- What Is the Coldcard Mk3? (And Where It Sits in 2026)
- Coldcard Mk3 at a Glance
- The July 2026 Coldcard “Entropy” Exploit — What Every Mk3 Owner Must Know
- Security Features (and Their Limits)
- Design, Build and Everyday Use
- Supported Cryptocurrencies
- Price, Value and the Current Coldcard Line-Up
- Should You Buy It? A Simple Decision Framework
- Buying & Funding a Coldcard in Malaysia & Singapore
- Common Pitfalls to Avoid
- Conclusion
- Frequently Asked Questions
Coldcard Mk3 Review — 2026 Verdict
Our rating: 5.5/10 (was 8.8/10 — downgraded after the 2026 entropy incident and discontinuation)
Our verdict: The Coldcard Mk3 was, in its day, one of the most respected Bitcoin-only cold wallets — air-gapped, open-source and built for people who take self-custody seriously. In 2026 the picture is very different. Coinkite has retired the Mk3 in favour of the Mk4/Mk5 and the Coldcard Q, and the device sits at the centre of the July 2026 “entropy” exploit that drained an estimated 1,816 BTC (~US$116 million). Any Mk3 wallet whose seed was generated between March 2021 and Coinkite’s 31 July 2026 patch should be treated as compromised. We no longer recommend the Mk3 for a fresh setup — buy a current model instead — and if you already own one, act on the migration steps below without delay.
Pros:
- Air-gapped (MicroSD/PSBT) transaction signing
- Fully open-source firmware
- Strong Bitcoin-only feature set (multisig, passphrases, duress PIN)
Cons:
- Discontinued — no longer sold by Coinkite
- Directly affected by the 2026 seed-entropy flaw (worst-hit model)
- Single secure element vs the dual-SE design of newer Coldcards
- Bitcoin only; steep learning curve for beginners
IMPORTANT SECURITY UPDATE (July 2026): A firmware bug first shipped in March 2021 caused some Coldcards to generate wallet seeds with far weaker randomness than intended. On the Mk3 this cut effective key strength to roughly 40 bits — low enough to brute-force without any physical access to the device. Beginning 30 July 2026, attackers swept an estimated 1,816 BTC (~US$116 million) from 5,200+ addresses. Updating firmware does not fix an already-generated seed. If you created your Mk3 wallet between March 2021 and 31 July 2026 (and did not add a BIP39 passphrase or 50+ dice rolls), generate a brand-new seed on a patched device and move your coins now. Full steps are in the section below.
For serious Bitcoin holders, security is everything — and few devices earned as much trust from the “not your keys, not your coins” crowd as the Coldcard. This updated Coldcard Mk3 review looks at what the wallet does well, where it now falls short, and — crucially — what the 2026 entropy exploit means for anyone who owns one or is thinking of buying one second-hand. With Bitcoin trading around US$79,000 in late August 2026 (after topping US$81,000 on 25 August), the stakes for getting cold storage right have rarely been higher.
Let’s look at why the Mk3 was so highly regarded, why we can no longer recommend it for a new setup, and which Coldcard makes sense today.
What Is the Coldcard Mk3? (And Where It Sits in 2026)
The Coldcard Mk3 is a Bitcoin-only hardware wallet made by Canadian manufacturer Coinkite. Launched in 2019, it built its reputation on true air-gapped operation — signing transactions offline via MicroSD card and PSBT files so private keys never touch an internet-connected device — plus fully open-source firmware that anyone can audit.
In 2026 the Mk3 is a legacy device. Coinkite has moved its line-up forward: the Mk4 arrived in 2022 with two secure-element chips and native NFC, the keyboard-and-QR Coldcard Q followed, and the current Mk-series (Mk4/Mk5) plus the Q are what Coinkite ships today. The Mk3 is no longer listed for sale on the official store. That matters for two reasons: newer models have a stronger hardware-security architecture, and — as the 2026 incident showed — the Mk3’s older firmware left it the most exposed to the seed-entropy flaw.
If you want the wider landscape first, our guide to the best cold storage wallets compares the leading options side by side.
Coldcard Mk3 at a Glance
| Feature | Details |
|---|---|
| Product | Coldcard Mk3 (Coinkite) |
| Type | Bitcoin-only hardware wallet |
| Status (2026) | Discontinued — superseded by Mk4/Mk5 & Coldcard Q |
| Supported assets | Bitcoin (BTC) only |
| Connectivity | USB (power/data), MicroSD (air-gapped signing & backups) |
| Secure element | Single secure element (Mk4/Mk5 use two, from two vendors) |
| Security features | PIN + duress PIN, passphrases, multisig, encrypted MicroSD backups, tamper-evident case |
| Original price | ~US$120 (no longer sold new by Coinkite) |
| 2026 security note | Affected by the July 2026 entropy exploit — seeds made Mar 2021–Jul 2026 at risk |
| Best for | Existing owners migrating to a new seed; not recommended for new buyers |
The July 2026 Coldcard “Entropy” Exploit — What Every Mk3 Owner Must Know
This is the single most important thing to understand about the Mk3 in 2026, so we’ll be specific.
What went wrong. A build-configuration error in Coldcard firmware version 4.0.1, released in March 2021, caused affected devices to fall back on a weak software random number generator instead of the device’s hardware entropy source when creating a wallet seed. A hardware wallet’s entire security rests on that seed being unpredictable. When randomness collapses, so does the key.
How bad on the Mk3. On the older Mk3, effective key strength fell to as little as ~40 bits (versus the 128 bits it should have), while newer Mk4/Mk5/Q devices were weakened to around 72 bits. Forty bits is brute-forceable with modern computing power — and because the weakness is in the seed itself, an attacker never needs to touch your device.
What happened. Starting 30 July 2026, an automated operation drained roughly 594 BTC (~US$38 million) from about 500 single-signature wallets in just 25 minutes. Three more waves followed. As of early August 2026, Galaxy Research and TRM Labs put the running total near 1,816 BTC (~US$116 million) across 5,200+ addresses — the third-largest crypto hack of the year, and the figure is still being tallied.
Who is at risk. Any Coldcard whose seed was generated on affected firmware between March 2021 and Coinkite’s 31 July 2026 patch. Two groups are not considered at risk under Coinkite’s incident notes: wallets protected by a BIP39 passphrase, and seeds created with at least 50 added dice rolls of user entropy.
What to do right now (step by step)
- Update to the latest firmware Coinkite released for your model (patched 31 July 2026). This stops new weak seeds — but does not repair your existing one.
- Generate a completely new seed on the patched device (ideally add dice-roll entropy or a passphrase), or move to a current model such as the Mk4/Mk5 or Coldcard Q.
- Verify the new wallet’s fingerprint and a fresh receive address before sending anything.
- Migrate funds with a small test transaction first, then transfer the remainder once it confirms.
- Retire the old seed permanently — never reuse it, even after patching.
The bigger lesson, echoed by security researchers, is that self-custody relocates risk rather than removing it: a wallet is only as trustworthy as the process that generated its key. Combining independently designed devices in a multisig setup is one of the strongest defences against any single-implementation failure like this one.
Security Features (and Their Limits)
Setting the 2026 firmware flaw aside, the Mk3’s day-to-day security model remains genuinely strong — which is exactly why the entropy bug was such a shock. Here is what the device offers:
PIN & duress PIN A login PIN gates access, and a separate “duress” PIN can open a decoy wallet if you are ever coerced.
Air-gapped signing Transactions are exported to a MicroSD card, signed offline on the Mk3, then re-imported — private keys never touch an online machine.
Encrypted backups The wallet writes encrypted seed backups to MicroSD for recovery.
Open-source firmware The code is public and auditable — though, as 2026 proved, open source improves scrutiny without guaranteeing safety.
Secure element The Mk3 uses a single secure-element chip to store secrets. The later Mk4/Mk5 upgraded to two secure elements from two different manufacturers, so a flaw in one vendor’s chip is not a single point of failure — a meaningful architectural improvement over the Mk3.
Multisig & passphrases The Mk3 has excellent multisignature support and optional passphrase (“25th word”) protection. Notably, a passphrase-protected wallet was not exposed to the entropy exploit — a strong argument for always using one.
For a broader primer on the trade-offs between online and offline storage, see our explainer on hot wallets vs cold wallets.
Design, Build and Everyday Use
The Mk3 keeps a deliberately utilitarian design: a compact, rugged plastic body, a numeric keypad, a small OLED screen and a tamper-evident case that makes physical interference visible. It has no battery — it draws power over USB — and no touchscreen, reflecting a “reduce the attack surface” philosophy.
That minimalism is a double-edged sword. Experienced Bitcoiners appreciate the transparency and control; newcomers often find the workflow (PSBT files, MicroSD shuffling, terse menus) intimidating compared with the friendlier apps of a Ledger Nano X or the touchscreen of a Trezor. If you want a Bitcoin-only bearer device with an even simpler concept, the Opendime takes a different approach entirely.
Supported Cryptocurrencies
The Mk3 supports Bitcoin (BTC) only — by design. Coinkite’s philosophy is that focusing on a single asset lets it implement deeper, Bitcoin-specific security (advanced multisig, PSBT workflows, coin-control) without the complexity of maintaining dozens of chains. If you hold a diversified portfolio of altcoins, this is the wrong wallet; a multi-asset device will suit you better. If you are a Bitcoin-first holder, the single-asset focus is a feature, not a limitation.
Price, Value and the Current Coldcard Line-Up
The Mk3 originally sold for about US$120, but it is no longer available new from Coinkite. Buying one second-hand in 2026 is strongly discouraged — not only because of the entropy history, but because a used hardware wallet can never be fully trusted (a seller could have pre-initialised or tampered with it). If you want a Coldcard, buy a current model, brand new, from Coinkite or an authorised reseller.
Here is how the Mk3 compares with today’s options (prices approximate, in USD — always confirm at the official Coinkite store):
| Wallet | Approx. price | Secure elements | Notes |
|---|---|---|---|
| Coldcard Mk3 | ~US$120 (discontinued) | One | Legacy; affected by 2026 entropy flaw |
| Coldcard Mk4 / Mk5 | ~US$155–178 | Two (dual-vendor) | Current Mk-series; NFC, native SHA-256/AES |
| Coldcard Q | ~US$249 | Two (dual-vendor) | QWERTY keyboard, QR scanner, battery, dual SD |
| Ledger Nano S Plus | ~US$79 | One (EAL5+/6+) | Multi-asset; app-based |
| Trezor Safe 5 | ~US$169 | One (EAL6+) | Touchscreen; multi-asset |
For value, the Mk4/Mk5 is the natural successor for a Bitcoin-only setup, while the Q justifies its premium if you want a keyboard, on-device QR scanning and battery power. Shoppers in Malaysia should budget roughly RM650–RM1,050 (at about RM4.20 to the US dollar) plus shipping and any import duty from Canada.
Should You Buy It? A Simple Decision Framework
| Your situation | What we’d do |
|---|---|
| You own an Mk3 with a seed made Mar 2021–Jul 2026 (no passphrase/dice) | Treat the seed as compromised. Patch firmware, generate a new seed (or new device), migrate funds today. |
| You own an Mk3 with a BIP39 passphrase or 50+ dice rolls | Not classed as at-risk, but still update firmware and consider migrating to a current model for the dual-SE architecture. |
| You want a new Bitcoin-only cold wallet | Buy a current Coldcard Mk4/Mk5 (or the Q) new — skip the Mk3. |
| You’re tempted by a cheap second-hand Mk3 | Don’t. Used hardware wallets are untrustworthy; the small saving isn’t worth the risk. |
| You hold altcoins, not just BTC | Choose a multi-asset wallet instead — the Coldcard is Bitcoin-only. |
Buying & Funding a Coldcard in Malaysia & Singapore
Coinkite ships Coldcards worldwide from Canada, so Malaysian and Singaporean buyers order direct from the official store (factor in shipping and possible import duty/SST). To avoid tampering, never buy a hardware wallet second-hand or from an unofficial marketplace listing.
You don’t buy the coins on the device — you buy Bitcoin on a regulated exchange, then withdraw it to your Coldcard address. In Malaysia, use a Digital Asset Exchange (DAX) registered with the Securities Commission (SC). As of mid-2026 there are five SC-registered DAX — Luno, HATA, MX Global, SINEGY and Kinetic DAX — operating under the SC’s revised digital-asset framework effective 20 May 2026; most support MYR deposits via DuitNow. Always check a platform against the SC’s current list before depositing.
In Singapore, buy through a MAS-licensed provider such as Coinhako, Independent Reserve, Crypto.com or Coinbase, funding via PayNow/FAST. For a Malaysia-focused walkthrough, see our guide to the best crypto cold wallets to use in Malaysia.
| Malaysia | Singapore | |
|---|---|---|
| Regulator | Securities Commission (SC) | Monetary Authority of Singapore (MAS) |
| Where to buy BTC | Luno, HATA, MX Global, SINEGY, Kinetic DAX | Coinhako, Independent Reserve, Crypto.com, Coinbase |
| Local payment rail | DuitNow | PayNow / FAST |
| Tax treatment | No general CGT; profits may be taxed under LHDN “badges of trade” | No CGT for investors; frequent trading may be taxed as income (IRAS) |
Tax note: neither country levies a broad capital-gains tax on crypto, but active trading can be treated as taxable income — keep records and confirm your position with LHDN or IRAS (or a tax professional).
Common Pitfalls to Avoid
- Assuming a firmware update fixes an old seed. It does not. A weak seed stays weak — you must generate a new one and move your coins.
- Buying a used Coldcard. Pre-owned hardware wallets can be tampered with or pre-seeded. Buy new, from official channels only.
- Skipping the passphrase. A BIP39 passphrase would have shielded owners from the 2026 exploit — and defends against physical theft too.
- Storing your seed phrase digitally. Never photograph or cloud-store your recovery words. Write them down; consider a metal backup.
- Not testing recovery. Verify you can restore from your backup before you transfer meaningful funds.
- Single-device over-reliance. For larger holdings, a multisig across different manufacturers removes any single point of failure.
Conclusion
The Coldcard Mk3 earned its reputation honestly: air-gapped signing, open-source firmware and a serious Bitcoin-only security model made it a favourite among self-custody purists. But 2026 has moved the goalposts. The Mk3 is discontinued, its single-secure-element design has been superseded, and it was the hardest-hit device in the July 2026 entropy exploit that cost holders an estimated US$116 million.
Our recommendation is clear. If you own an Mk3, don’t panic — but do act: update firmware, generate a fresh seed (or move to a current model), and migrate your funds with a test transaction first. If you’re shopping today, skip the Mk3 and choose a new Coldcard Mk4/Mk5 or the Q, both of which carry the stronger dual-secure-element architecture. Cold storage still beats leaving coins on an exchange — but only when the device, its firmware and the way you set it up are all sound.
Frequently Asked Questions
Prices, model availability and firmware details were verified in August 2026 and can change — always confirm current pricing, the latest firmware and security notices directly with Coinkite before you buy or migrate.
Disclaimer: This Coldcard Mk3 review is provided by KayaToday for general information only and is not financial, investment or security advice. Cryptocurrency self-custody carries risk, including the permanent loss of funds. Do your own research and consult a qualified professional before making decisions. KayaToday is not affiliated with Coinkite.
Read also: Best Cold Storage Wallets | Safest Ways to Store Bitcoin
Sources: Coinkite / Coldcard (official), Coinkite security advisory, Securities Commission Malaysia.