NewsCryptoCoinkite Issues Security Advisory for Coldcard Mk3 After Reports of $38M in Bitcoin Transfers

Coinkite Issues Security Advisory for Coldcard Mk3 After Reports of $38M in Bitcoin Transfers

Author: CryptoNewsNet·

Key Takeaways

  • Approximately 594 BTC valued at $38 million moved from around 500 dormant single-signature Bitcoin addresses within 25 minutes on July 30, 2026, suggesting a coordinated exploit rather than independent owner activity.
  • Coinkite's advisory is limited to Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3, with the company's early analysis indicating that Mk4, Q, and Mk5 models are not affected.
  • Community researchers have focused on possible weak randomness in seed generation on older Mk2 and Mk3 firmware as the likely vulnerability, though Coinkite has not confirmed a root cause.
  • Wallets protected with a BIP-39 passphrase appear to carry minimal risk, while Mk3 owners without a passphrase are advised to migrate to a new seed generated on an unaffected device.
  • Coinkite CEO Rodolfo Novak confirmed the company is conducting a thorough investigation and will publish a formal technical review as findings develop.
Coinkite Issues Security Advisory for Coldcard Mk3 After Reports of $38M in Bitcoin Transfers

Coinkite Issues Security Advisory for Coldcard Mk3 After Reports of $38M in Bitcoin Transfers

On July 30, 2026, approximately 594 BTC — valued at roughly $38 million — moved from around 500 single-signature addresses within a window of about 25 minutes. Many of those wallets had sat dormant for years, with individual balances typically ranging between 0.15 and 0.26 BTC. The coordinated movement drew immediate attention from the Bitcoin community, as the systematic sweep of long-inactive wallets in a narrow time frame is a pattern often associated with an attacker exploiting a shared vulnerability rather than independent owners acting simultaneously.

Coinkite has not yet confirmed whether the transfer of nearly 600 BTC is directly connected to the security advisory it issued for its Coldcard Mk3 hardware wallet. However, the timing and scale of the activity prompted the company to act.

Coinkite's Response

Coinkite CEO Rodolfo Novak, widely known in the industry as NVK, said the company is devoting significant resources to the investigation. "We are all hands on deck doing a deep dive on everything, technical post soon," Novak said on X. He noted that the company's communication channels had been "bombarded" with inquiries following the reports.

In a separate update, Novak stated: "We've done alot of investigation about the COLDCARD reports, blog post incoming."

Affected Devices

According to the security advisory published on the company's blog, the potentially affected devices are specifically limited to the Mk3 model. Anyone who generated a seed phrase on a Mk3 running firmware version 4.0.1 — released in March 2021 — through version 5.0.3, which was the final release supporting the Mk3, may be affected.

Coinkite stated that its early analysis indicates the Mk4, Q, and Mk5 models are not affected.

The company described the advisory as reflecting preliminary findings and said a formal technical review will be published as the investigation progresses. Community researchers have been independently reviewing on-chain activity linked to the incident. Discussion has largely focused on the possibility of weak randomness in seed generation on certain older Mk2 and Mk3 firmware versions, rather than a supply chain compromise. The integrity of a hardware wallet's random number generator is foundational to its security purpose: if seed entropy is predictable or duplicated, an attacker could reconstruct private keys without physical access to the device. As of publication, Coinkite has not confirmed a root cause.

Risk Assessment for Passphrase Users

Wallets protected with a BIP-39 passphrase — a user-added phrase distinct from the device PIN — appear to carry minimal risk based on Coinkite's early analysis. A BIP-39 passphrase functions as an additional entropy layer layered on top of the seed phrase, creating a separate wallet that an attacker cannot derive from the seed alone. The company advised passphrase users to continue safeguarding that phrase and to avoid entering it on untrusted devices or websites.

For Mk3 owners who did not use a passphrase, Coinkite recommended migrating to a new seed generated on an unaffected device. The company cautioned against rushing the process. Specifically, it advised sending a small test transaction first, verifying the new wallet and receive address directly on the device screen, and retaining the old backup until the migration is fully confirmed.

Interim Steps for Mk3-Only Owners

For users whose Mk3 is their only hardware device, Coinkite outlined two interim options:

  • Add a strong, unique BIP-39 passphrase and transfer funds to the newly protected wallet.
  • Generate a replacement seed using the Mk3's dice-roll import path, which bypasses the device's random number generator. Coinkite noted that this is an advanced procedure requiring careful verification.

Full technical steps are available in the advisory on the company's blog. Coinkite said its investigation is ongoing and that additional details will be released.

Coldcard has established itself as a security-focused, air-gapped hardware wallet since its release, and the reports have generated significant attention across the Bitcoin community as device owners evaluate their own security setups. The incident underscores a broader consideration in self-custody: the security of a hardware wallet depends not only on its physical design but also on the correctness of its firmware across every version a device has ever run.