EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Coldcard Mk3 Security Alert: Experts investigate the theft of $38 million Bitcoin wallet

2026-07-31 12:58:01
Bookmark

Canadian hardware wallet maker Coinkite issues emergency security warning

Canadian hardware wallet maker Coinkite recently issued an emergency security warning to users of its Coldcard Mk3 signature device, advising users to transfer funds from wallets that generate seed phrases using specific affected firmware versions. The company said the risk involves Mk3 firmware versions 4.0.1 (released in March 2021) to 5.0.3-the last firmware version to support Mk3; and based on preliminary analysis, its Mk4, Q and Mk5 models are not affected.

The warning comes as Bitcoin security researchers intensify their investigation into an unusual transfer of 594.48 bitcoins from a single-signature address. Coinkite stressed that there is currently no conclusive public evidence that the Mk3 seed generation problem is directly related to the incident, but the company still requires users to take action "out of a high degree of caution."

Core Points

Coinkite warns Coldcard Mk3 users to divert funds from wallets that generate seeds using affected firmware versions 4.0.1 to 5.0.3. Based on Coinkite's preliminary findings, the issue does not appear to affect newer hardware models (Mk4, Q, Mk5). Coinkite's recommendations focus on safer recovery operations: generate new seeds on unaffected devices, verify backup and receiving addresses, and conduct microtest transactions first. Security analysts are investigating the transfer of 594.48 bitcoins from single-signature addresses, but there is currently no public evidence linking them directly to Mk3 firmware issues. Coinkite said that in its preliminary assessment, seeds protected using the BIP-39 passphrase (as opposed to Coldcard PIN) faced extremely low risks.

Coinkite's Mk3 seed generation warning

Coinkite stated on its official blog that seeds created on Mk3 running firmware version 4.0.1 or later (up to 5.0.3) could put funds at risk. The company's preliminary analysis did not find the same problem with Coldcard Mk4, Q or Mk5 devices. The company's suggestions are practical and phased. Coinkite urges affected users to generate new seeds on unaffected devices, confirm that the backup is correct, and ensure that the correct receiving address is used. Users should send a small test transaction first and then transfer the remaining balance. Coinkite also sought to clarify a common point of confusion in hardware wallet security discussions: In its evaluation, the "BIP-39 passphrase" was a relevant protection mechanism and should not be confused with Coldcard PIN.

Risks from firmware version to actual user

The importance of Coinkite's warning lies in the deterministic way Bitcoin wallets derive addresses from seed phrases. If seed generation is flawed in reducing randomness-or introduces patterns that attackers can exploit-then previously used addresses may become easier to guess. Hardware wallets are designed to make theft more difficult, because seeds should be unpredictable, so any flaws that affect entropy can have knock-on consequences. Although the company did not provide technical details in the warning summary, it clarified the scope of what users need to check: Not all Coldcard Mk3 seeds are automatically suspicious, and only those created within the specified firmware version range require attention. For users who cannot determine the exact firmware version used when the seed was generated, Coinkite's steps suggest a conservative approach: treat the wallet as potentially exposed and transfer funds accordingly. This "caution first" attitude is particularly important in the broader environment. Hardware wallet security incidents-even if the evidence remains circumstantial-often trigger defensive behavior by users and threat researchers, because stolen seeds can sometimes lead to repeated attacks attempts rather than a single breach.

Safety researchers associate context, not causality

Attention began to rise after a Reddit user described his wallet being emptied of funds (allegedly involving a Coldcard Mk3 purchased in May 2021). According to the user's description, the seed was later restored to the Coldcard Mk4 in January 2026, which meant it was subsequently entered into a second device. However, this information is self-reported by users and does not in itself establish a direct link between Coldcard hardware and the wider range of suspicious transactions. Separately, AnchorWatch CEO and co-founder Rob Hamilton released a preliminary analysis claiming that during the window period of three blocks, 594.48 bitcoins were transferred through 500 transactions. In this analysis, Hamilton pointed out that a total of 1,324 unspent transaction outputs were involved, and that these addresses appeared to be single-signed addresses. He also said that approximately 562 bitcoins were later merged into another address. Hamilton believes the pattern "looks like there was an entropy defect somewhere when the wallet was generated" and describes the event as consistent with a problem of randomness, but this is still an explanation rather than evidence. As of the time of report, according to CoinGecko data, based on a bitcoin price of US$64,364.07, 594.48 bitcoins were worth approximately US$38.3 million.

Another researcher, Kevin Loaec, CEO of Wizardsardine, proposed a hypothesis that focused on how low-entropy seeds might be produced. In his view, a low-quality random number generator-which could come from software components, secure element behavior, device batches or specific firmware-could lead to insufficient randomness in the wallet. Loaec said an attacker with knowledge of the vulnerability could use AI-generated scripts to brute force affected wallets while limiting the search to a narrow set of BIP-84 derived paths. This could explain why money transfers seem to be concentrated on native SegWit addresses, and why some wallets may only be partially emptied. He emphasized that this theory had not been confirmed and that further scanning could reveal more affected assets. The key tension between these analyses is the difference between "consistent with the vulnerability" and "proven to be caused by that particular device." Coinkite's warnings fall into the former-credible internal assessments suggest that certain Mk3 firmware versions may put users at risk-while external money transfer investigations remain a broader pattern that researchers are still trying to attribute.

What should affected users pay attention to next

If Coinkite's risk assessment is accurate, the most important variables for users are whether its seed phrase originates from the affected firmware version range and whether it is protected using a BIP-39 passphrase. The company's initial statement that BIP-39 passphrase seeds face "extremely low risk" provides some comfort, but does not eliminate the need for verification and secure migration. Looking ahead, readers should focus on the formal technical review Coinkite promises, as well as further independent analysis that may strengthen or weaken the suspicious connection between Mk3 seed generation issues and the transfer of 594.48 bitcoin funds. Until the situation becomes clear, the cautious conclusion remains unchanged: treat potentially affected wallets as exposed and use newly generated seed material on unaffected hardware to transfer funds.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP