Hardware wallet manufacturer Coinkite has issued an urgent security advisory for users of its Coldcard Mk3 device after reports emerged that approximately 594.5 Bitcoin, worth around $38 million, was stolen from hundreds of wallets in what appears to be a coordinated attack.
The company warned that users who generated wallet seeds on a Coldcard Mk3 running firmware version 4.0.1, released in March 2021, or any later Mk3 firmware may have funds at risk. The advisory covers firmware through version 5.0.3, the final release supporting the Mk3 model, although Coinkite stressed that its investigation remains ongoing. The warning followed blockchain analysis showing approximately 594.5 BTC being swept from around 500 single-signature Bitcoin addresses in a tightly coordinated series of transactions spanning Bitcoin blocks 960188 to 960191. Security researchers believe the theft may be linked to weak entropy during seed generation, although Coinkite has not confirmed that the firmware issue was the direct cause of the attack.
Importantly, Coinkite said its preliminary analysis indicates that the newer Coldcard Mk4, Mk5 and Coldcard Q models are not affected. The company also stated that wallets protected with a BIP-39 passphrase appear to face minimal exposure even if the underlying seed was generated on an affected Mk3 device.
Precautionary Advisory Amid Ongoing Investigation
Coinkite emphasized that the advisory is precautionary and should not be interpreted as confirmation that every wallet involved in the 594 BTC theft was compromised through the same vulnerability. Blockchain investigators observed the stolen funds being consolidated into addresses controlled by the attacker shortly after the coordinated sweep. Additional on-chain analysis has suggested that the total amount potentially linked to similar transactions could exceed 1,000 BTC if earlier suspicious transfers are ultimately connected to the same incident, although that broader figure has not been confirmed.
Bitcoin developer James O’Beirne advised users whose funds are secured by a single key generated on a Coldcard Mk3 between 2021 and 2023—without a BIP-39 passphrase, dice-generated entropy or multisignature protection—to move their funds immediately. Researchers believe the incident may involve insufficient randomness during wallet creation, dramatically reducing the search space available to an attacker. Coinkite has not yet released a full technical explanation of the issue and said its forensic investigation remains in progress.
Users Urged to Migrate Funds
As an immediate mitigation, Coinkite recommends that affected users create a strong, unique BIP-39 passphrase on their existing wallet before transferring funds to a newly derived address. As a longer-term solution, the company advises generating an entirely new seed on an unaffected Coldcard model and migrating Bitcoin after verifying the destination wallet through a small test transaction. For experienced users who must continue using a Mk3, Coinkite also described an advanced recovery method using at least 99 rolls of a physical six-sided die to generate entropy independently of the device’s random-number generator.
The incident highlights the critical importance of secure seed generation in self-custody. Hardware wallets are widely regarded as one of the safest methods of storing digital assets because private keys never leave the device. However, if the original seed is generated with insufficient entropy, every subsequent security measure can be undermined. Although the precise cause of the 594 BTC theft has yet to be conclusively established, the advisory has prompted one of the most significant hardware wallet security responses in recent years. Until Coinkite completes its investigation, affected Mk3 users are being urged to assume their wallets may be vulnerable and migrate funds as a precaution.
