Fintech & Crypto Alerts · Quinn Barrett · 31 July 2026

Coldcard issues Mk3 warning amid $38M Bitcoin wallet drain

Coldcard issues Mk3 warning amid $38M Bitcoin wallet drain

Coinkite has warned Coldcard Mk3 users to migrate funds after identifying a potential seed-generation risk on firmware from version 4.0.1 through 5.0.3. The Coldcard issues Mk3 warning arrives as experts separately examine an unexplained sweep of 594.48 BTC worth about $38.3 million, with no proven link so far.

Key Takeaways

Canadian Bitcoin hardware maker Coinkite issued the alert on Thursday, advising users of its Coldcard Mk3 signing device to move funds from wallets whose seed phrases were generated on affected firmware. The issue stretches from version 4.0.1, released in March 2021, through 5.0.3, the final firmware supporting the Mk3.

According to the company's early analysis, the Mk4, Q and Mk5 models are not affected. Coinkite said its investigation is ongoing and promised a formal technical review. Readers following Fintech & Crypto Alerts should treat this as a precautionary migration, not a confirmed exploit attribution.

What did Coinkite tell Coldcard Mk3 users to do?

"Out of an abundance of caution," Coinkite urged affected users to generate a new seed on an unaffected device, verify its backup and receive address, send a small test transaction and only then move the remaining funds.

Coinkite's early analysis also indicates that affected seeds used with a BIP-39 passphrase face minimal risk. The firm stressed that this refers to a passphrase rather than the Coldcard PIN.

Is the $38 million Bitcoin drain linked to the Mk3 issue?

The warning coincides with scrutiny of an unexplained, coordinated sweep involving 594.48 BTC from single-signature addresses. At the time of Cointelegraph's report, that stash was worth about $38.3 million at a Bitcoin price of $64,364.07, per CoinGecko.

A Reddit user said funds were drained from a wallet whose seed was generated on a Coldcard Mk3 bought in May 2021 and later restored onto a Coldcard Mk4 in January 2026. That account is self-reported and does not establish a connection between Coldcard and the broader sweep. No definitive public evidence has established that the Mk3 issue caused those transfers.

In a preliminary analysis, AnchorWatch CEO and co-founder Rob Hamilton said 1,324 unspent transaction outputs were swept across 500 transactions within a three-block window. He said 562 BTC was later consolidated into another address and, at a glance, the pattern looked like flawed entropy in wallet generation somewhere along the way.

Why might some wallets still be at risk?

Wizardsardine CEO Kevin Loaec's current hypothesis is that a low-entropy random-number generator—potentially in a software library, secure element or particular device batch or firmware version—produced wallet seeds with insufficient randomness. He suggested an attacker who knew of the flaw may have used an AI-generated script to brute-force affected wallets, searching only a limited range of BIP-84 derivation paths.

That theory could explain why the sweep appears concentrated in native SegWit addresses and why some wallets were only partially drained, though Loaec stressed it remains unconfirmed. If correct, he warned, wallets that were only partially drained may remain at risk of further theft, and funds in other address types could be exposed if the attacker expands the scan.

← Open in blast feed