The thing about "self-custody" is it only works if the math that protects your private key actually stays private.

The Summary

The Signal

A hardware wallet's entire security model rests on one promise: the random number generator (RNG) that creates your seed phrase produces entropy no one else can reproduce. The Coldcard Mk3's RNG failed that test. Instead of true randomness, it produced weak, predictable keys. Attackers who understood the flaw could regenerate the same "unique" seed phrases and drain wallets at will.

The speed of the drain tells you everything. 594 BTC across multiple addresses, swept clean in 25 minutes. That's not someone guessing passwords. That's automated tooling, probably running through a list of compromised seeds generated by the faulty RNG. The attackers knew exactly which wallets to hit.

"A hardware wallet randomness bug turned 'impossible to guess' seeds into guessable ones, and $38 million is already gone."

Coinkite's warning to Mk3 users is unambiguous: migrate your funds now. Not next week. Not after you check Reddit. Now. The company identified a "potential seed-generation risk" in the Mk3 line, which is corporate-speak for "the thing we told you was cryptographically secure wasn't." Newer models don't appear affected, but if your Bitcoin sits on a Mk3-generated seed, you're holding a losing lottery ticket.

Here's what makes this different from exchange hacks or bridge exploits:

  • Self-custody was supposed to eliminate counterparty risk
  • Hardware wallets were the gold standard for serious holders
  • The failure wasn't in user behavior but in the device's core function

This undermines the foundation of the "not your keys, not your coins" mantra. If the device that generates your keys is flawed, self-custody becomes self-exposure.

The Implication

If you're holding Bitcoin on a Coldcard Mk3, you need to assume your wallet is compromised and move funds to a new address generated on different hardware. Don't transfer to another Mk3-generated address. That's like changing the lock on a door after someone stole the master key to the whole building.

For the broader crypto ecosystem, this is a reminder that hardware security is only as strong as its weakest component. The RNG is the foundation. If it's flawed, everything built on top collapses. Expect other hardware wallet makers to face scrutiny over their entropy sources. The next few weeks will reveal whether this is a Coldcard problem or an industry-wide vulnerability that no one bothered to audit closely enough.

Sources

BeInCrypto | CoinDesk | CoinTelegraph