- Block identified two Coldcard wallet vulnerabilities affecting cryptographic seed generation.
- The flaws impact Mk2–Mk5 and Q models, potentially making some wallet seeds more predictable.
- Affected users should generate new secure seed phrases after updating firmware and moving funds.
Max Guise, the Bitcoin Product Lead at Block, has highlighted key aspects of the latest report from the firm’s Bitcoin engineering and security team investigating the draining of non-Bitkey wallets. The report alleged flaws in cryptographic key generation that may have made some Bitcoin wallets predictable rather than truly random, among other critical issues.
Block’s disclosure has raised broader questions about hardware wallet design, responsible vulnerability disclosure, and how self-custody users should assess the security of their seed phrases and key generation processes. Beyond the report and potential consequences, Bitcoin users are curious about the vulnerabilities Block identified in different Coldcard hardware wallet models and how they affect cryptographic key generation.
Vulnerabilities Identified by Block
Block’s report identified two key vulnerabilities affecting several Coldcard hardware wallet models. The first issue impacted the Mk2 and Mk3 devices, where a firmware error caused the wallet to rely on Yasmarang, a deterministic software-based random number generator (RNG), instead of the device’s true hardware RNG when creating wallet seeds. According to the report, this could make wallet generation more predictable under certain conditions, potentially increasing the risk of private key recovery.
The second vulnerability affects the Mk4, Mk5, and Q models. While these devices introduced an additional security layer by adding hardware-generated randomness during startup, Block found that the implementation retained only a small portion of that entropy during the reseeding process. According to the report, this may limit the amount of secure randomness used to generate wallet seeds, reducing the overall cryptographic strength of the process.
Lessons for the Bitcoin Ecosystem
The incident reported by Block underscores critical structural realities regarding the security of self-custody hardware. It shows that codebases require continuous, behavioral audits. It also reveals that total reliance on vendor code creates a single point of failure and reinforces that responsible disclosure prevents mass exploitation. Note that Block’s private notification allowed Coinkite to develop fixes before the vulnerabilities became public knowledge.
Considering the current situation, Coldcard users who generated their seed phrase on an affected model without using manual dice rolls or a BIP-39 passphrase are advised to isolate their devices and ensure they run on clean, malware-free computers. They would need to run a complete offline firmware update, establish a temporary hot wallet, move their Bitcoins to the hot wallet, generate a new secure seed phrase, and move their funds back to cold storage.
Related: 594 BTC Stolen From 500 Wallets as Coldcard Seed Flaw Investigated
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.