Coinkite Urges Coldcard Mk3 Users to Move Funds After $38M Bitcoin Theft

2 hour ago 5 sources negative

Key takeaways:

  • The theft of 594.5 BTC may trigger short-term sell pressure if hackers liquidate on exchanges, potentially weighing on Bitcoin's price.
  • This incident could erode trust in single-sig hardware wallets, accelerating a structural shift toward multi-signature custody solutions.
  • Monitoring stolen-fund addresses for exchange deposits offers a leading indicator of selling intent and market impact.

Coinkite issued an urgent security advisory on July 31, warning all Coldcard Mk3 users that seeds generated on firmware versions 4.0.1 through 5.0.3 may put their Bitcoin at risk. The alert follows a coordinated sweep of approximately 594.5 BTC (around $38.3 million) from 500 single-signature addresses within Bitcoin blocks 960188 to 960191. While Coinkite has not confirmed a direct link between the theft and the Mk3 vulnerability, multiple blockchain experts suspect weak entropy in seed generation as the root cause.

The drained funds were moved in a rapid three-block window. Security researcher James O'Beirne warned users whose Bitcoin is secured by a single key generated on a Coldcard Mk3 between 2021 and 2023—without dice rolls, passphrases, or multi-signature—to move funds immediately. Clay Garrett of Block’s security team identified an additional set of 695 earlier transactions with the same fingerprint, moving 488.10957948 BTC. If related, the total stolen could reach 1,082.58680432 BTC.

Coinkite stated that the Mk4, Q, and Mk5 models are not affected based on early analysis, though O’Beirne cautioned that Mk2 and Mk4 might also be at risk. Wallets using a BIP-39 passphrase on an affected Mk3 seed face minimal risk, the company added.

For affected users, Coinkite recommends either migrating to a new seed generated on an unaffected Coldcard model, or using a strong, unique BIP-39 passphrase as a temporary measure. Advanced users can create a dice-only seed on an empty Mk3 running firmware 4.1.9 by entering at least 99 independent die rolls. The firm stressed careful migration, advising against rushing the process.

The exact cause of the entropy flaw remains under investigation. Wizardsardine CEO Kevin Loaec hypothesized that low randomness could stem from a software library, secure element, device batch, or firmware version, but no confirmed technical report has been published. The incident echoes past weak-randomness vulnerabilities like Randstorm and Ill Bloom, though Coinkite has yet to disclose whether a similar flaw is responsible. Users are urged to follow the advisory and monitor for further updates as the company continues its review.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.