Loading market data...
Back to Feed
CRYPTO NEWS

Coldcard issues Mk3 warning as experts examine $38M Bitcoin wallet drainCoinkite urged Coldcard Mk3 users to migrate funds after identifying a potential seed-generation risk, as Bitcoin security experts separately examine an unexplained $38 million wallet drain.

Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

Published on CryptoNews: Source published: 2 min read
AI-generated editorial illustration for Coldcard issues Mk3 warning as experts examine $38M Bitcoin wallet drainCoinkite urged Coldcard Mk3 users to migrate funds after identifying a potential seed-generation risk, as Bitcoin security experts separately examine an unexplained $38 million wallet drain.
AI-generated editorial illustration.
Visit source

AI-assisted summary based on the linked source. Verify market-moving details at the original publisher before acting.

Canadian Bitcoin hardware wallet maker Coinkite has issued a warning to users of its Coldcard Mk3 device after identifying a potential security vulnerability related to seed phrase generation on certain firmware versions. Specifically, seeds created on an Mk3 running firmware version 4.0.1 (released in March 2021) through to version 5.0.3 (the final Mk3 firmware) may put funds at risk, according to Coinkite’s early analysis. Users are advised to migrate funds generated on these firmware versions by creating a new seed on an unaffected device (such as Mk4, Q, or Mk5 models), verifying backups, and moving funds carefully after testing with small transactions. The company noted that the issue seems minimal if seeds were used with a BIP-39 passphrase, distinct from the device PIN, and said its investigation is ongoing with a formal technical review forthcoming.

The warning coincides with the examination by Bitcoin security experts of an unexplained drain involving 594.48 BTC (approximately $38.3 million at the time) swept from single-signature addresses in a coordinated series of 500 transactions spanning three blocks. The funds were consolidated mostly into a single address afterward. AnchorWatch CEO Rob Hamilton suggested the sweep points to flawed entropy during wallet seed generation but cautioned that there is no definitive public evidence linking this large sweep directly to Coinkite’s Mk3 seed-generation issue. Additionally, a Reddit user reported that funds were drained from a Coldcard Mk3 wallet seed generated in May 2021 and later restored onto a Coldcard Mk4 in January 2026, but this anecdote does not establish a broader connection.

Experts, including Wizardsardine CEO Kevin Loaec, hypothesize that the root cause may be a low-entropy random-number generator within some software libraries, secure elements, or particular device batches or firmware versions. The attacker may have exploited this vulnerability using an AI-generated brute-force attack targeting a narrow range of wallet derivation paths, primarily focusing on native SegWit (BIP-84) addresses. This theory might explain why some wallets were only partially drained and why the sweep was concentrated on certain address types, though Loaec emphasized that this remains unconfirmed. He warned that partially drained wallets could still be vulnerable to further theft, and funds in other address types might also be at risk if the attacker broadens their scanning range.

Coinkite has urged users to act “out of an abundance of caution” while investigations continue and commits to full transparency with forthcoming technical details. The company’s announcement reflects ongoing concerns about hardware wallet seed security and the critical importance of robust entropy in generating secure wallet keys. Cointelegraph stresses that readers should independently verify this information as investigations develop.

Read the original source

> JOIN THE ALPHA

Get breaking crypto news before your friends do. Join 50,000+ degens receiving alpha directly to their inbox.

>
[ENCRYPTED][NO_SPAM][UNSUBSCRIBE_ANYTIME]