Coinkite warned Coldcard Mk3 users to move funds after a possible seed-generation flaw, as analysts probe a 594.48 BTC sweep from single-signature wallets.
"Out of an abundance of caution," the Canadian hardware maker said Thursday, urging affected users to generate a new seed on an unaffected device, verify its backup and receive address, send a small test transaction and only then move the remaining funds. The company said its investigation is ongoing and promised a formal technical review.
Seeds created on an Mk3 running firmware version 4.0.1, released in March 2021, through version 5.0.3, the final firmware supporting the device, may put funds at risk, Coinkite said. The Mk4, Q and Mk5 are not affected. Affected seeds used with a BIP-39 passphrase face minimal risk, the company said, distinguishing a passphrase from the Coldcard PIN.
The warning follows a coordinated sweep that moved 594.48 BTC, worth about $38.3 million at a Bitcoin price of $64,364.07, according to CoinGecko. AnchorWatch chief executive Rob Hamilton said 1,324 unspent transaction outputs were swept across 500 transactions within a three-block window, with 562 BTC later consolidated into another address. "At a glance, this looks like there was flawed entropy in wallet generation somewhere along the way," he wrote.
The sweep drew attention after a Reddit user said funds had been drained from a wallet whose seed was generated on a Coldcard Mk3 bought in May 2021. The user said the seed was later restored onto a Coldcard Mk4 in January 2026, meaning it had been entered into a second device. The account is self-reported and does not establish a connection between Coldcard and the broader sweep.
Wizardsardine chief executive Kevin Loaec said his current hypothesis is that a low-entropy random-number generator, potentially in a software library, secure element or particular device batch or firmware version, produced wallet seeds with insufficient randomness. He suggested an attacker who knew of the flaw may have used an AI-generated script to brute-force affected wallets, but searched only a limited range of BIP-84 derivation paths. That could explain why the sweep appears concentrated in native SegWit addresses and why some wallets were only partially drained, though Loaec stressed the theory remains unconfirmed.
If the hypothesis is correct, wallets that were only partially drained may remain at risk of further theft, Loaec warned. Funds held in other address types could also be exposed if the attacker expands the scan to include them. Coinkite recommended affected users generate a new seed on an unaffected device, verify their backup and receive address, send a small test transaction and only then move the remaining funds. For experienced users, the company outlined a dice-roll seed generation method that avoids the Mk3's random-number generator.
This article is for informational purposes only and does not constitute investment advice.