Coldcard Mk3 Flags After 594 BTC Moves Without Clear Cause
0
0

Canadian hardware wallet vendor Coinkite has issued an urgent security advisory for its Coldcard Mk3 signing device, warning users to move funds away from wallets whose seed phrases were generated on certain Mk3 firmware versions. The company says the issue affects Mk3 firmware 4.0.1 through 5.0.3, and that affected seeds may put funds at risk.
The warning arrives as Bitcoin investigators and security specialists scrutinize an unrelated-looking but highly unusual sweep of 594.48 BTC from single-signature addresses. While commentators have connected the timing to Mk3 devices, Coinkite stresses that no definitive public proof has linked its firmware warning to the broader sweep.
Key takeaways
- Coinkite’s advisory targets Coldcard Mk3 firmware versions 4.0.1 to 5.0.3; Mk4, Q, and Mk5 are stated as not affected.
- The recommended response is to generate a fresh seed on an unaffected device, verify backups and receiving addresses, then send test transactions before moving remaining funds.
- Early internal analysis from Coinkite indicates BIP-39 passphrases (distinct from the device PIN) may face minimal risk.
- Security experts are analyzing a separate event: a sweep of 594.48 BTC across 500 transactions within a narrow three-block window from single-signature addresses.
Coinkite flags an Mk3 firmware window
In a post on its official blog, Coinkite said that seeds created on a Coldcard Mk3 running firmware version 4.0.1 (released in March 2021) or any later Mk3 firmware may expose funds to risk. The company extends the affected range through firmware version 5.0.3, described as the final firmware supporting the Mk3.
Coinkite’s early analysis also draws a boundary around which components of wallet setup are most relevant. It said seeds used with a BIP-39 passphrase face minimal risk, while clarifying that this refers to a passphrase rather than the Coldcard PIN.
Importantly, the company framed its guidance as a precautionary measure. “Out of an abundance of caution,” Coinkite urged users with potentially affected seeds to generate a new seed on an unaffected device, confirm the backup, verify the receiving address, send a small test transaction, and only then transfer the rest of their funds. Coinkite added that its investigation is still ongoing and that it will deliver a formal technical review.
What triggered renewed attention: the 594.48 BTC sweep
Interest in this broader incident intensified after a Reddit user reported that a wallet drained from an account associated with a Coldcard Mk3 purchased in May 2021 had later been restored onto a Coldcard Mk4 in January 2026. That user’s account is self-reported and does not, by itself, establish a direct connection between the Mk3 firmware warning and the sweep activity.
Separately, AnchorWatch CEO and co-founder Rob Hamilton published a preliminary analysis stating that 1,324 unspent transaction outputs were swept across 500 transactions in a three-block window, moving a total of 594.48 BTC. In his write-up, Hamilton noted that all affected addresses were single-signature, and that 562 BTC was later consolidated into another address.
Hamilton described the pattern as consistent with “flawed entropy in wallet generation somewhere along the way,” echoing the possibility that randomness quality during seed creation may have mattered. At the time of writing, the 594.48 BTC was estimated to be worth about $38.3 million based on Bitcoin’s price of $64,364.07, according to CoinGecko.
Experts debate cause: low-entropy seeds and partial drainage
Another security researcher, Wizardsardine CEO Kevin Loaec, offered a hypothesis focused on the randomness source itself rather than the sweep mechanics. In a separate post, Loaec said his current theory is that a low-entropy random-number generator—potentially located in a software library, a secure element, or a specific device batch or firmware version—produced wallet seeds with insufficient randomness.
Loaec further suggested that if attackers were aware of the flaw, they may have used an AI-generated brute-force script. In his account, the search was confined to a limited set of BIP-84 derivation paths, which could help explain why the sweep appears concentrated in native SegWit addresses and why some wallets were only partially drained. He emphasized that the idea remains unconfirmed.
Crucially, Loaec warned that if his model is correct, wallets that saw only partial drainage could remain vulnerable to additional attempts. He also said funds in other address types might be exposed if the attacker expands scanning beyond the initially targeted formats.
Why the guidance matters for users—especially in light of the speculation
Even though Coinkite has not publicly connected the Coldcard Mk3 firmware issue to the 594.48 BTC sweep, the overlap in themes—seed quality, single-signature theft, and concentrated sweep behavior—means the advisory should be treated as a direct action item. Hardware-wallet incidents differ from typical “compromised computer” narratives: if the weakness is in seed generation, reusing the same seed (even on a different device) can keep exposure alive.
That’s why Coinkite’s recommended operational steps are specific and defensive: creating a new seed on an unaffected device, validating backups, confirming the correct receiving address, and using a small test transfer before moving the remainder. This sequence is aimed at reducing the risk of both theft and user error during migration—two failure modes that often show up around recovery events.
For users, the key uncertainty is whether the sweep investigators will eventually find deterministic evidence linking the Mk3 firmware range to the stolen outputs. Until then, Coinkite’s advisory stands independently as a risk-management decision for any Coldcard Mk3 owner who created seeds during the stated firmware window.
Going forward, readers should watch for Coinkite’s promised formal technical review and for any public forensic work that either corroborates or rules out a relationship between the Mk3 seed-generation warning and the 594.48 BTC sweep pattern described by security specialists.
This article was originally published as Coldcard Mk3 Flags After 594 BTC Moves Without Clear Cause on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.
0
0
Securely connect the portfolio you’re using to start.





