The alert dropped into a Bitcoin security Telegram group I follow on July 31, 2026, at 7:43 AM Bali time. I was half-awake, sipping kopi tubruk at the kitchen table while my daughter tried to convince me that cereal without milk was “basically the same thing.”
The message was three sentences: Coldcard Mk3 weak entropy exploit confirmed. 1,082 BTC drained since 2024. Check your firmware NOW.
I set down the coffee. I have a Coldcard Mk3.
What Actually Happened
Since at least early 2024, attackers have been quietly draining wallets tied to Coldcard Mk3 devices running firmware below version 4.0.3. The root cause is a weak entropy flaw — essentially, the random number generator used to create private keys wasn’t random enough.
Not “slightly less random.” Predictably broken under targeted conditions.
As of August 3, 2026, the confirmed damage:
- 1,196+ wallets compromised
- 1,082.65 BTC stolen (~$70.2M at current prices)
- Attacks ongoing — the flaw was baked into key generation, so wallets created under old firmware remain vulnerable even after patching
Coldcard’s manufacturer (Coinkite) released the Mk4 and Mk5 with the entropy issue fixed. But existing Mk3 owners — many of whom bought the device precisely because they wanted long-term reliable cold storage — got caught in the gap between hardware generation and public disclosure.
Confession: I didn’t check my firmware version for 14 months. I set up the Mk3, did the seed ceremony correctly, put it in a dry box, and felt smug about my security hygiene. That smugness is exactly how this kind of attack finds victims.
Who Is at Risk: The Exact Criteria
You’re in the danger zone if all three of these apply:
- You own a Coldcard Mk3 (not Mk4 or Mk5)
- Your wallet was created when your firmware was below version 4.0.3
- You haven’t already migrated to a new seed on patched hardware
If you bought a Mk3 after Coinkite released the 4.0.3 patch and ran the upgrade before ever generating a seed — you’re fine. The key generation happens at wallet setup, not continuously. The entropy problem is frozen into the seed the moment it was generated.
That last point trips people up. Updating firmware on a Mk3 does not fix a wallet created under bad entropy. The private keys those seeds derived are still predictable to anyone running the attack vector. You have to generate fresh keys on clean hardware and move your funds.
The 5-Step Survival Checklist
Step 1: Check Your Firmware Version
Power on the Mk3. Navigate to: Advanced → Upgrade → Show Version
- Version 4.0.3 or higher: firmware is patched. Still read Step 2.
- Version below 4.0.3: you are running vulnerable firmware. Move to Step 2 immediately.
Step 2: Determine When Your Wallet Was Created
This is the critical question. If you generated your seed phrase on the Mk3 before you upgraded to 4.0.3, that seed may have been created under compromised entropy — even if you’ve since patched the device.
Check your records. When did you first initialize this Coldcard? If you don’t know, assume the worst.
Step 3: Upgrade Firmware (and Understand What It Does — and Doesn’t — Fix)
If you’re on firmware below 4.0.3:
- Go to coldcard.com and download the latest Mk3 firmware
- Verify the SHA256 hash before loading onto the device (Coinkite publishes them)
- Follow the official upgrade procedure — do NOT skip the hash verification step
What this fixes: protects any new seed you generate after the upgrade. What this does NOT fix: any existing seed created before the upgrade. Those keys are still potentially exposed.
Step 4: Migration Decision Tree
If your seed was created AFTER you installed 4.0.3 (or you bought a Mk4/Mk5): → You’re likely fine. Continue monitoring for future disclosures.
If your seed was created BEFORE 4.0.3 on Mk3: → Treat the wallet as compromised. Proceed to full migration.
Full migration process:
- Get a new hardware wallet — either a Coldcard Mk5, a Ledger Nano X, or a Trezor Safe 5. Diversify hardware manufacturers if you’re moving to multisig.
- Generate a fresh seed phrase on the new device. Never reuse the Mk3 seed.
- Move funds in a single transaction from the old Mk3 wallet to the new wallet. Don’t do it in pieces — each on-chain move costs fees and delays.
- Verify the transfer confirmed on-chain before powering down the Mk3.
- Destroy or securely archive the old seed. Don’t keep it around as a “backup” — it’s a liability.
Step 5: Harden with Multisig (If Your Balance Warrants It)
If you’re holding more than $20,000 in self-custody, the Coldcard Mk3 incident makes a strong argument for multisig.
A 2-of-3 multisig setup means: even if one device is fully compromised, the attacker can’t move your funds without the other keys. Here’s a setup that costs roughly $400-500 in hardware and takes a weekend to configure properly:
- Key 1: Coldcard Mk5 (air-gapped signing)
- Key 2: Trezor Safe 5 (different manufacturer, different attack surface)
- Key 3: Paper/steel backup stored offline in a separate location
Tools like Sparrow Wallet (free, open-source) coordinate the multisig policy on the software side. Unchained Capital also offers custodial multisig assistance for those who want human backup verification.
The tradeoff: more complexity at signing time. Each spend requires pulling out two devices. For long-term cold storage that you don’t touch often, that friction is a feature, not a bug.
Mk3 vs Mk4 vs Mk5: What Changed
| Model | Entropy Issue | Status | Notes |
|---|---|---|---|
| Coldcard Mk3 (fw < 4.0.3) | ❌ Vulnerable | Patch available | Wallets created under old fw still at risk |
| Coldcard Mk3 (fw ≥ 4.0.3) | ✅ Patched | Safe for new seeds | Old seeds remain exposed |
| Coldcard Mk4 | ✅ Not affected | Production model | Different hardware entropy source |
| Coldcard Mk5 | ✅ Not affected | Current flagship | Adds NFC, tap-to-sign |
The Mk4 and Mk5 ship with the entropy issue resolved at the hardware level, not just firmware. If you’re replacing hardware, the Mk5 at ~$220 is the current recommended Coldcard for long-term storage.
Why This Attack Stayed Hidden for Two Years
The weak entropy doesn’t make keys immediately breakable — it narrows the keyspace enough that attackers running targeted sweeps can reconstruct keys over time, especially for wallets with public transaction history (i.e., wallets that have sent Bitcoin, leaving the public key exposed on-chain).
The moment you spend from a Bitcoin address, your public key hits the chain. Normally that’s fine — public keys are designed to be public. But combined with a compromised entropy source, that public key becomes a partial leak toward your private key.
This is why the attack apparently started with more active wallets and worked its way through the victim list. Dormant wallets with no transaction history may still be at risk — they just haven’t been targeted yet.
The Solana DEX security rating framework I wrote a few weeks ago covered a similar delayed disclosure problem in DeFi protocols — the pattern is consistent: vulnerabilities stay quiet until someone maps the profitable attack path.
Passive Income and Cold Storage: The Connection
Here’s where this gets relevant for how I think about crypto as a passive income base: you can’t earn yield on assets you lose to hacks.
I know that sounds obvious. But the number of people who spent 2023-2025 chasing 15% DeFi yields while running Mk3 Coldcards on outdated firmware — that’s not a small group.
Security is the boring infrastructure that makes every other strategy work. The Raydium exploit last week (full survival guide here) cost RAY holders 14.1% in a day. The Coldcard Mk3 issue has been silently bleeding BTC since 2024. Both happened to people who were paying attention to yield, not security.
My current setup:
- BTC: Coldcard Mk5 (post-migration, new seed generated August 2026)
- ETH staking via Lido — hot wallet exposure managed via withdrawal address set to cold storage
- Stablecoin yield on Aave — accessed through a hardware wallet, not a browser extension
For my stablecoin yield strategy — Aave USDC at 3-7% APY as of August 2026 (APY fluctuates, verify on-chain before deploying) — the Aave and Lido yield stacking guide has the deployment details. But none of that matters if the cold storage holding the underlying BTC is compromised.
Fix the foundation first. Yield is the second layer.
If you’re holding Bitcoin specifically, the Bitcoin passive income strategies guide covers the risk hierarchy between hot and cold storage in more depth — including why self-custody defaults to cold storage for anything you’re not actively lending.
Timeline: What Coinkite Said and When
- 2024 (ongoing): Attacks begin against Mk3 wallets with exposed public keys
- Early 2026: Security researchers identify the entropy pattern in compromised wallets
- July 2026: Coinkite issues public disclosure and firmware patch confirmation
- August 3, 2026: Full scope confirmed: 1,196+ wallets, 1,082.65 BTC (~$70.2M)
Coinkite’s official response includes: confirming the firmware 4.0.3 patch, recommending migration for any seed generated pre-patch, and publishing verification tools for affected addresses. They’re not covering losses — this is a self-custody product, and the risk disclosure was always part of the package.
That’s not a criticism. It’s just the reality of hardware wallets: you own the keys, you own the responsibility.
The Risk Section (Read This)
Hardware wallet vulnerabilities are not theoretical. The $70.2M figure above is real. That said:
- Mk4 and Mk5 owners are not affected. The entropy issue is Mk3-specific.
- Firmware 4.0.3 on Mk3 protects new seeds generated after the upgrade. It does not retroactively protect compromised seeds.
- Migration has risks too. Sending your entire BTC balance to a new wallet in a single transaction requires careful attention to address verification. Triple-check the destination address. Use a testnet transaction if unfamiliar with the process.
- Multisig adds complexity. A mismanaged multisig setup can lock you out of your own funds. Practice the recovery procedure before loading any significant balance.
If you’re unsure, consult with a Bitcoin-only technical advisor before moving significant holdings. The cost of getting advice is lower than the cost of losing funds to a botched migration.
Passive income isn’t lazy money — it’s freedom money.
But freedom money has to be protected first. The Coldcard Mk3 situation is a reminder that cold storage is a practice, not a product purchase. Devices need maintenance, firmware updates, and periodic audit.
Check your firmware version today. It takes 90 seconds.
Disclaimer: This article is educational and not financial advice. Cryptocurrency involves significant risk including loss of principal. All security recommendations reflect best practices as of August 2026 and may change as new information emerges. Verify firmware versions and migration procedures directly on Coinkite’s official website before taking action.
Join the Discussion