Login
Sign Up
Woofun AI reports that Coinkite issued a critical advisory on July 30, warning users of a potential entropy flaw in Coldcard Mk3 devices running firmware 4.0.1 or later, coinciding with a massive sweep of 594 BTC from compromised addresses.
The scope of the vulnerability spans firmware versions released from March 2021 through 5.0.3, the final update supporting the Mk3 model. Coinkite characterizes this notice as early analysis, with a formal technical review pending. No explanation of the entropy failure mechanism has been published, nor has the company provided a count of affected devices or a definitive figure for total funds lost.
Between 01:31 and 01:56 UTC, 594.48 BTC was moved from approximately 500 single-signature addresses. AnchorWatch chief executive Rob Hamilton, following preliminary reporting by Atlas 21, identified 1,324 unspent transaction outputs swept across 500 transactions within a three-block window, specifically blocks 960188 to 960191.
Subsequently, around 562 BTC was consolidated into a single address. With Bitcoin trading near $64,300, the consolidated amount represented approximately $38.3 million. This rapid consolidation suggests a coordinated effort to aggregate drained assets before moving them further.
Hamilton’s initial assessment pointed to an entropy flaw in the wallet generation process. Kevin Loaec of Wizardsardine, one of the first to raise public alarm, hypothesized a low-entropy random-number generator, potentially embedded within a software library, as the root cause.
Evidence linking the sweep to firmware age includes the fact that every drained address was single-signature and many had been dormant for years, with coins spanning 2021 to 2026. This timeline closely tracks the age of the affected firmware. Coinkite has not confirmed a direct link between the sweep and its advisory, and no definitive public evidence establishes one.
The advisory targets seeds generated on an affected Mk3, not every wallet the device has touched. Three conditions must hold: the device must be an Mk3, the firmware must be 4.0.1 or later, and the seed must have been generated on that device. Users often struggle because a Coldcard reports the firmware it is running now, not the version in place when the wallet was first created. Anyone who generated a seed before March 2021 and never regenerated afterwards falls outside the stated range. Anyone who set up after that date, or who cannot reconstruct the sequence, should assume they are in scope until Coinkite’s review narrows it. A seed generated elsewhere and imported into the Mk3 never used the device’s random-number generator, so the flaw does not reach it. Coinkite is direct about newer hardware: Mk4, Q, and Mk5 are unaffected on current analysis, and the advisory recommends using one of them to create the replacement seed.
A self-reported case illustrates the inherited weakness. A Reddit user described funds drained from a wallet whose seed was generated on an Mk3 bought in May 2021, then restored onto an Mk4 in January 2026. The newer, unaffected device inherited the original words and with them the original weakness. This account is self-reported and establishes nothing about the wider sweep, though the mechanism it describes is exactly what Coinkite is warning about.
The remedy is a seed that was never generated by an affected device. Given the recent events, an affected user should verify their funds are still present before planning a migration. An emptied wallet calls for incident response rather than a careful transfer. Coinkite stresses proceeding calmly, noting that a rushed migration can create more immediate risk than the flaw itself. Coinkite offers two routes, both treated as interim rather than complete fixes.
The first applies a BIP-39 passphrase, meaning a separate secret added to the recovery words, not the Coldcard PIN. The PIN protects the device and leaves the underlying keys untouched, so it offers nothing here. Read the official passphrase instructions first, then select "Passphrase" on the Mk3 and enter something long, random and unique. Never a quotation, a name, a familiar phrase or a reused password, and never typed into a computer, phone or website.
Back it up exactly, stored separately from the seed words, because losing it means losing the funds. Select "APPLY", record the new wallet’s eight-digit fingerprint, then power the device off and back on, re-enter the passphrase and confirm the same fingerprint appears. Export the passphrase wallet to your coordinator, verify its receive address on the Mk3 screen, then power-cycle and sign in without the passphrase to reach the original wallet.
Send a small test transaction, re-enter the passphrase, confirm the test arrived, and only then move the remainder. Every passphrase produces a valid wallet, including one containing a typo. Verifying the fingerprint before each send is what catches that. The second route sidesteps the device’s random-number generator entirely. On an empty Mk3 running 4.1.9, selecting "Import Existing > Dice Rolls" and entering at least 99 independent rolls of a fair six-sided die creates a seed by hashing the roll sequence directly.
Coinkite is specific that the ordinary "New Wallet" flow does not do this, so it must be the dice path. This is an advanced procedure and Coinkite labels it as such. Running both seeds on one device means alternating between them safely: verify each written backup and fingerprint before erasing anything, verify a receive address for the dice wallet, restore and verify the original, and send a test transaction before moving the balance. The roll sequence is key material.
It should never be photographed, saved digitally or entered into a networked computer. The dice-roll documentation covers the method in full.
Coinkite’s early analysis puts funds behind a strong BIP-39 passphrase at minimal risk from this issue, because the passphrase derives a separate wallet from both the original seed and the added secret. Automated searching for wallets built directly from a weakened base seed will not reach it. That aligns with what Friday’s sweep showed: every drained address was single-signature, each holding more than 0.15 BTC. The underlying entropy flaw remains regardless.
Those recovery words are still weaker than intended, and everything now depends on the strength and secrecy of one added phrase. The permanent fix is a new seed from an unaffected device. Coinkite’s investigation continues, and the scope may shift when the formal review lands. Owners should follow the company’s own updates rather than screenshots, forwarded messages or any third-party service offering to test whether a phrase is vulnerable. That last point deserves emphasis.
A warning at this scale attracts phishing aimed at exactly the people most likely to act quickly. No legitimate tool asks for seed words, and no support form, website or recovery service should ever receive them. The lesson here is narrower than "hardware wallets failed." An offline device keeps a private key away from malware, which it did. What it cannot do is protect a seed that was already predictable at the moment it was created, and key generation is where the entire security model starts.