Coinkite Warns Coldcard Mk3 Owners After Reports of $38M Bitcoin Loss

CN
1 hour ago

Key Takeaways

  • Coinkite issued a security advisory for Coldcard Mk3 users on July 30, 2026.
  • Reports show about 594 BTC, near $38 million, left roughly 500 dormant wallets.
  • Coinkite’s advisory covers Mk3 firmware 4.0.1 through 5.0.3, its final supported release.

Hardware wallet incidents rarely unfold as isolated events. When long-dormant addresses begin moving in a tightly coordinated pattern, the timing alone warrants scrutiny. That was the case on July 30, 2026, when an alleged 594 BTC, worth about $38 million, moved from approximately 500 single-signature addresses within roughly 25 minutes.

X post screenshot

Many of the wallets had remained inactive for years, with balances typically ranging from 0.15 to 0.26 BTC. At the time of writing, despite widespread discussions online, the company has not confirmed whether the transfer of nearly 600 BTC is directly connected to the Coldcard security advisory.

Coinkite CEO Rodolfo Novak, known in the industry as NVK, said the company is treating the reports with urgency. “We are all hands on deck doing a deep dive on everything, technical post soon,” Novak said on X. He added that the company’s communication channels were “bombarded” with inquiries following the reports. In a separate update, Novak stressed, “We’ve done alot of investigation about the COLDCARD reports, blog post incoming.”

The company’s security advisory blog post names a specific range of affected devices. Anyone who generated a seed on a Mk3 running firmware version 4.0.1, released in March 2021, through version 5.0.3, the final release supporting the Mk3, may be affected. Coinkite explained that its early analysis shows the Mk4, Q and Mk5 models are not affected.

X post screenshot

Coinkite described the advisory as reflecting early findings, and said a formal technical review will follow as the investigation continues. Community researchers have been reviewing onchain activity tied to the reports. Discussion has centered on the possibility of weak randomness in seed generation on certain older Mk2 and Mk3 firmware versions, rather than a supply chain compromise. At the time of publication, Coinkite has not confirmed a root cause.

According to the advisory, wallets protected with a BIP-39 passphrase, a user-added phrase distinct from the device PIN, appear to carry minimal risk under Coinkite’s early analysis. The company advised passphrase users to keep protecting that phrase and avoid entering it on untrusted devices or websites.

For Mk3 owners who did not use a passphrase, Coinkite recommended migrating to a new seed generated on an unaffected device. The company said the process should not be rushed. It advised sending a small test transaction first, verifying the new wallet and receive address on the device screen, and holding onto the old backup until the migration is confirmed.

Coinkite outlined two interim steps for owners whose Mk3 is their only device:

  • Add a strong, unique BIP-39 passphrase and move funds to the newly protected wallet.
  • Generate a replacement seed using the Mk3’s dice-roll import path, which does not rely on the device’s random number generator, though Coinkite described this as an advanced procedure requiring careful verification.

Coinkite published full technical steps in its advisory, available on the company’s blog. The company explained its investigation is ongoing and that additional details will follow. Coldcard has built a reputation as a security-focused, air-gapped hardware wallet option since its release, and the reports have drawn wide attention across the Bitcoin community as owners assess their own devices.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink