Coldcard warns Mk3 users after $38M Bitcoin sweep
Coinkite warned Coldcard Mk3 users that seeds generated on firmware 4.0.1–5.0.3 may be vulnerable and urged affected users to move funds as experts probe a 594.48 BTC sweep.
Coinkite, the maker of the Coldcard hardware wallet, warned owners that seed phrases created on Mk3 devices running firmware version 4.0.1 (released March 2021) through 5.0.3 may put funds at risk. The company said newer models Mk4, Q and Mk5 are not affected and that its investigation is ongoing.
The firm advised users with affected seeds to generate a new seed on an unaffected device, verify the backup and receive address, send a small test transaction and only then transfer remaining funds. Coinkite’s early analysis indicates seeds protected with a BIP-39 passphrase face minimal risk and clarified that the passphrase is separate from the Coldcard PIN. The company pledged a formal technical review as it continues probing the issue.
Security researchers mapped a coordinated sweep of 594.48 BTC, equal to about $38.3 million at the time of reporting. AnchorWatch’s preliminary analysis found 1,324 unspent transaction outputs moved across 500 transactions within a three-block window. The firm reported that all affected addresses were single-signature wallets and that 562 BTC was later consolidated into another address.
“At a glance, this looks like there was flawed entropy in wallet generation somewhere along the way,” AnchorWatch’s CEO Rob Hamilton wrote in his initial post about the activity.
Outside specialists are examining multiple possible causes. Kevin Loaec, CEO of Wizardsardine, proposed that a low-entropy random-number generator used during seed creation could be responsible. He suggested the weakness might originate in a software library, a secure element, a specific device batch or a particular firmware version.
Loaec outlined a scenario in which an attacker who discovered the flaw ran an automated script focused on a limited set of BIP-84 derivation paths, which produce native SegWit addresses. That approach could explain why the sweep appears concentrated in native SegWit addresses and why some wallets were only partially drained. He cautioned that the theory remains unconfirmed.
A self-reported account on a public forum described funds taken from a wallet whose seed was generated on an Mk3 bought in May 2021 and later restored onto an Mk4 in January 2026. Coinkite and outside analysts note that a single report does not establish a definitive link between the Mk3 firmware and the larger sweep.
Researchers warned that wallets only partially drained could still be at risk if an attacker expands searches to other derivation paths or address types. Blockchain analysis and device-level examinations are continuing to determine whether flawed entropy during seed generation is the cause and to identify the exact scope of affected wallets.
Coinkite reiterated its guidance for affected users and asked customers to follow the recommended verification and transfer steps while the company and independent researchers complete their investigations.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








