Coinkite issued an urgent security advisory on July 31, warning all Coldcard Mk3 users that seeds generated on firmware versions 4.0.1 through 5.0.3 may put their Bitcoin at risk. The alert follows a coordinated sweep of approximately 594.5 BTC (around $38.3 million) from 500 single-signature addresses within Bitcoin blocks 960188 to 960191. While Coinkite has not confirmed a direct link between the theft and the Mk3 vulnerability, multiple blockchain experts suspect weak entropy in seed generation as the root cause.
The drained funds were moved in a rapid three-block window. Security researcher James O'Beirne warned users whose Bitcoin is secured by a single key generated on a Coldcard Mk3 between 2021 and 2023—without dice rolls, passphrases, or multi-signature—to move funds immediately. Clay Garrett of Block’s security team identified an additional set of 695 earlier transactions with the same fingerprint, moving 488.10957948 BTC. If related, the total stolen could reach 1,082.58680432 BTC.
Coinkite stated that the Mk4, Q, and Mk5 models are not affected based on early analysis, though O’Beirne cautioned that Mk2 and Mk4 might also be at risk. Wallets using a BIP-39 passphrase on an affected Mk3 seed face minimal risk, the company added.
For affected users, Coinkite recommends either migrating to a new seed generated on an unaffected Coldcard model, or using a strong, unique BIP-39 passphrase as a temporary measure. Advanced users can create a dice-only seed on an empty Mk3 running firmware 4.1.9 by entering at least 99 independent die rolls. The firm stressed careful migration, advising against rushing the process.
The exact cause of the entropy flaw remains under investigation. Wizardsardine CEO Kevin Loaec hypothesized that low randomness could stem from a software library, secure element, device batch, or firmware version, but no confirmed technical report has been published. The incident echoes past weak-randomness vulnerabilities like Randstorm and Ill Bloom, though Coinkite has yet to disclose whether a similar flaw is responsible. Users are urged to follow the advisory and monitor for further updates as the company continues its review.