NewsCryptoCoinkite Warns Coldcard Mk3 Users After 594 BTC Swept From 500 Addresses

Coinkite Warns Coldcard Mk3 Users After 594 BTC Swept From 500 Addresses

Author: Coindoo·

Key Takeaways

  • Coinkite warned that seeds generated directly on a Coldcard Mk3 running firmware 4.0.1 (March 2021) through version 5.0.3 may be vulnerable to a potential low-entropy random-number generator flaw.
  • Approximately 594.48 BTC was moved from roughly 500 single-signature addresses within a three-block window on July 30, 2026, though Coinkite has not confirmed any link between the sweep and the disclosed vulnerability.
  • Firmware updates alone cannot remediate the issue because the weakness affects seeds already created, meaning the permanent fix requires generating an entirely new seed on an unaffected device.
  • Coldcard Mk4, Q, and Mk5 models are unaffected based on current analysis, and users with only an Mk3 can apply interim measures such as a BIP-39 passphrase or dice-based seed generation while awaiting a full migration.
  • Seeds created outside the Mk3 and later imported into the device are not affected, since they never used the Mk3 random-number generator during creation.
Coinkite Warns Coldcard Mk3 Users After 594 BTC Swept From 500 Addresses

Coinkite, the manufacturer behind the Coldcard hardware wallet line, issued a security advisory on July 30, 2026, warning that seed phrases generated on a Coldcard Mk3 running firmware 4.0.1 (released March 2021) or any later version may be vulnerable. The flaw persists through version 5.0.3, the final firmware release supporting the Mk3 model. Coldcard has been a prominent name among Bitcoin-only hardware wallet manufacturers, and the advisory reaches a user base that specifically chose the device for its air-gapped design and self-custody focus.

The advisory follows a suspicious on-chain event in which approximately 594.48 BTC moved out of roughly 500 single-signature addresses within a narrow three-block window. Coinkite has not confirmed any link between the sweep and the disclosed vulnerability.

The Friday Morning Sweep

Between approximately 01:31 and 01:56 UTC, 594.48 BTC was moved from about 500 single-signature addresses. Rob Hamilton, chief executive of AnchorWatch, conducted a preliminary on-chain analysis following initial reporting by Atlas 21. Hamilton identified 1,324 unspent transaction outputs (UTXOs) swept across 500 transactions within blocks 960188 through 960191. Approximately 562 BTC was subsequently consolidated into a single address.

At a Bitcoin price near $64,300, the total value moved amounted to approximately $38.3 million.

Hamilton's initial assessment suggested that wallet generation had suffered an entropy flaw at some stage. Kevin Loaec of Wizardsardine, one of the first to raise public alarm, pointed to a possible low-entropy random-number generator, potentially within a software library. Entropy—the unpredictability that determines how hard a seed is to guess—is the foundation of every cryptocurrency wallet's security. When entropy is insufficient, the space of possible seeds an attacker must search shrinks from astronomically large to potentially tractable.

Two factors pointed toward a seed-generation issue rather than a compromise at any single exchange or service. First, every drained address was single-signature. Second, many of the addresses had been dormant for years, with coins dating from 2021 through 2026—a timeline that closely corresponds to the age of the affected firmware versions.

Coinkite has not confirmed any connection between the sweep and its advisory. No definitive public evidence has established such a link.

Scope of the Vulnerability

The advisory specifically targets seeds that were generated on an affected Mk3 device, not every wallet the device has interacted with. Three conditions must be met for a seed to be considered at risk:

  1. The seed words were created directly on the Coldcard Mk3.
  2. The device was running firmware 4.0.1 (March 2021) or later at the time of seed creation.
  3. That seed still controls Bitcoin or wallets derived from it.

The second condition presents a practical challenge for users. A Coldcard reports the firmware version currently installed, not the version that was running when a wallet was originally created. What matters is the firmware version active at the moment of seed generation—a detail unrelated to the hardware purchase date.

Users who generated a seed before March 2021 and never regenerated it afterward fall outside the affected range. Anyone who set up a wallet after that date, or who cannot reconstruct the firmware history of their device, should assume they are within scope until Coinkite's formal review narrows the parameters.

A seed generated elsewhere and subsequently imported into the Mk3 never used the device's random-number generator and is therefore unaffected by this specific flaw. Coinkite confirmed that the Mk4, Q, and Mk5 models are unaffected based on current analysis and recommended using one of these newer devices to generate a replacement seed.

Coinkite described the notice as early analysis, with a formal technical review to follow. The company has not published an explanation of the entropy failure mechanism, a count of affected devices, or a figure for funds potentially lost. Random-number generation flaws have surfaced in other cryptocurrency projects over the years, including instances where weak RNG allowed private keys to be reconstructed, which is why seed-entropy auditing remains an active area of security research.

Why Updating Firmware Alone Does Not Help

Installing new firmware addresses how future seeds are created but has no effect on seed phrases that already exist. A seed serves as the source from which every private key and address in a wallet is derived. If the randomness behind that seed was weaker than intended, an attacker could search a substantially smaller range of possible seeds until finding ones that control funded addresses. The recovery words appear random to their owner regardless, because the weakness lies in the device's selection process rather than in the appearance of the finished phrase.

A case reported on Reddit illustrated this dynamic. A user described funds drained from a wallet whose seed was originally generated on an Mk3 purchased in May 2021, then restored onto an Mk4 in January 2026. The newer, unaffected device inherited the original seed words—and with them, the original vulnerability. This account is self-reported and does not establish anything about the broader sweep, though the mechanism it describes matches what Coinkite's advisory addresses.

The permanent remedy is a seed that was never generated by an affected device.

Migration With a Second Device

Coinkite emphasized proceeding calmly, noting that a rushed migration can create more immediate risk than the vulnerability itself. Before any migration, an affected user should first verify that their funds are still present. An already-emptied wallet requires incident response rather than a careful transfer.

For users with access to a second, unaffected device, Coinkite recommended the following steps:

  1. Generate a new seed on an unaffected Coldcard (Mk4, Q, or Mk5).
  2. Record and verify the backup before depositing anything.
  3. Verify a receive address on the device's own screen.
  4. Send a small test transaction and confirm the new wallet functions correctly.
  5. Move the remaining funds only after all checks pass.
  6. Retain the old backup until the migration is complete and confirmed.

Interim Measures for Mk3-Only Users

For users whose only device is an affected Mk3, Coinkite offered two interim routes—neither treated as a complete fix.

Option 1: BIP-39 Passphrase

The first approach involves applying a BIP-39 passphrase—a separate secret added to the recovery words, distinct from the Coldcard PIN. The PIN protects device access but leaves underlying keys untouched, offering no protection in this scenario. The BIP-39 passphrase, sometimes called the "25th word," is an optional layer standardized across most hardware and software wallets that support the BIP-39 recovery format.

Users should read the official passphrase instructions first, then select Passphrase on the Mk3 and enter a phrase that is long, random, and unique. It should never be a quotation, a name, a familiar phrase, or a reused password, and it should never be typed into a computer, phone, or website. The passphrase must be backed up exactly and stored separately from the seed words, because losing it means losing access to the funds.

After entering the passphrase, select APPLY and record the new wallet's eight-digit fingerprint. Power the device off and back on, re-enter the passphrase, and confirm that the same fingerprint appears. Export the passphrase-protected wallet to a coordinator software, verify its receive address on the Mk3 screen, then power-cycle and sign in without the passphrase to access the original wallet. Send a small test transaction, re-enter the passphrase, confirm the test arrived, and only then move the remainder.

Every passphrase produces a valid wallet, including one containing a typo. Verifying the fingerprint before each send is what catches such errors.

Option 2: Dice-Based Seed Generation

The second route bypasses the device's random-number generator entirely. On an empty Mk3 running firmware 4.1.9, selecting Import Existing > Dice Rolls and entering at least 99 independent rolls of a fair six-sided die creates a seed by hashing the roll sequence directly. Coinkite specified that the ordinary New Wallet flow does not perform this operation—it must be the dice path.

This is an advanced procedure, labeled as such by Coinkite. The dice-roll documentation covers the method in full.

When running both seeds on a single device, users should alternate between them carefully: verify each written backup and fingerprint before erasing anything, verify a receive address for the dice wallet, restore and verify the original wallet, and send a test transaction before moving the balance.

The roll sequence itself is key material. It should never be photographed, saved digitally, or entered into a networked computer.

A Passphrase Buys Time, Not Permanent Safety

Coinkite's early analysis placed funds secured behind a strong BIP-39 passphrase at minimal risk from this issue, because the passphrase derives a separate wallet from both the original seed and the added secret. Automated searching for wallets built directly from a weakened base seed would not reach passphrase-protected wallets.

This aligns with what the Friday sweep demonstrated: every drained address was single-signature, each holding more than 0.15 BTC.

The underlying entropy flaw remains regardless of passphrase use. Those recovery words are still weaker than intended, and everything depends on the strength and secrecy of one added phrase. The permanent fix remains a new seed generated on an unaffected device.

Broader Considerations for Hardware Wallet Users

Coinkite's investigation is ongoing, and the scope may shift when the formal technical review is published. The company urged owners to follow its official updates rather than screenshots, forwarded messages, or any third-party service claiming to test whether a seed phrase is vulnerable.

This last point carries particular weight. A warning at this scale tends to attract phishing campaigns targeting exactly the users most likely to act quickly. No legitimate tool asks for seed words, and no support form, website, or recovery service should ever receive them. The broader hardware wallet ecosystem—including Ledger, Trezor, BitBox, and others—consistently reinforces the same principle: seed phrases must never be entered into any internet-connected device, a rule that applies regardless of which manufacturer issued the wallet.

The lesson is narrower than a blanket conclusion that hardware wallets have failed. An offline device keeps private keys away from malware, which it did in this case. What it cannot do is protect a seed that was already predictable at the moment of creation—and key generation is where the entire security model begins. For users evaluating whether their own setup is at risk, the practical question is not which device currently holds the seed but where and when that seed was first created.

Disclaimer: This article is for informational and security-awareness purposes only. Follow Coinkite's official instructions and never disclose seed words, private keys, wallet backups, or BIP-39 passphrases to anyone.

Methodology: Firmware versions, affected models, migration steps, the passphrase procedure, and the dice-only alternative are drawn from Coinkite's July 30, 2026 security advisory and its linked documentation. Sweep figures are drawn from AnchorWatch chief executive Rob Hamilton's preliminary on-chain analysis, following reporting by Atlas 21. Coinkite has not confirmed a link between the sweep and the seed-generation issue.