Coinkite warns Coldcard Mk3 users to transfer funds: 594.5 bitcoins were stolen and seed generation was flawed.
Coinkite issued a security warning reminding Coldcard Mk3 users to transfer funds immediately. Previously, 594.5 bitcoins (BTC) out of 500 addresses were transferred out in batches, and the investigation found that there were security flaws in the seed generation of these addresses.
Key Information
Since version 4.0.1, all Mk3 firmware versions may generate seeds that pose security risks. Users of Mk4, Mk5 and Q series who use older versions of firmware need to immediately update their devices, generate new seeds and transfer funds. Among the reported victims, no use of multi-signature or Taproot wallets was found.
Detailed explanation of Coldcard seed risks
Coinkite pointed out in the security bulletin that since version 4.0.1 released in March 2021, all Mk3 firmware versions have entropy problems, which affects the wallet seeds generated by the device. Seeds generated using Mk4 and Mk5 devices before 5.6.0, and Q-series devices before 1.5.0Q are also at serious risks.
The company said that the affected seeds actually contained only about 72 bits of entropy instead of the expected 128 bits, although the extent of impact varied among models. TAPSIGNER, OPENDIME, and SATSCARD are not affected by this issue because they use separate code libraries. Firmware updates cannot repair existing seeds.
Users should first install the repaired firmware, then generate a new seed, then backup it, verify the collection address on the device, and finally send a micro-test transaction. Mk3 users without other devices can temporarily use the strong and unique BIP-39 mnemonic, but Coinkite still recommends that users migrate to newly generated seeds.
Impact of Bitcoin theft incident
Atlas21 reported that on July 30, an automated operation cleared 500 single-signature addresses in blocks 960188 to 960191. These transactions consumed 1324 UTXOs, transferred 594.5 BTC, valued at approximately US$38 million, and a transaction fee of approximately 0.044 BTC. No multiple signatures or Taproot addresses were found.
The median victim loss was 0.41 BTC, of which 110 addresses were lost more than 1 BTC, and the largest single loss was 29.9 BTC. Atlas21 said transaction patterns indicate flaws in the way these wallets were created when they were created. The first public report came from a user whose 24-word seed was generated on Coldcard in 2021 and was never entered into a computer.
The importance of this incident is that offline storage cannot ensure the safety of funds when the underlying seeds lack enough randomness. Coinkite's warning covers wallets created over the past five years, and if users do not migrate, funds will always be at risk. After the incident, the Bitcoin market price remained around $64000.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC