
Canadian Bitcoin hardware maker Coinkite has warned users of its Coldcard Mk3 signing device—a popular Bitcoin-only hardware wallet—to move their funds after identifying a potential flaw in how certain firmware versions generated wallet seed phrases.
In a blog post, Coinkite said seeds created on an Mk3 running firmware version 4.0.1, released in March 2021, or any later Mk3 version may put funds at risk. The issue extends through version 5.0.3, the final firmware supporting the Mk3. The Mk4, Q, and Mk5 are not affected, according to the company’s early analysis.
A seed phrase—typically a sequence of 12 or 24 words—is the master key to a Bitcoin wallet. It is generated using a random number generator (RNG) built into the device. If the RNG has a flaw, the seeds it produces may not be as random as they appear, and potentially reproducible by someone who knows about the flaw.
Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk,” said Coinkite.
Affected users are advised to generate a new seed on an unaffected device, verify its backup and receive address, send a small test transaction and only then move the remaining funds. The company said its investigation is ongoing and promised a formal technical review.
COLDCARD Mk3 Security Advisory
If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk.
Mk4, Q and Mk5 are not affected based on our early analysis.
Read the advisory and migrate carefully:https://t.co/3vgPHOjMS7
— COLDCARD (@COLDCARDwallet) July 30, 2026
Coinkite CEO Rodolfo Novak, known online as NVK, said the company is treating the reports with urgency.
“We are all hands on deck doing a deep dive on everything, technical post soon,” Novak said on X.
He added that the company’s communication channels were “bombarded” with inquiries following the reports.
In a separate update, Novak stressed, “We’ve done alot of investigation about the COLDCARD reports, blog post incoming.”
Coinkite said its early analysis indicates that affected seeds used with a BIP-39 passphrase face minimal risk, stressing that this refers to a passphrase rather than the Coldcard PIN. A BIP-39 passphrase is an optional extra word or phrase added on top of a seed, effectively creating a separate hidden wallet that requires both the seed and the passphrase to access.
The advisory is publicly available on Coinkite’s blog.
Experts Examine 594 BTC Sweep
The warning coincides with—though has not been formally linked to —a suspicious coordinated movement of funds that caught the attention of Bitcoin security researchers on Thursday.
The sweep attracted attention after a Reddit user reported that funds had been drained from a wallet whose seed was generated on a Coldcard Mk3 purchased in May 2021. The user said the seed was later restored onto a Coldcard Mk4 in January 2026, meaning it had been entered into a second device. The account is self-reported and does not by itself establish a connection between the Coldcard Mk3 firmware flaw and the broader sweep.
In a preliminary analysis, AnchorWatch CEO and co-founder Rob Hamilton said that 1,324 unspent transaction outputs (UTXOs—individual chunks of bitcoin sitting at specific addresses) were swept across 500 transactions within a three-block window, moving 594.48 BTC worth approximately $38.3 million at current prices, according to CoinGecko.
Hamilton said all addresses involved were single-signature and that 562 BTC was subsequently consolidated into another address that has not moved since.
“At a glance, this looks like there was flawed entropy in wallet generation somewhere along the way,” he wrote.
None of the addresses stolen from were Taproot addresses—Bitcoin’s newest and most privacy-preserving address format.
Many of the wallets had remained inactive for years, with balances typically ranging from 0.15 to 0.26 BTC.
Separately, Wizardsardine CEO Kevin Loaec posted his own hypothesi, suggesting that a low-entropy random number generator—potentially in a software library, secure element, or a particular device batch or firmware version—produced wallet seeds with insufficient randomness. He suggested an attacker who knew of the flaw may have used an AI-generated script to brute-force affected wallets, but searched only a limited range of BIP-84 derivation paths — the standard path used by wallets generating native SegWit addresses, identifiable by the bc1q prefix. BIP-84 defines the standard derivation path for wallets which generate native SegWit addresses.
I’ve conducted some preliminary analysis of the ~600 BTC which have moved in a 15 minute period this morning.
What we know:
– 1,324 UTXOs were swept across 500 transactions all within a 3 block window (594.48 BTC).
– From there, 562 BTC was swept again to a new address which…— Rob Hamilton (@Rob1Ham) July 30, 2026
That could explain why the sweep appears concentrated in native SegWit addresses and why some wallets were only partially drained. Loaec stressed, however, that the theory remains unconfirmed, and warned that if his hypothesis is correct, partially drained wallets may remain at risk — as could funds held in other address types, should the attacker expand their scan.
Open Questions Remain
It is worth noting that, despite the timing, no definitive public evidence has established that the Mk3 firmware flaw caused the transfers. The only first-hand account linking the two is a self-reported Reddit post, and Coinkite has not confirmed any direct connection.
Coinkite has not disclosed whether the flaw has been actively exploited. The company’s advisory explicitly describes its findings as early analysis, and a full technical post-mortem has yet to be published.
There is also an uncomfortable question the company will eventually need to answer directly: when exactly was this flaw identified, and by whom? No public information currently establishes whether Coinkite discovered the vulnerability internally and chose to delay disclosure, or whether it was only surfaced in connection with the sweep on Thursday. Hardware wallet manufacturers occupy a position of extraordinary trust, and users who generated seeds in the intervening five years had no reason to consider themselves at risk. Even if the vulnerability was only recently discovered internally, the timeline will require a thorough and transparent explanation.
For now, Coinkite’s guidance is clear: if a seed was generated on a Coldcard Mk3 running firmware 4.0.1 or later, treat that wallet as potentially compromised and migrate funds as soon as possible. Do not rush the process, and do not skip the test transaction step.
