Coldcard seed-generation flaw linked to 594 BTC drained in 25 minutes
Coinkite has confirmed a seed-generation flaw affecting parts of the Coldcard hardware-wallet line, after on-chain analysts tracked the theft of 594.48 BTC in a burst of transactions completed within roughly 25 minutes. The incident involved 1,324 UTXOs swept through 500 transactions across a three-block window, with the funds taken from about 500 single-signature addresses. Security researchers said the issue traces back to firmware changes introduced in March 2021 that accidentally disabled the secure chip’s hardware random-number generator, leaving key generation to rely on predictable inputs such as a chip serial number and clock registers. Coinkite first focused its warning on the Mk3, then later expanded the affected scope to include older firmware on the Mk4, Mk5 and Q. The company said users should not wait for a firmware update and should move funds by creating a new seed on an unaffected device, verifying backups, testing with a small transaction and then transferring the full balance. Devices including TAPSIGNER, OPENDIME and SATSCARD were said to be outside the affected codebase.








