Hardware wallets are usually sold around one simple idea: keep the private key away from the internet, and you remove a large part of the risk.
That is true, but only after the key has been created correctly.
A recent warning from Coinkite shows how security can fail much earlier – at the moment the wallet generates its seed phrase. The device may remain offline, never expose the key to a computer and still create a wallet that is far easier to attack than its owner realizes.
On July 30, Coinkite advised users to move funds from wallets whose seed phrases were generated on a Coldcard Mk3 running firmware 4.0.1 or later.
Older firmware versions on the Mk4, Mk5 and Q were also affected, although Coinkite estimates that the problem was less severe on those devices.










