one 32-bit state word. Hashing limited inputs cannot create more possibilities. SHA-256, BIP-39 and Bitcoin were not broken; the integration of randomness was.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7022\" src=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/Why-Mk3-exposure-is-more-severe\u2014and-why-72-bits-needs-context.png\" alt=\"Why Mk3 exposure is more severe\u2014and why \u201c72 bits\u201d needs context\" width=\"1024\" height=\"1024\" srcset=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/Why-Mk3-exposure-is-more-severe\u2014and-why-72-bits-needs-context.png 1024w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/Why-Mk3-exposure-is-more-severe\u2014and-why-72-bits-needs-context-300x300.png 300w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/Why-Mk3-exposure-is-more-severe\u2014and-why-72-bits-needs-context-150x150.png 150w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/Why-Mk3-exposure-is-more-severe\u2014and-why-72-bits-needs-context-768x768.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<h2>Why Mk3 exposure is more severe\u2014and why \u201c72 bits\u201d needs context<\/h2>\n<p><a href=\"https:\/\/blog.coinkite.com\/entropy-technical-backgrounder\/\" rel=\"noopener\">Coinkite<\/a> estimates about 40 bits for affected Mk3 generation and about 72 bits for Mk4\/Mk5\/Q under its model. Block warns that timers may correlate, identifiers may be partly known and a raw ceiling near 73 bits is not 73 bits of independent security. For a fixed fallback state and call history, it identifies at most 2\u00b3\u00b2 secure-element reseed streams.<\/p>\n<p>No universal cracking time follows. Cost depends on device, attacker knowledge, timing, UID, call history, derivation work and hardware. Block had not completed full end-to-end testing before disclosure.<\/p>\n<h2>Does installing firmware 5.6.0 repair an old wallet?<\/h2>\n<p>No. An update fixes future generation; it cannot add entropy to existing keys. Install verified 5.6.0+ on Mk4\/Mk5 or 1.5.0Q+ on Q <strong>before<\/strong> creating a replacement. Use the official <a href=\"https:\/\/coldcard.com\/downloads\" rel=\"noopener\">downloads<\/a> and <a href=\"https:\/\/coldcard.com\/docs\/upgrade\/\" rel=\"noopener\">upgrade-verification guide<\/a>, then check the post-install version on-device.<\/p>\n<p>A new Mk5 or Q may ship with older firmware, so buying one is not enough. For destination research, see our <a href=\"https:\/\/cryptolinks.com\/2214\/coldcard\">COLDCARD review<\/a>, <a href=\"https:\/\/cryptolinks.com\/hardware-wallet\">hardware-wallet guide<\/a> and <a href=\"https:\/\/cryptolinks.com\/news\/secure-crypto-storage\">secure-storage guide<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7015\" src=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/Are-dice-generated-COLDCARD-seeds-affected.png\" alt=\"Are dice-generated COLDCARD seeds affected\" width=\"1024\" height=\"1024\" srcset=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/Are-dice-generated-COLDCARD-seeds-affected.png 1024w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/Are-dice-generated-COLDCARD-seeds-affected-300x300.png 300w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/Are-dice-generated-COLDCARD-seeds-affected-150x150.png 150w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/Are-dice-generated-COLDCARD-seeds-affected-768x768.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<h2>Are dice-generated COLDCARD seeds affected?<\/h2>\n<p>Coinkite says a seed is outside this issue if at least 50 fair, independent and private D6 rolls were added before the final words appeared. Fifty rolls contribute about 128 bits; 99 contribute about 256. Fewer, uncertain, recorded or reused rolls should be treated as affected. Never enter real rolls on a connected computer.<\/p>\n<p>On fixed firmware, Coinkite says device entropy is sufficient and dice are optional\u2014not a mandatory repair.<\/p>\n<h2>Does a BIP-39 passphrase protect an affected seed?<\/h2>\n<p>A strong, unique BIP-39 passphrase creates a different wallet and an independent guessing barrier. A name, quote, common phrase or reused password may be weak.<\/p>\n<p><strong>The COLDCARD PIN is not a passphrase.<\/strong> It protects physical device access, not keys reconstructed offline. Every passphrase typo creates another valid wallet, so back it up exactly and separately, record the XFP, power-cycle, re-enter it and confirm the same XFP. Coinkite still recommends a new-seed migration.<\/p>\n<h2>What single-signature users should do in the next 48 hours<\/h2>\n<p>This is an editorial plan, not an official deadline. Active exploitation makes delay unwise; rushed migration remains dangerous.<\/p>\n<h3>First 15 minutes<\/h3>\n<p>Ignore unsolicited support. Never enter a seed in a checker or use an address supplied by support. Check funds with an existing watch-only wallet or known public addresses, then record model, seed origin and firmware at generation. Unknown means potentially affected.<\/p>\n<h3>Today<\/h3>\n<p>Choose a verified destination. Install fixed firmware before generation. Create a new seed, back it up offline, recheck the words, power-cycle and confirm the XFP. Verify a receive address on the device. Send a small test, wait for confirmation and prove control before moving the remainder.<\/p>\n<h3>Next 48 hours and after<\/h3>\n<p>Transfer carefully, verifying every address. Splitting a transfer only limits operational-error impact; it does not change cryptographic exposure. Check expected accounts, change branches, passphrase wallets, temporary seeds and paper wallets. Keep the old backup until reconciliation is complete, then mark it retired, replace old allowlists\/descriptors and never receive to it again.<\/p>\n<p>See our <a href=\"https:\/\/cryptolinks.com\/news\/wallet-safety-now-passkeys-mpc-recovery\">wallet safety and recovery guide<\/a> and <a href=\"https:\/\/cryptolinks.com\/news\/guide-to-protecting-your-crypto-assets\">asset-protection guide<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7019\" src=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/The-questions-Coinkite-and-wallet-auditors-still-need-to-answer.png\" alt=\"How to migrate without losing funds to a rushed mistake\" width=\"1024\" height=\"1024\" srcset=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/The-questions-Coinkite-and-wallet-auditors-still-need-to-answer.png 1024w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/The-questions-Coinkite-and-wallet-auditors-still-need-to-answer-300x300.png 300w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/The-questions-Coinkite-and-wallet-auditors-still-need-to-answer-150x150.png 150w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/The-questions-Coinkite-and-wallet-auditors-still-need-to-answer-768x768.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>&nbsp;<\/p>\n<h2>How to migrate without losing funds to a rushed mistake<\/h2>\n<table>\n<thead>\n<tr>\n<th>Mistake<\/th>\n<th>Danger<\/th>\n<th>Safer alternative<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Seed in a checker<\/td>\n<td>Immediate theft<\/td>\n<td>Never disclose it<\/td>\n<\/tr>\n<tr>\n<td>Generate before updating<\/td>\n<td>Another affected seed<\/td>\n<td>Verify fixed firmware first<\/td>\n<\/tr>\n<tr>\n<td>Skip test transaction<\/td>\n<td>Hidden address\/backup error<\/td>\n<td>Send and confirm a test<\/td>\n<\/tr>\n<tr>\n<td>Confuse PIN\/passphrase<\/td>\n<td>No offline protection<\/td>\n<td>Verify BIP-39 use<\/td>\n<\/tr>\n<tr>\n<td>Lose or mistype passphrase<\/td>\n<td>Permanent loss\/wrong wallet<\/td>\n<td>Separate backup and XFP check<\/td>\n<\/tr>\n<tr>\n<td>Reuse old addresses<\/td>\n<td>New funds return to exposed keys<\/td>\n<td>Replace allowlists<\/td>\n<\/tr>\n<tr>\n<td>Destroy old backup early<\/td>\n<td>Missed accounts become unrecoverable<\/td>\n<td>Retain until reconciled<\/td>\n<\/tr>\n<tr>\n<td>Use factory firmware<\/td>\n<td>May predate hotfix<\/td>\n<td>Upgrade first<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>What to do when an Mk3 is the only available device<\/h2>\n<p>Coinkite\u2019s temporary option is a strong passphrase created entirely on-device: follow its <a href=\"https:\/\/coldcard.com\/docs\/passphrase\/\" rel=\"noopener\">passphrase guide<\/a>, back it up separately, verify the XFP and destination address, and test before moving. Treat it as interim protection.<\/p>\n<p>The advanced replacement path requires an empty Mk3 on 4.1.9, <strong>Import Existing \u2192 Dice Rolls<\/strong>, and at least 99 independent D6 rolls. Do not substitute New Wallet. One-device seed switching, restoration, backup and XFP checks make this error-prone; follow the complete official procedure.<\/p>\n<h2>Paper wallets, Seed XOR and other affected functions<\/h2>\n<p>Block found other secrets using the construction:<\/p>\n<table>\n<thead>\n<tr>\n<th>Function<\/th>\n<th>Potential impact<\/th>\n<th>Review<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>New\/ephemeral seeds<\/td>\n<td>Weak wallet or temporary secret<\/td>\n<td>Replace if affected<\/td>\n<\/tr>\n<tr>\n<td>Random paper-wallet keys<\/td>\n<td>Direct key exposure<\/td>\n<td>Migrate; dice-only path differs<\/td>\n<\/tr>\n<tr>\n<td>Random Seed XOR masks<\/td>\n<td>Weak random mask<\/td>\n<td>Recreate<\/td>\n<\/tr>\n<tr>\n<td>Default deterministic Seed XOR split<\/td>\n<td>Different path<\/td>\n<td>Confirm mode used<\/td>\n<\/tr>\n<tr>\n<td>Some cloning, USB, Key Teleport, Web2FA, Secure Notes and HSM material<\/td>\n<td>Feature-specific risk<\/td>\n<td>Rotate under official guidance<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>An imported primary seed can be sound while an auxiliary secret is weak. See our <a href=\"https:\/\/cryptolinks.com\/paper-wallet\">paper-wallet resources<\/a>.<\/p>\n<h2>Why no online entropy checker can safely test your seed<\/h2>\n<p>Risk is classified from generation history; no legitimate checker needs the words. Expect fake emails, ads, download pages, extensions, QR codes, screen-sharing requests, giveaways and compensation claims. Treat anyone who contacts you first as hostile.<\/p>\n<p>An xpub cannot spend, but it exposes addresses, balances and history. Do not share it casually or create a watch-only wallet by uploading a seed. See our <a href=\"https:\/\/cryptolinks.com\/news\/avoiding-crypto-scams-a-guide\">crypto-scam guide<\/a>.<\/p>\n<h2>What the initial victim pattern does\u2014and does not\u2014prove<\/h2>\n<p>Atlas21 counted 490 native SegWit, five legacy and five nested SegWit addresses, with no Taproot victims. Taproot is not a defense: a weak master secret can affect every derived address. The pattern may reflect usage, scanning coverage or a balance threshold. Unmoved UTXOs are not proven safe.<\/p>\n<p>No multisig output appeared in the initial set, but a quorum made from enough vulnerable keys can still fail. One vulnerable key below the threshold is a different risk and should be replaced carefully.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7018\" src=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/openart-gpt-image-2-1_1785495093880_413c1a87.png\" alt=\" The questions Coinkite and wallet auditors still need to answer\" width=\"1024\" height=\"1024\" srcset=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/openart-gpt-image-2-1_1785495093880_413c1a87.png 1024w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/openart-gpt-image-2-1_1785495093880_413c1a87-300x300.png 300w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/openart-gpt-image-2-1_1785495093880_413c1a87-150x150.png 150w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/openart-gpt-image-2-1_1785495093880_413c1a87-768x768.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<h2>The questions Coinkite and wallet auditors still need to answer<\/h2>\n<p>The disclosure raises questions that should be addressed without inventing conclusions:<\/p>\n<ul>\n<li>Why did an open-source codebase not reveal the fallback earlier?<\/li>\n<li>Which automated tests should have failed when the hardware RNG was disabled?<\/li>\n<li>Why was a non-cryptographic PRNG reachable from secret-generation code?<\/li>\n<li>Why did the later reseed retain only 32 bits?<\/li>\n<li>Should entropy-source tests become mandatory in hardware-wallet audits?<\/li>\n<li>Should production devices expose entropy-health evidence?<\/li>\n<li>How should vendors design emergency key-migration communications?<\/li>\n<li>What does this incident show about long-term firmware maintenance?<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7017\" src=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/My-conclusion-the-safe-response-is-a-new-key-not-a-firmware-only-fix.png\" alt=\"My conclusion the safe response is a new key, not a firmware-only fix\" width=\"1024\" height=\"1024\" srcset=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/My-conclusion-the-safe-response-is-a-new-key-not-a-firmware-only-fix.png 1024w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/My-conclusion-the-safe-response-is-a-new-key-not-a-firmware-only-fix-300x300.png 300w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/My-conclusion-the-safe-response-is-a-new-key-not-a-firmware-only-fix-150x150.png 150w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/07\/My-conclusion-the-safe-response-is-a-new-key-not-a-firmware-only-fix-768x768.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<h2>My conclusion: the safe response is a new key, not a firmware-only fix<\/h2>\n<p>This is a key-generation failure, not a failure of Bitcoin. For an affected single-signature wallet, the durable response is a new seed created through verified fixed or independent generation, followed by an on-chain transfer.<\/p>\n<p>Move promptly without converting cryptographic risk into operational loss: verify firmware, backup, XFP, address and test transaction. Keep the old backup until reconciliation is complete, and never enter seed words online.<\/p>\n<h2>Frequently asked questions<\/h2>\n<h3>What is the COLDCARD entropy bug?<\/h3>\n<p>Affected firmware used a predictable software RNG fallback, with absent or limited cryptographic reseeding, when generating secrets.<\/p>\n<h3>Was 594 BTC really stolen?<\/h3>\n<p>The 594.5 BTC sweep is confirmed on-chain; attribution of every address to COLDCARD is not.<\/p>\n<h3>Which Mk3 firmware is affected?<\/h3>\n<p>Coinkite says 4.0.1+; Block traces the path to 4.0.0, which should be treated conservatively.<\/p>\n<h3>Are Mk4, Mk5 and Q affected?<\/h3>\n<p>Yes: Mk4\/Mk5 seeds before 5.6.0 and Q seeds before 1.5.0Q.<\/p>\n<h3>Is Mk2 affected?<\/h3>\n<p>Block identifies Mk2 4.0.0\u20134.1.9. Seek direct Coinkite clarification and do not assume omission means safety.<\/p>\n<h3>Does updating protect an existing seed?<\/h3>\n<p>No. It fixes future generation; existing affected funds must move to a new seed.<\/p>\n<h3>Do 50 dice rolls change the risk?<\/h3>\n<p>Coinkite says 50+ fair, private D6 rolls added before final words protect against this issue alone. Uncertain means migrate.<\/p>\n<h3>Is the PIN a BIP-39 passphrase?<\/h3>\n<p>No. The PIN controls device access; a passphrase derives another wallet.<\/p>\n<h3>Does a strong passphrase permanently fix the seed?<\/h3>\n<p>No. It can add a strong interim barrier, but migration is still recommended.<\/p>\n<h3>Are imported seeds affected?<\/h3>\n<p>Independently secure imported seeds are outside the primary bug, though auxiliary secrets need review.<\/p>\n<h3>Must users buy a new wallet?<\/h3>\n<p>No. A verified updated Mk4\/Mk5 or Q can generate a replacement; the Mk3 dice path is advanced.<\/p>\n<h3>Can an online tool check the seed?<\/h3>\n<p>No legitimate online tool needs the words. Entering them creates immediate theft risk.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A coordinated sweep removed approximately 594.5 BTC from around 500 single-signature addresses. Coinkite has now confirmed a seed-generation entropy defect affecting Mk3 and pre-hotfix Mk4, Mk5 and Q seeds\u2014and installing new firmware alone does not repair keys that already exist. On July 30, 2026, roughly 594.5 BTC moved from about 500 single-signature addresses in a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":7016,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-7014","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/posts\/7014","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/comments?post=7014"}],"version-history":[{"count":2,"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/posts\/7014\/revisions"}],"predecessor-version":[{"id":7024,"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/posts\/7014\/revisions\/7024"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/media\/7016"}],"wp:attachment":[{"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/media?parent=7014"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/categories?post=7014"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/tags?post=7014"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}