Coldcard manufacturer Coinkite has warned that users who created wallet seeds on its discontinued Coldcard Mk3 hardware wallet may need to move their bitcoin, after reports of coordinated thefts involving hundreds of addresses raised concerns about weak randomness in older devices.
The advisory applies to Mk3 wallets that generated a seed using firmware version 4.0.1, released in March 2021, or any subsequent version through firmware 5.0.3, the final Mk3-supported release. Coinkite said the issue may expose funds when the seed was generated on an affected device and used as the sole protection for a wallet.
Reports published on July 30 described bitcoin being swept from around 500 single-signature addresses in transactions spanning Bitcoin blocks 960188 through 960191. One estimate put the amount at roughly 594.5 BTC, valued at about $38.3 million at the time of the report.
Coinkite has not confirmed that those transactions resulted from the Mk3 seed-generation flaw. The company said its investigation remains underway and that it would release further details as they become available. Yet the timing of the wallet drains and the company’s security warning have focused attention on the risks of flawed entropy, the randomness used to create a wallet’s secret recovery phrase.
Single-key Mk3 wallets face the greatest exposure
Bitcoin developer James O’Beirne said users should urgently move funds if their bitcoin is controlled by a single private key generated by a Coldcard Mk3 between 2021 and 2023, without additional dice rolls, a BIP-39 passphrase, or a multisignature setup.
A BIP-39 passphrase is an optional secret added to a wallet recovery phrase. It generates a separate wallet from the same seed words, meaning possession of the seed phrase alone would not give an attacker access to the passphrase-protected funds.
O’Beirne said preliminary analysis had excluded the Coldcard Mk2 and Mk4 from the known issue, though he cautioned that the assessment was not final and those models could also require review. The Mk3 warning is more specific because Coinkite has identified the firmware range in which seeds may have been created with insufficiently secure randomness.
The practical danger is concentrated in wallets whose recovery phrase was generated entirely by an affected Mk3 device and then used without another layer of protection. A weak random-number process can reduce the number of possible seed phrases far below the level users expect from a hardware wallet. If attackers can identify that pattern, they could derive potential private keys remotely and monitor the blockchain for wallets holding funds.
That scenario differs from a stolen hardware wallet or a phishing attack: the device does not need to be physically accessed, and the owner may retain both the wallet and recovery phrase while an attacker obtains the same keys through a predictable generation process.
Potential losses may extend beyond the initial address set
Clay Garrett, a member of Block’s engineering and security team, identified another group of transactions that may be connected to the reported Coldcard drain activity. Garrett said 695 earlier transactions shared the same “full fingerprint” as the initially identified set and moved an additional 488.10957948 BTC.
If the additional transactions are ultimately linked to the same activity, the combined amount would reach 1,082.58680432 BTC, according to Garrett’s analysis. The connection has not been confirmed by Coinkite, and blockchain patterns alone do not establish the source of a compromise or identify the party controlling the transactions.
The reported scale has nevertheless made remediation urgent for users who fit the affected profile. Bitcoin transactions are irreversible once confirmed, leaving wallet owners little recourse if an exposed private key is used to transfer funds.
Coinkite recommends passphrase protection or a new seed
For users with an affected Mk3-generated seed, Coinkite said applying a strong and unique BIP-39 passphrase on the device provides limited exposure to the underlying issue. The company advised users to create the passphrase directly on the Coldcard and transfer funds to the wallet derived from that protected configuration.
That option may help users respond quickly, but it introduces an operational burden: the passphrase must be retained securely. Losing it can make the associated wallet inaccessible even if the owner still possesses the original seed words.
Coinkite’s preferred longer-term measure is to migrate funds to a completely new seed generated on an unaffected Coldcard model. A new seed would replace the potentially predictable recovery phrase rather than adding protection around it.
The company also outlined an advanced route for owners who have an empty Mk3 device. Users can install firmware version 4.1.9 and generate a replacement seed through the dedicated dice-roll process, entering at least 99 independent rolls of a fair six-sided die. Coinkite said this procedure hashes the dice sequence directly and does not rely on the device’s random-number generator.
Manual entropy offers a way to create a seed independently of the component now under scrutiny, though it requires careful execution. Users must accurately record every roll, ensure the die is fair, and avoid reusing or exposing the resulting seed phrase.
Migration errors can create a separate risk
Coinkite warned that hurried wallet migrations can produce immediate security problems. Users moving funds should verify the destination address on their hardware wallet screen, avoid entering recovery phrases into websites or software wallets, and consider sending a small test transaction before moving larger balances.
Multisignature setups can also reduce dependence on a single hardware wallet or seed-generation process. In a multisignature arrangement, spending requires approval from more than one key, so the compromise of one device-generated seed would not automatically permit a transfer. That protection depends on the keys being created independently and stored securely.
For Coldcard Mk3 owners, the immediate question is whether their wallet was created within the affected firmware period and whether it relies only on that seed. Users with dice-generated entropy, a strong BIP-39 passphrase, or independently generated multisignature keys have additional safeguards, while those relying on a standard single-signature Mk3 seed have been advised to move funds without delay.
Worried about wallet hacks? Learn key crypto security practices to better protect your bitcoin from similar vulnerabilities.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

