First published
7/31/2026
Last updated
7/31/2026

Coinkite just released a security advisory warning that private keys generated on a Coldcard device may be vulnerable to attack due to a lower than expected number of random bits. Mk3, Mk4, Mk5, and Q models are all affected, with Mk3 most severely vulnerable.

How This Affects Unchained Vaults 

An Unchained vault is most commonly composed of three total keys, including two client-controlled keys and the Unchained key. Unchained’s private key is not affected by this vulnerability.

If you generated private keys on Coldcard devices, the funds in your Unchained vault may be at risk of loss! 

Note: Even if you subsequently transferred your private keys to Trezor, Ledger, or other devices, if you originally generated them on a Coldcard, they are still vulnerable.

What You Should Do 

The actions we are requesting you to take will differ based on your situation.

If you generated 2 of 3 private keys on a Coldcard:

  1. If you have funds contained at an address which was previously spent from, then these funds are at immediate risk of loss. If we have determined that you are in this category, you will have received an email from us.
    1. We recommend that you immediately sweep these funds into a new vault. Step-by-step instructions may be found in our knowledge base.
    2. Make sure to set a high fee rate – exceeding 50 sats/vbyte – to ensure your sweep transactions are promptly mined.
    3. Do not hesitate based on potential RBF attacks because your funds are already vulnerable.
  2. If you have not reused addresses, then your funds are less likely to be at immediate risk of loss.
    1. We still recommend that you sweep your funds into a new vault. Step-by-step instructions may be found in our knowledge base.
    2. When you broadcast this sweep transaction, you may become vulnerable to RBF attacks. There are steps you may choose to take which may reduce RBF attack risk:
      1. Submit your sweep transaction directly to a miner rather than broadcasting it to the mempool. We will shortly be publishing step-by-step instructions for doing this on our knowledge base – check back here for a link once it is ready.
        AND/OR
      2. Set a high transaction fee so your transaction is more difficult to RBF.
    3. Any other transaction on your vault, including a transaction to sell bitcoin, is subject to the same risks.

If you generated 1 of 3 private keys on a Coldcard 

If you generated 1 of 3 private keys on a Coldcard then your funds are safe absent an additional security breach, but you should still replace your vulnerable key. Step-by-step instructions may be found in our knowledge base.

Replacing Your Hardware 

If you are affected and need new hardware devices, they can be purchased online or at local retailers such as Best Buy. Note that simply transferring your existing private keys from vulnerable Coldcards to new devices does not fix the underlying vulnerability. New keys must be generated on new devices.

If you choose not to purchase new devices, you may choose instead to update your vulnerable Coldcard firmware to a new version that Coldcard has represented as fixing the bug and regenerating keys after this update. Unchained has not reviewed the firmware upgrade for sufficiency, so please refer to Coldcard's security update for further information.

If You Need Unchained to Co-Sign 

If you need Unchained to co-sign a sweep transaction with you: please be aware that using Unchained’s signature alongside your own does not provide more security than signing the transaction entirely yourself (since all vulnerable Coldcard-derived public keys in a redeem script are exposed regardless of who signs).  During this time, we have increased the cadence of our reviews and are working to process each request for Unchained’s key signature as quickly as possible, while maintaining appropriate diligence and control standards.

Why Multisig Matters 

Multisig lets you use devices from multiple vendors so a newly-discovered vulnerability affecting only one does not by itself compromise your bitcoin. If you’re already a client, this is a great opportunity to help friends and family who may be exposed to risks like these

DISCLAIMER: This article is provided for educational purposes only and has not been tailored to your specific circumstances. Please do your own research before taking any action or inaction based on the contents of this article.