Coldcard warns of seed-generation security incident affecting older MK3 devices

Coldcard has published a security advisory about a seed-generation issue tied to older MK3 hardware wallet firmware, saying the problem may have affected wallets whose seeds were created on vulnerable versions. The company said it has issued firmware fixes and urged users to approach any wallet migration carefully.
The advisory, posted on Coldcard’s official blog, says the issue is linked to entropy in the seed-generation process rather than to hardware wallets broadly. According to the notice, the confirmed impact applies to Coldcard MK3 devices running firmware versions 4.0.1 through 5.0.3.
Older MK3 firmware is the focus of the warning
Coldcard said the affected range is limited to the MK3 model and that other models appear to remain safe. The company’s guidance centers on users who created seeds on vulnerable firmware, since those wallets may carry a security risk even if they have remained offline.
The advisory does not frame the issue as a general failure of hardware wallets, but as a specific problem in Coldcard’s own security review and seed-generation process. That distinction matters for readers trying to judge whether the incident affects self-custody tools more broadly.
Users are being told not to rush a migration
Coldcard also warned that moving funds too quickly can introduce new risks if the process is handled carelessly. In its guidance, the company said users should migrate with “care and calm,” underscoring that a hurried transfer can create a more immediate problem than the one being addressed.
Secondary reports have since described the incident as linked to thefts from wallets that may have used vulnerable seed generation, but the clearest public reference point remains Coldcard’s own advisory. The company’s statement is the main confirmed source for the affected firmware range and the recommended response.






