Coldcard Seed-Generation Flaw Triggers Wallet Drains; ~1,000 BTC Spotted Moving On-Chain

AI Market Summary
A Coldcard seed-generation randomness bug affecting MK3/MK4/MK5/Q wallets is reportedly being exploited, with ~1,000 BTC linked to the issue moving on-chain. Because compromised seeds can enable direct asset loss, the event elevates near-term self-custody and hardware-wallet trust risk, potentially driving key-rotation urgency and shifting some users toward alternative custody paths. Coinkite's firmware patch may contain the issue if adoption is rapid.
Impact level
● Medium
Affected assets
BTC/USDT-2.86%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Coldcard users are reporting active wallet drains tied to a seed-generation weakness affecting Coldcard MK3, MK4, MK5 and Q devices. The flaw enables attackers to recover seed phrases without any user interaction in certain cases. According to the disclosure, wallets created after the end of 2020 may be vulnerable if the seed was generated without sufficient entropy—specifically, without at least 50 dice rolls. Seeds produced under these conditions may not have enough randomness and could be brute-forced. Roughly 1,000 BTC has been observed moving on-chain in activity linked to the vulnerability. The issue extends beyond standard seeds. It can also impact ephemeral keys, session keys used for Clone Coldcard or Key Teleport, and BIP 85 child seeds if they were derived from a compromised parent seed. Coinkite has released a firmware update to address the problem. Seeds generated after installing the patched firmware are expected to be secure. Why it matters: A custody-level failure can rapidly turn a hardware or firmware issue into direct asset loss. If a seed is exposed, users may need to rotate keys and migrate funds quickly. Market sentiment: Bearish, stress-on, event-driven, de-risking. Traders and holders are treating the reports as an urgent self-custody risk due to confirmed drains and associated on-chain movement. Comparable precedent: In 2023, Trust Wallet patched a browser extension wallet-generation vulnerability that resulted in about $170,000 in user losses; the company said only users who created addresses during the affected window were impacted (The Block). In contrast, the current incident centers on Coldcard seed generation and includes reported active BTC movement, making remediation primarily dependent on seed rotation rather than simply updating an extension. Ripple effects: Custody shocks typically propagate through user migration, hardware-wallet trust, and exchange deposit behavior more than through protocol liquidity. If additional vulnerable seeds are swept before users move funds, confidence in self-custody tooling could weaken. If firmware uptake and seed rotation slow new drains, the fallout may remain largely confined to affected Coldcard users. Opportunities and risks: - Opportunities: If adoption of Coinkite’s firmware patch and fresh seed generation halt the related on-chain drains, verified migrations could be read as a security-stabilization signal. - Risks: If further on-chain movements tied to the flaw appear before users relocate funds, exposure reduction via prompt seed rotation becomes critical to limiting direct custody losses.