Coldcard Firmware Flaw Exposes Thousands of Bitcoin Wallets
A security flaw in Coldcard seed phrase generation has put thousands of Bitcoin wallets at risk. The issue, which affects devices produced by Coinkite, allowed attackers to derive and test keys offline under specific conditions.
The vulnerability was discovered in March 2021 firmware integration error that redirected seed generation to a deterministic pseudorandom number generator instead of the STM32 hardware random number generator.
Coinkite estimated effective entropy of approximately 40 bits for Mk3 hardware and around 72 bits for Mk4, Mk5, and Q models, compared with the 128-bit entropy expected from a standard 12-word BIP-39 seed.
The company released emergency firmware updates on July 31, but installing new firmware does not retroactively secure seeds already generated under vulnerable conditions. Users with potentially exposed seeds were advised to generate new seeds on updated firmware and transfer their funds, as restoring an original weak seed would preserve the vulnerability.