Coldcard Mk3 vulnerability alert issued amid investigation of $38M Bitcoin theft

Coldcard Mk3 vulnerability alert issued amid investigation of $38M Bitcoin theft

Following the discovery of a seed-generation vulnerability, Coinkite has advised Coldcard Mk3 owners to transfer their cryptocurrency holdings, while security researchers investigate a separate $38 million Bitcoin wallet compromise.

Coinkite, a Canadian manufacturer of Bitcoin hardware wallets, has issued an advisory to owners of its Coldcard Mk3 signing device, recommending they transfer cryptocurrency from wallets whose seed phrases were created on firmware versions that may be compromised.

The company announced on Thursday that seed phrases generated on Mk3 devices running firmware version 4.0.1, which was released in March 2021, or any subsequent Mk3 firmware release could potentially expose funds to security risks. According to Coinkite's preliminary investigation, the vulnerability affects versions through 5.0.3, which represents the last firmware update supporting the Mk3 model, though the Mk4, Q and Mk5 models remain unaffected.

This advisory coincides with ongoing analysis by Bitcoin security professionals into a coordinated, unexplained transfer of 594.48 BTC from single-signature wallet addresses. That said, no conclusive public proof has been presented linking the Mk3 vulnerability to these particular fund transfers.

"Out of an abundance of caution," Coinkite recommended that users who may be affected should create a fresh seed on a device not impacted by the issue, confirm both its backup and receive address, conduct a small test transaction and only after that transfer the bulk of their holdings. The manufacturer stated that its investigation continues and pledged to release a formal technical assessment.

According to Coinkite's preliminary findings, affected seeds that were used in combination with a BIP-39 passphrase present minimal risk exposure, noting that this specifically refers to a passphrase and not the Coldcard PIN code.

Experts examine 594 BTC sweep

The suspicious transfer gained widespread attention following a Reddit post from a user claiming that cryptocurrency had been removed from a wallet whose seed had been created on a Coldcard Mk3 device purchased in May 2021.

According to the user's account, the seed was subsequently restored onto a Coldcard Mk4 device in January 2026, indicating that the seed phrase had been inputted into a secondary device at that time. This report is self-described and has not demonstrated any definitive link between Coldcard hardware and the larger-scale transfer event.

Rob Hamilton, CEO and co-founder of AnchorWatch, shared a preliminary examination on Friday indicating that 1,324 unspent transaction outputs were transferred in 500 separate transactions occurring within a span of just three blocks, totaling 594.48 BTC.

Based on current valuations, the 594.48 BTC represented approximately $38.3 million in value at the time of writing, calculated using a Bitcoin price of $64,364.07, per CoinGecko data.

Hamilton noted that every address involved utilized single-signature configurations and that 562 BTC was subsequently combined into a single address. "At a glance, this looks like there was flawed entropy in wallet generation somewhere along the way," he stated.

In a separate analysis, Kevin Loaec, CEO of Wizardsardine, indicated that his working hypothesis points to a low-entropy random-number generator, which could potentially exist within a software library, secure element chip, or specific device batch or firmware release, resulting in wallet seeds with inadequate randomness.

Loaec proposed that an attacker with knowledge of this weakness might have employed an AI-generated script to brute-force vulnerable wallets, though limiting their search to a restricted set of BIP-84 derivation paths. This scenario could account for why the transfer activity appears focused on native SegWit addresses and why certain wallets were only partially emptied, although Loaec emphasized that this explanation has not been verified.

Loaec cautioned that, should his hypothesis prove accurate, wallets that experienced only partial draining could continue to face the threat of additional theft. He further noted that cryptocurrency stored in alternative address formats might also be vulnerable should the attacker broaden their scanning parameters to encompass them.

← Zurück zum Blog