Skip to main content

Coldcard Mk3 Flags After 594 BTC Moves Without Clear Cause



Canadian hardware wallet vendor Coinkite has issued an urgent security advisory for its Coldcard Mk3 signing device, warning users to move funds away from wallets whose seed phrases were generated on certain Mk3 firmware versions. The company says the issue affects Mk3 firmware 4.0.1 through 5.0.3, and that affected seeds may put funds at risk.


The warning arrives as Bitcoin investigators and security specialists scrutinize an unrelated-looking but highly unusual sweep of 594.48 BTC from single-signature addresses. While commentators have connected the timing to Mk3 devices, Coinkite stresses that no definitive public proof has linked its firmware warning to the broader sweep.



Key takeaways



  • Coinkite’s advisory targets Coldcard Mk3 firmware versions 4.0.1 to 5.0.3; Mk4, Q, and Mk5 are stated as not affected.

  • The recommended response is to generate a fresh seed on an unaffected device, verify backups and receiving addresses, then send test transactions before moving remaining funds.

  • Early internal analysis from Coinkite indicates BIP-39 passphrases (distinct from the device PIN) may face minimal risk.

  • Security experts are analyzing a separate event: a sweep of 594.48 BTC across 500 transactions within a narrow three-block window from single-signature addresses.



Coinkite flags an Mk3 firmware window


In a post on its official blog, Coinkite said that seeds created on a Coldcard Mk3 running firmware version 4.0.1 (released in March 2021) or any later Mk3 firmware may expose funds to risk. The company extends the affected range through firmware version 5.0.3, described as the final firmware supporting the Mk3.


Coinkite’s early analysis also draws a boundary around which components of wallet setup are most relevant. It said seeds used with a BIP-39 passphrase face minimal risk, while clarifying that this refers to a passphrase rather than the Coldcard PIN.


Importantly, the company framed its guidance as a precautionary measure. “Out of an abundance of caution,” Coinkite urged users with potentially affected seeds to generate a new seed on an unaffected device, confirm the backup, verify the receiving address, send a small test transaction, and only then transfer the rest of their funds. Coinkite added that its investigation is still ongoing and that it will deliver a formal technical review.



What triggered renewed attention: the 594.48 BTC sweep


Interest in this broader incident intensified after a Reddit user reported that a wallet drained from an account associated with a Coldcard Mk3 purchased in May 2021 had later been restored onto a Coldcard Mk4 in January 2026. That user’s account is self-reported and does not, by itself, establish a direct connection between the Mk3 firmware warning and the sweep activity.


Separately, AnchorWatch CEO and co-founder Rob Hamilton published a preliminary analysis stating that 1,324 unspent transaction outputs were swept across 500 transactions in a three-block window, moving a total of 594.48 BTC. In his write-up, Hamilton noted that all affected addresses were single-signature, and that 562 BTC was later consolidated into another address.


Hamilton described the pattern as consistent with “flawed entropy in wallet generation somewhere along the way,” echoing the possibility that randomness quality during seed creation may have mattered. At the time of writing, the 594.48 BTC was estimated to be worth about $38.3 million based on Bitcoin’s price of $64,364.07, according to CoinGecko.



Experts debate cause: low-entropy seeds and partial drainage


Another security researcher, Wizardsardine CEO Kevin Loaec, offered a hypothesis focused on the randomness source itself rather than the sweep mechanics. In a separate post, Loaec said his current theory is that a low-entropy random-number generator—potentially located in a software library, a secure element, or a specific device batch or firmware version—produced wallet seeds with insufficient randomness.


Loaec further suggested that if attackers were aware of the flaw, they may have used an AI-generated brute-force script. In his account, the search was confined to a limited set of BIP-84 derivation paths, which could help explain why the sweep appears concentrated in native SegWit addresses and why some wallets were only partially drained. He emphasized that the idea remains unconfirmed.


Crucially, Loaec warned that if his model is correct, wallets that saw only partial drainage could remain vulnerable to additional attempts. He also said funds in other address types might be exposed if the attacker expands scanning beyond the initially targeted formats.



Why the guidance matters for users—especially in light of the speculation


Even though Coinkite has not publicly connected the Coldcard Mk3 firmware issue to the 594.48 BTC sweep, the overlap in themes—seed quality, single-signature theft, and concentrated sweep behavior—means the advisory should be treated as a direct action item. Hardware-wallet incidents differ from typical “compromised computer” narratives: if the weakness is in seed generation, reusing the same seed (even on a different device) can keep exposure alive.


That’s why Coinkite’s recommended operational steps are specific and defensive: creating a new seed on an unaffected device, validating backups, confirming the correct receiving address, and using a small test transfer before moving the remainder. This sequence is aimed at reducing the risk of both theft and user error during migration—two failure modes that often show up around recovery events.


For users, the key uncertainty is whether the sweep investigators will eventually find deterministic evidence linking the Mk3 firmware range to the stolen outputs. Until then, Coinkite’s advisory stands independently as a risk-management decision for any Coldcard Mk3 owner who created seeds during the stated firmware window.



Going forward, readers should watch for Coinkite’s promised formal technical review and for any public forensic work that either corroborates or rules out a relationship between the Mk3 seed-generation warning and the 594.48 BTC sweep pattern described by security specialists.



https://www.cryptobreaking.com/coldcard-mk3-flags-after-594/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Coldcard%20Mk3%20Flags%20After%20594%20BTC%20Moves%20Without%20Clear%20Cause%20

Comments

Popular posts from this blog

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...