Coldcard Mk3 Alert: 594 BTC Taken From 500 Addresses as Coinkite Flags Seed-Generation Risk

AI Market Summary
Coinkite warned that Coldcard-generated Bitcoin seeds on certain firmware versions may have materially reduced entropy (~72 vs 128 bits), following an apparent automated sweep of 594.5 BTC from ~500 single-signature addresses. While BTC price action was largely unchanged, the event raises acute self-custody and hardware-wallet risk, likely increasing near-term caution around UTXO management, key-generation practices, and device firmware hygiene.
Impact level
● Medium
Affected assets
BTC/USDT-1.65%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Coinkite, the Canadian maker of the Coldcard hardware wallet, has issued a warning that Bitcoin funds could be exposed if wallet seeds were generated on certain firmware versions affected by a flaw tied to device-generated entropy. The company said the problem impacts every Coldcard Mk3 firmware release since version 4.0.1, first released in March 2021. It also extends to seeds created on Mk4 and Mk5 devices before firmware 5.6.0, and on the Coldcard Q before version 1.5.0Q. Coinkite described the risk on Mk4, Mk5, and Q as less severe than Mk3, but still serious. Coinkite estimates affected seeds may contain about 72 bits of entropy rather than the expected 128 bits, potentially weakening the resulting private keys. The firm added that TAPSIGNER, OPENDIME, and SATSCARD are not impacted because they rely on different codebases. Users who generated seeds under the affected conditions are being urged to move funds to a fresh seed created on an unaffected device. Coinkite advised Mk4 and Mk5 owners to upgrade to firmware 5.6.0 or later before generating a replacement seed, while Coldcard Q users should install version 1.5.0Q or later. The guidance also recommends backing up and verifying the new seed, confirming a new receive address on the device, and sending a small test transaction before transferring the remaining balance. If an Mk3 is the only available option, Coinkite suggested temporarily using a strong, unique BIP39 passphrase and carefully checking the wallet fingerprint and receive address. The advisory follows reports on July 30 that Bitcoin had been drained from Coldcard wallets. Atlas21 said an automated process swept 500 single-signature addresses across four consecutive blocks (960188 to 960191). In total, 1,324 UTXOs worth 594.5 BTC were moved, valued at roughly $38 million at current prices. Atlas21 pointed to weak private keys generated at wallet creation as the likely cause. No multisig or Taproot wallets were listed among the victims. The median loss was 0.41 BTC, with 110 victims losing more than 1 BTC. The largest reported loss was 29.9 BTC, while transaction fees for the operation totaled about 0.044 BTC. Atlas21 said the first public warning came from a Reddit user who claimed their Coldcard generated a 24-word seed phrase in 2021 and that the seed had never been entered on a computer. Despite the scale of the drain, Bitcoin's price showed little reaction and continued trading near $64,000. The post Coldcard Mk3 Users Warned of Risk After 594 BTC Swept From 500 Addresses appeared first on CryptoPotato.