Crypto
Home›Crypto›Market Structure›Coldcard seed generation flaw could allow private-key…
Coldcard seed generation flaw could allow private-key recreation
Coinkite says affected Coldcard models could require an on-chain migration to new keys because updated firmware cannot change the key material behind already-generated addresses.
A flaw in how Coldcard hardware wallets generate seed phrases could let an attacker recreate the private keys, according to information discussed by Coinkite and a Bitcoin Core contributor. The issue is tied to seeds created during device setup before specific firmware versions.
Coinkite said funds connected to seeds generated on Coldcard Mk3 devices running firmware 4.0.1 or later may be at risk, and that Mk4 and Mk5 devices are also affected until firmware 5.6.0. For Coldcard Q devices, Coinkite said the exposure begins before firmware 1.5.0Q, and that the impact is less severe but still serious.
Bitcoin Core contributor instagibbs demonstrated the vulnerability by recreating the vulnerable seed on a newly initialized Mk3 device, showing how predictable seed generation can undermine the hardware wallet’s offline protections. The company said it plans a formal technical review of the root cause.
The underlying concern is that seed generation happens before secure storage, offline signing, and on-device verification, so weak randomness can reduce the seed space until candidate seeds can be tested and addresses monitored for deposits. Coinkite advised that because updated firmware cannot change the key material controlling old addresses, the clear remediation for at-risk wallets is to move to new keys via a newly generated seed, and it highlighted that a strong, unique BIP-39 passphrase and multisig can add barriers.
Latest closeBitcoin $62,929.67 ▼2.8%