By BitBrainers Editorial
What Happened
The attack targeted single-signature wallets whose seeds were generated on Coldcard Mk3 hardware running firmware version 4.0.1 or later. That firmware, released in March 2021, contained a flaw in how the device generated randomness for seed creation. Instead of drawing from the hardware random number generator, affected devices fell back to software-based key generation seeded by predictable, non-secret chip data.
A seed generated from predictable inputs is not truly random. If someone can reconstruct the inputs, they can reconstruct the private key. Every wallet created on a compromised Mk3 since March 2021 was potentially sitting on a key an attacker could calculate without ever touching the device.
The attacker swept funds into four consolidation addresses, where they have not moved: 562.02 BTC, 398.48 BTC, 89.62 BTC, and 32.45 BTC. The sweep covered 1,196 addresses in a 41-minute window across nine blocks, with every transaction paying an identical hardcoded fee of 30 sat/vB — a significant overpay versus the 0.4–1.0 sat/vB median that week and leaving no change output. That pattern points to an automated tool spending keys it already held, not owners moving their own funds. All victims were single-signature wallets holding more than 0.15 BTC, many dormant for years.
Who Is Affected
Coinkite, the Canadian company behind Coldcard, issued a security advisory Thursday night warning Mk3 users that seeds generated on firmware 4.0.1 through 5.0.3 may be at risk. That covers the entire Mk3 firmware lifecycle from March 2021 through its final supported version.
The Mk4, Q, and Mk5 are in a different position. Coinkite's early analysis described them as unaffected, but independent analysis by Bitcoin Core developer Gregory Maxwell reached a different conclusion: the same class of entropy weakness is present on these devices, approximately 32 bits harder to exploit than on the Mk3. That is not the same as safe. If you hold significant funds on any Coldcard device and your seed was generated by the device without dice rolls or a strong BIP-39 passphrase, treat it as a risk and migrate. Do not wait for a definitive statement from Coinkite.
If you hold Bitcoin on a Coldcard Mk3 without a BIP-39 passphrase and your seed was generated after March 2021, treat that wallet as compromised. Move funds now, not after you finish reading.
The Lesson That Never Gets Old Enough
Hardware wallets fail. Not often, and not usually like this, but the history is long enough that "cold storage is safe" should always have a footnote. Ledger's 2020 customer data breach exposed 270,000 users to physical threats. Trezor disclosed a laser fault-injection vulnerability in 2026 affecting its TROPIC01 chip. Coldcard's randomness flaw went unnoticed for five years across hundreds of devices.
None of this means hardware wallets are not worth using. The alternative, leaving coins on an exchange, hands custody to a third party that can freeze withdrawals, go bankrupt, or get hacked on a scale that dwarfs any single hardware flaw. The point is that hardware wallets are the best available option, not a perfect one.
The specific flaw here, weak randomness in seed generation, is the kind of vulnerability that is invisible until it is not. The seed looks correct. The wallet functions normally. Coins arrive and leave without issue. The weakness is structural, baked in at the moment of creation, and impossible to detect by looking at the device or the wallet itself.
Self-custody is not set and forget.
We cover the security stories most feeds miss until they become headlines. Weekly, free.
SubscribeWhat to Do Right Now
Before doing anything, confirm you are actually affected. You are at high risk only if all four of these are true: your seed was generated on a Coldcard Mk3 running firmware 4.0.1 or later, you did not use a strong BIP-39 passphrase, you did not use dice rolls for extra entropy, and it is a single-signature wallet. If you used a strong unique passphrase or dice rolls at seed generation, Coinkite and the majority of security researchers consider your risk minimal.
Step 1: Stay calm. Urgent but not reckless.
Every experienced voice in the security community is repeating the same thing. Panic transactions and rushed moves lose more coins than the exploit itself. Do not act under stress. Do not send everything in one big transaction. Do not respond to anyone in your DMs offering help.
Step 2: Never enter your existing seed anywhere.
Do not type your seed phrase into any website, app, phone, or tool claiming to check whether it is affected. Anyone asking for your seed is a scammer, not a helper. This applies to every tool, including ones that look official.
Step 3: Best solution. Get clean hardware and generate a new seed.
Get a hardware wallet from a different manufacturer entirely. Trezor, Jade, SeedSigner, and Keystone are the names security researchers are pointing to right now. Do not migrate to a Mk4, Q, or Mk5 as your solution. Coinkite confirmed on Friday that these devices carry a weaker version of the same flaw and issued a separate warning to their users.
Step 4: No clean hardware right now. Temporary fix only.
On the existing Mk3, create a strong and completely unique BIP-39 passphrase and move funds to the new passphrase-protected wallet derived from it. This is a short-term mitigation only. Migrate to a fresh seed on new hardware as soon as possible. Do not treat the passphrase step as a permanent solution.
If the amount is significant, consider multisig for the new setup.
If you feel overwhelmed, some providers including Swan are offering temporary custodial or assisted multisig options. Prefer multisig if you are moving a meaningful amount to a new setup. No single point of failure means one compromised device cannot drain everything.
One rule that overrides all of the above
Do not enter your existing seed phrase into any website, app, or tool claiming to check whether it is affected. Any tool asking for your seed phrase is the attack, not the solution.
We covered the basics of hardware wallet selection and the difference between hot and cold storage in Hot Wallet vs Cold Wallet: Which One Should You Actually Use. The Coldcard story is a reminder that "cold" is not a security guarantee on its own. The device, the firmware, the seed generation process, and the passphrase configuration all matter.
What We Still Do Not Know
Coinkite framed its advisory as issued "out of an abundance of caution" while the investigation continues. The timing and victim profile, single-signature wallets created on Mk3-era firmware, many dormant for years, is consistent with a weak entropy flaw. Independent researchers including AnchorWatch CEO Rob Hamilton, Wizardsardine CEO Kevin Loaec, and developer James O'Beirne all pointed to flawed seed generation as the likely cause. But the formal forensic review has not concluded and the causal link is not yet officially confirmed.
One risk that is not speculative: on-chain analysts have noted the attacker swept only addresses holding more than 0.15 BTC. The most likely explanation is that the target list was sorted by balance and truncated at a round number — 500 addresses in the first wave, now over 1,190 confirmed. The attacker almost certainly already holds the private keys to smaller balances. A second wave targeting sub-0.15 BTC addresses is a real possibility. If your address was generated on an affected device, the balance threshold is not protection.
Sources
CoinDesk: Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep
Cointelegraph via TradingView: Coldcard issues Mk3 warning as experts examine $38M Bitcoin wallet drain
Crypto.news: Coldcard Mk3 warning follows $38M Bitcoin drain
Atlas21: 594 bitcoin drained in fifteen minutes: what we know so far
Cryptobriefing: Coinkite warns COLDCARD Mk3 users after $38M Bitcoin stolen from dormant wallets
Bitcoin Magazine: Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen
CoinDesk: Coldcard's $38M+ Exploit Shakes Faith in Self-Custody
This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.