First published
7/31/2026
Last updated
8/2/2026

Coinkite just released a security advisory warning that private keys generated on a Coldcard device may be vulnerable to attack due to a lower than expected number of random bits. Mk3, Mk4, Mk5, and Q models are all affected, with Mk3 most severely vulnerable.

How This Affects Unchained Vaults 

An Unchained vault is most commonly composed of three total keys, including two client-controlled keys and the Unchained key. Unchained’s private key is not affected by this vulnerability.

If you generated private keys on Coldcard devices, the funds in your Unchained vault may be at risk of loss! 

Note: Even if you subsequently transferred your private keys to Trezor, Ledger, or other devices, if you originally generated them on a Coldcard, they are still vulnerable.

What You Should Do 

The actions we are requesting you to take will differ based on your situation.

If you generated 2 of 3 private keys on a Coldcard:
  1. If you have funds contained at an address which was previously spent from, then these funds are at immediate risk of loss. If we have determined that you are in this category, you will have received an email from us.
    1. We recommend that you immediately sweep these funds into a new vault. Step-by-step instructions (including for IRA vaults) may be found in our knowledge base.
    2. Make sure to set a high fee rate – exceeding 50 sats/vbyte – to ensure your sweep transactions are promptly mined.
    3. Do not hesitate based on potential RBF attacks because your funds are already vulnerable.
  2. If you have not reused addresses, then your funds are less likely to be at immediate risk of loss.
    1. We still recommend that you sweep your funds into a new vault. Step-by-step instructions (including for IRA vaults) may be found in our knowledge base.
    2. When you broadcast this sweep transaction, you may become vulnerable to RBF attacks. There are steps you may choose to take which may reduce RBF attack risk:
      1. Submit your sweep transaction directly to a miner rather than broadcasting it to the mempool. Step-by-step instructions for doing this are found on our knowledge base.
        AND/OR
      2. Set a high transaction fee so your transaction is more difficult to RBF.
    3. Any other transaction on your vault, including a transaction to sell bitcoin, is subject to the same risks.

If you generated 1 of 3 private keys on a Coldcard:

Your funds are safe absent an additional security breach, but you should still take steps to build a new vault with uncompromised keys when you can. Step-by-step instructions (including for IRA vaults) may be found in our knowledge base.

Replacing Your Hardware 

If you are affected and need new hardware devices, they can be purchased online or at local retailers such as Best Buy. Note that simply transferring your existing private keys from vulnerable Coldcards to new devices does not fix the underlying vulnerability. New keys must be generated on new devices.

If you choose not to purchase new devices, you may choose instead to update your vulnerable Coldcard firmware to a new version that Coldcard has represented as fixing the bug and regenerating keys after this update. Unchained has not reviewed the firmware upgrade for sufficiency, so please refer to Coldcard's security update for further information.

If You Need Unchained to Co-Sign 

If you need Unchained to co-sign a sweep transaction with you: please be aware that using Unchained’s signature alongside your own does not provide more security than signing the transaction entirely yourself (since all vulnerable Coldcard-derived public keys in a redeem script are exposed regardless of who signs).  During this time, we have increased the cadence of our reviews and are working to process each request for Unchained’s key signature as quickly as possible, while maintaining appropriate diligence and control standards.

Why Multisig Matters 

Multisig lets you use devices from multiple vendors so a newly-discovered vulnerability affecting only one does not by itself compromise your bitcoin. If you’re already a client, this is a great opportunity to help friends and family who may be exposed to risks like these

Frequently Asked Questions

1. Which keys are affected?

Treat any key or seed phrase generated by a Coldcard as potentially compromised, regardless of the Coldcard model or where that seed is stored today. Moving a Coldcard-generated seed to another hardware wallet does not make it safe.

A seed generated by a different hardware wallet and later imported into a Coldcard is not affected by this seed-generation vulnerability. If you are not certain where a seed was originally generated, treat it as affected and replace it.

2. Is the Unchained key affected?

No. The Unchained-controlled key was generated independently of Coldcard and is not affected by this vulnerability.

3. I have one Coldcard-generated key and one key generated by another device. Are my funds at risk?

An attacker with only one of the three keys in a standard 2-of-3 Unchained vault cannot move your bitcoin. Your vault retains its multisig protection as long as your other client key and the Unchained key remain secure.

Replace the Coldcard-generated key when you are able, to restore full redundancy, but take the time to verify every step and destination address. A rushed or incorrect transaction can create more risk than a careful replacement.

4. I had two affected Coldcard keys, but I already replaced one. Am I still exposed to the RBF attack?

No, not to the RBF attack described. Once the first replacement transaction is confirmed, the attacker no longer has the 2-of-3 threshold needed to replace a pending transaction.

The remaining Coldcard-generated key is still potentially compromised and should also be replaced when you are able.

5. I have two affected Coldcard keys. Should I replace both keys individually or create a new vault?

Create a new vault using two independently generated, non-Coldcard keys and transfer the full balance. This is the preferred path when both client-controlled keys need replacement because it avoids two sequential key-replacement workflows. Instructions can be found here. Be mindful of the RBF attack risk, and the option to use Slipstream.

6. Can I replace one key now and the second later?

Yes. Replacing one affected key is a meaningful security improvement because it removes the attacker's ability to reach the 2-of-3 signing threshold. Be mindful of the RBF attack risk, and the option to use Slipstream. Complete the second replacement as soon as practical so neither of your keys remain potentially compromised.

7. What is a reused address, and am I exposed if I deposited funds to the same address several times?

For this specific attack scenario, the relevant pattern is an address from and later received bitcoin again. (Addresses and vaults are not the same thing. If you've spent from a vault and received bitcoin again in that vault, it was most likely received to a new address.) Spending reveals information that is not public when an address has only received bitcoin. You do not need to hesitate before transacting due to RBF attacks because your funds are already vulnerable. Please read the next question and answer below.

Several deposits to the same address doesn’t necessarily create this particular exposure. 

8. How can I tell whether I have funds on a reused address?

We have attempted to reach out to clients we believe have 2 Coldcards and funds on a reused address. We do not believe there are many clients in this position.

If you have never spent funds from your vault, then you have no reused addresses in that vault. Additionally, if you have clicked the Deposit button to generate a new address for each deposit you’ve made, then you have no reused addresses in that vault.

If you cannot determine this confidently, contact Unchained Support and ask for help reviewing your vault. Note that this is only relevant to you if you have a vault with 2 Coldcard-generated keys.

9. If I sell bitcoin through the Unchained trading desk, does the RBF risk still apply?

Yes. A sale from an Unchained vault is an on-chain transaction that is signed and broadcast to the bitcoin network. Do not assume that using the trading desk avoids the pending-transaction exposure. Consider mitigation using Slipstream

10. What hardware wallets can I use as replacements?

For this remediation, use a non-Coldcard device. See Unchained's current hardware-wallet support list.

11. Does account lock protect me from this vulnerability?

No. Locking your account helps protect the Unchained account from unauthorized online access. It cannot stop an attacker who already has enough private keys and wallet information from creating and broadcasting a transaction directly to the bitcoin network.

You do not need to lock your account unless you believe your account credentials are at risk. Unlocking your account to take further action can take time.

12. What happens to vaults that use a key shared through Connections?

Coordinate the replacement with every Connection partner before starting. A shared-key replacement can affect multiple vaults, and each funded vault may require a sweep transaction into a new key quorum.

Pause new deposits until the replacement is complete. Each vault owner must broadcast the transaction generated for their vault. Follow Unchained's shared-key replacement guidance.

13. Are IRA key replacements or vault-to-vault transfers taxable events?

A key replacement or transfer between vaults inside the same Unchained IRA does not move the assets out of the IRA and is generally not treated as a taxable distribution. Keep the assets within the same IRA account.

Transfers outside of vaults within an IRA account will be reported to the IRS as taxable withdrawals. Unchained does not provide tax or legal advice; confirm any situation-specific questions with your tax adviser.

14. Why does the IRA interface show an alarming warning when I request a deposit address?

The warning is intended to prevent an outside deposit from being sent directly to an IRA vault without going through the approved contribution or rollover process.

You may proceed when you are using Unchained's workflow to move bitcoin between vaults in the same IRA account. Do not disregard the warning for bitcoin coming from a personal wallet, exchange, or any other source outside the IRA.

15. Can I sell the bitcoin to cash inside my IRA while I replace keys?

Yes. You can sell bitcoin within the IRA and keep the proceeds as cash inside the same IRA account. Keeping the proceeds inside the IRA does not create a distribution. Follow the approved IRA trading workflow and consult your tax adviser if you have questions about your circumstances. If you have 2 Coldcards, be mindful of the RBF attack risk.

16. How quickly will Unchained process replacement signatures?

We have increased the cadence of our reviews and are working to process each request for Unchained’s key signature as quickly as possible, while maintaining appropriate diligence and control standards.

17. Is free help available, or is a paid concierge session required?

Paid Concierge service is not required for ordinary client support. Active Unchained clients can request help by emailing hello@unchained.com or calling +1 844-486-2424. We are experiencing high volumes and wait times are longer than usual.

Concierge and Signature services are available for clients who want scheduled one-on-one video call assistance or enhanced ongoing support. Currently, wait times are also longer than usual for these services.

DISCLAIMER: This article is provided for educational purposes only and has not been tailored to your specific circumstances. Please do your own research before taking any action or inaction based on the contents of this article.