Coldcard Mk3 Seed Flaw Sparks Urgent Bitcoin Wallet Warning As $38 Million Vanishes
A newly uncovered flaw in one of the crypto industry's best-known hardware wallets has prompted an urgent warning for Bitcoin holders, after researchers spotted a coordinated theft that drained hundreds of wallets within minutes.
While investigators have not confirmed that both incidents are connected, the timing has intensified concerns over the security of affected devices.
Canadian hardware wallet maker Coinkite has advised users who generated Bitcoin seed phrases on certain Coldcard Mk3 firmware versions to move their funds as a precaution.
At the same time, security researchers are investigating the theft of 594.48 BTC, worth around $38.3 million, from approximately 500 single-signature wallets.
Which Coldcard Devices Are Affected
Coinkite said the issue is linked to firmware rather than the hardware itself.
According to the company's advisory, any seed generated on a Coldcard Mk3 running firmware version 4.0.1 through 5.0.3, the final firmware release supporting the Mk3, may be vulnerable because of a flaw affecting the randomness used during seed generation.
The problem stems from insufficient entropy during the creation of wallet seeds, potentially making them more predictable than intended.
The Block's Bitcoin engineering and security team reported that the original Mk1 never ran the faulty code.
Mk2 and Mk3 devices running firmware version 3.2.2 or later generated seeds correctly using a hardware random number generator before the vulnerable firmware series was introduced.
Earlier, Coinkite said its initial analysis showed the newer Coldcard Mk4, Q and Mk5 models were not affected.
However, the company later clarified that these newer devices also generate seeds using only 72 bits of entropy instead of the intended 128 bits, although through a different design.
Even so, the company has not classified those models as vulnerable in the same way as the Mk3.
Coinkite also confirmed that its Tapsigner, Opendime and Satscard products use different codebases and are not affected.
Researchers Investigate $38 Million Bitcoin Sweep
The security warning surfaced as blockchain analysts examined a coordinated movement of Bitcoin from hundreds of wallets over a very short period.
AnchorWatch CEO and co-founder Rob Hamilton said 1,324 unspent transaction outputs were spent across 500 transactions within just three Bitcoin blocks.
Between 01:31 UTC and 01:56 UTC, attackers swept 594.48 BTC, worth about $38.3 million based on CoinGecko pricing at the time, before consolidating 562 BTC into a single address.
Many of the affected wallets had remained inactive for years, with funds dating back to seeds created between 2021 and 2026.
Hamilton wrote,
"At a glance, this looks like there was flawed entropy in wallet generation somewhere along the way."
The total losses could be even higher.
Clay Garrett from The Block's Bitcoin engineering team identified another 695 transactions with similar characteristics that transferred an additional 488.1 BTC.
If those transactions are linked to the same incident, the overall theft could reach approximately 1,082 BTC.
Despite the overlap in timing, Coinkite has not confirmed that the firmware flaw caused the wallet drains.
Could Weak Randomness Be Behind The Theft
The investigation remains open, with several theories being examined.
A Reddit user reported that funds disappeared from a wallet whose seed had originally been generated on a Coldcard Mk3 purchased in May 2021 before later being restored onto a Coldcard Mk4 in January 2026.
The account remains self-reported and does not establish any wider connection to the broader theft.
Wizardsardine CEO Kevin Loaec said his "current hypothesis" is that a low-entropy random number generator, possibly within a software library, secure element, device batch or firmware version, created wallet seeds with insufficient randomness.
He suggested an attacker may have used an AI-generated script to brute-force affected wallets while searching only a limited range of BIP-84 derivation paths.
According to Loaec, that could explain why many of the stolen funds came from native SegWit wallets and why some wallets were only partially emptied.
However, he stressed that the theory remains unverified, and no public technical evidence has identified the exact source of the weakness or demonstrated how the private keys were derived.
How Coinkite Wants Users To Protect Their Funds
Coinkite is urging affected users to migrate their Bitcoin to a newly generated wallet as a precaution rather than waiting for the investigation to conclude.
The company recommends creating a new seed on an unaffected device, verifying both the backup and receiving address, sending a small test transaction first, and only then transferring the remaining balance.
Users are also advised to keep the original backup until every transfer has been successfully confirmed.
For users who already protect their wallets with a separate BIP-39 passphrase, Coinkite said the risk is "minimal," while emphasising that this refers to the optional passphrase and not the Coldcard PIN.
The company added that this protection only applies if the passphrase has never been entered into a computer, smartphone or website.
Users whose Mk3 is their only available device have limited alternatives.
As a temporary measure, Coinkite recommends using a strong, unique BIP-39 passphrase.
Advanced users can also generate a dice-only seed on an empty Mk3 running firmware 4.1.9 by entering at least 99 independent rolls of a fair six-sided die, eliminating reliance on the device's random number generator.
Coinkite said its investigation is ongoing and that a full technical review will be published once its analysis is complete.