
Galaxy Research linked suspected Coldcard-related sweeps across 4,585 addresses to three attack waves, while Coinkite widened warnings, issued fixed firmware and urged users to regenerate seeds and move funds.
A Coldcard seed-generation vulnerability affecting Coinkite hardware wallets widened beyond the initial Mk2 and Mk3 focus, with Block’s Bitcoin engineering team and Coinkite tracing the main confirmed issue to a broken random-number-generator check that can leave wallet creation dependent on predictable device data rather than true randomness. Bitcoin Core contributor instagibbs said he reproduced the flaw on a newly initialized Mk3. Coinkite said users should assume seeds generated before the latest fixes may be compromised, upgrade firmware, create a new seed phrase and move funds immediately, while noting that a strong BIP-39 passphrase can materially reduce risk but does not remove the need to migrate. Galaxy Research said its preliminary on-chain analysis linked suspected thefts tied to the vulnerable firmware to 4,585 addresses in three waves between July 30 and Aug. 1. Galaxy’s reporting cited 1,158.8480 BTC in one breakdown, while a newer figure from the same research line put the drained total at 1,367.05 BTC. Coinkite has not verified that the wallet drains were caused by the firmware flaw, and Galaxy said blockchain data alone cannot determine whether later sweeps were carried out by the same attacker or a separate party exploiting the same vulnerable address pool.