Coldcard Warns Mk3 Users of Seed Risk After $38M Sweep
Coinkite warns Coldcard Mk3 users with seeds from firmware 4.0.1 to 5.0.3 to move funds amid a $38M Bitcoin sweep. Experts suspect flawed entropy may have enabled an attacker to drain single-signature wallets, though no definitive link is confirmed.
Quick Take
Coldcard Mk3 firmware 4.0.1 through 5.0.3 may have generated weak seeds, risking funds.
An attacker swept 594.48 BTC ($38M) from single-signature addresses in 500 transactions.
Experts suspect low-entropy RNG produced vulnerable seeds, enabling brute-force thefts.
Affected users urged to migrate funds; further investigation ongoing.
Market Impact Analysis
BearishSecurity warning on a specific hardware wallet could erode user trust and prompt asset movement, potentially exerting short-term selling pressure.
Speculation Analysis
Key Takeaways
- Coldcard Mk3 firmware versions 4.0.1 to 5.0.3 may have produced weak seeds, putting funds at risk of theft.
- An attacker swept 594.48 BTC ($38M) from single-signature addresses in 500 transactions.
- Experts suspect low-entropy RNG produced vulnerable seeds, enabling brute-force attacks.
- Affected users urged to migrate funds immediately; further investigation is ongoing.
- Partially drained wallets remain at risk if the attacker broadens the scan to other address types.
What Happened
Coinkite issued a warning for Coldcard Mk3 users after Bitcoin security experts noticed a large, coordinated sweep of 594.48 BTC from single-signature addresses. The sweep, worth about $38.3 million, occurred across 500 transactions in just three blocks. Coinkite suspects that seeds generated on Mk3 devices running firmware 4.0.1 through 5.0.3 may have been created with insufficient entropy, making them vulnerable to brute-force attacks. While no definitive link has been established, the company is urging affected users to move their funds to new wallets generated on unaffected hardware. The investigation continues.
The Numbers
The sweep moved 594.48 BTC across 500 transactions, consolidating 1,324 UTXOs into a single address holding 562 BTC. The value at the time was roughly $38.3 million. The affected firmware versions cover a period from March 2021 onward. Notably, a Reddit user reported a drain of a wallet whose seed was created on an Mk3 and later restored on an Mk4, suggesting the flaw may persist across device restoration. The sheer speed and scale of the sweep — completed in three blocks — points to an automated attack.
Why It Happened
Preliminary analysis points to flawed entropy in the random-number generator used by the Coldcard Mk3 during seed creation on specific firmware. Experts believe a low-entropy RNG, possibly in a software library or secure element, produced predictable seeds. An attacker who discovered this weakness could have run a brute-force script to derive private keys for addresses following the BIP-84 standard. The sweep’s laser focus on single-signature wallets suggests the attacker knew exactly which derivation paths to target, using AI-generated scripts to automate the theft.
Broader Impact
This incident rattles trust in hardware wallets, reminding users that even dedicated signing devices can harbor critical flaws. While the Mk4 and newer models appear unaffected, the episode highlights the risk of firmware-dependent vulnerabilities. It may accelerate adoption of multisig setups and passphrase protection as additional layers. For the wider market, any sustained uncertainty could prompt short-term selling pressure as users scramble to secure funds.
What to Watch Next
- Coinkite’s formal technical review could reveal whether the flaw was in a specific hardware batch or a broader library vulnerability.
- If the attacker expands the scan to include BIP-44 or BIP-49 addresses, more wallets could be drained.
- Users should monitor their addresses for any unusual activity and migrate funds if they used an affected Mk3 firmware.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.