Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Bitcoin Crypto News

    Coldcard Mk3 Alert as Experts Investigate $38M Bitcoin Wallet Drain

    51 seconds ago
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Coldcard Mk3 Alert As Experts Investigate $38m Bitcoin Wallet Drain
    Coldcard Mk3 Alert As Experts Investigate $38m Bitcoin Wallet Drain

    Canadian hardware wallet maker Coinkite has issued an urgent security warning for owners of its Coldcard Mk3 signing device, advising users to move funds away from wallets whose seed phrases were generated using specific affected firmware versions. The company said the risk applies to Mk3 firmware 4.0.1 (released in March 2021) through 5.0.3, the last firmware version that supports the Mk3—while its Mk4, Q, and Mk5 models are not affected, based on early analysis.

    The alert arrives amid renewed scrutiny from Bitcoin security researchers investigating an unexplained, coordinated sweep of 594.48 BTC from single-signature addresses. Coinkite emphasized that, at this stage, there is no definitive public proof linking the Mk3 seed-generation issue to that activity, but the company is asking users to act “out of an abundance of caution.”

    Key takeaways

    • Coinkite warns Coldcard Mk3 users to migrate funds from wallets whose seeds were created on affected firmware versions 4.0.1 through 5.0.3.
    • The issue does not appear to affect newer hardware models (Mk4, Q, Mk5), according to Coinkite’s early findings.
    • Coinkite’s guidance focuses on safer recovery hygiene: generate a new seed on an unaffected device, verify backups and receive addresses, and test with a small transaction first.
    • Security analysts are examining a 594.48 BTC sweep from single-signature addresses, but no public evidence currently ties it directly to the Mk3 firmware problem.
    • Coinkite says seeds protected with a BIP-39 passphrase (distinct from the Coldcard PIN) show minimal risk in its preliminary assessment.

    Coinkite’s Mk3 seed-generation warning

    In a post on its official blog, Coinkite said seeds created on an Mk3 running firmware version 4.0.1 or later versions—up to 5.0.3—may put funds at risk. The company’s early analysis did not identify the same concern for Coldcard Mk4, Q, or Mk5 devices.

    The company’s recommendation is practical and staged. Coinkite urged affected users to generate a new seed on a device considered unaffected, confirm that the backup is correct, and ensure they are using the intended receive address. Users should then send a small test transaction before transferring the remainder of the balance.

    Coinkite also tried to clarify a point of confusion that often arises in hardware wallet security discussions: in its assessment, the “BIP-39 passphrase” is the relevant protection mechanism, and it should not be conflated with the Coldcard PIN.

    From firmware versions to real-world user risk

    The significance of Coinkite’s warning lies in how deterministically Bitcoin wallets derive addresses from seed phrases. If seed generation was compromised in a way that reduced randomness—or introduced patterns an attacker could exploit—then previously used addresses may become more guessable. Hardware wallets are designed specifically to make theft difficult precisely because the seed should be unpredictable, so any defect that affects entropy can have downstream consequences.

    While the company did not provide technical details in the excerpted warning, it did set boundaries around what users need to check: not every Coldcard Mk3 seed is automatically suspect, but those created on the specified firmware range. For users who cannot confidently identify the exact firmware version used during seed generation, Coinkite’s steps imply a conservative approach: treat the wallet as potentially exposed and migrate funds accordingly.

    That “caution first” posture is particularly important given the broader environment. Hardware wallet security incidents—even when the evidence remains circumstantial—tend to trigger defensive behavior from both users and threat researchers, because a stolen seed can sometimes lead to recurring attempts rather than a single breach.

    Security researchers link context, not causation

    Attention intensified after a Reddit user described a wallet drain they claimed involved a Coldcard Mk3 purchased in May 2021. According to the user’s account, the seed was later restored onto a Coldcard Mk4 in January 2026, meaning it was entered into a second device afterward. The information, however, is self-reported and does not, on its own, establish a direct connection between Coldcard hardware and a larger set of suspicious transactions.

    Separately, AnchorWatch CEO and co-founder Rob Hamilton published a preliminary analysis claiming that 594.48 BTC was swept across 500 transactions over a three-block window. In that assessment, Hamilton noted that 1,324 unspent transaction outputs were involved and that the addresses appeared to be single-signature. He also stated that roughly 562 BTC was later consolidated into another address. Hamilton suggested the pattern “looks like there was flawed entropy in wallet generation somewhere along the way,” describing the event as consistent with randomness issues, though this remains an interpretation rather than proof.

    At the time of the reporting, the 594.48 BTC was valued at approximately $38.3 million using a Bitcoin price of $64,364.07, according to CoinGecko.

    Another researcher, Wizardsardine CEO Kevin Loaec, offered a hypothesis focused on how low-entropy seeds might be produced. In his view, a low-quality random-number generator—potentially from a software component, secure element behavior, device batch, or specific firmware—could have resulted in wallets with insufficient randomness. Loaec suggested an attacker with knowledge of the flaw might use an AI-generated script to brute-force affected wallets, while limiting the search to a narrower set of BIP-84 derivation paths. That would align with why the sweep appears concentrated in native SegWit addresses, and why some wallets may have been only partially drained. He stressed that this theory is still unconfirmed and that further scanning might expose additional holdings.

    The key tension across these analyses is the difference between “consistent with a flaw” and “proven caused by this specific device.” Coinkite’s warning sits in the first category—credible internal assessment that certain Mk3 firmware versions may expose users—while the external sweep investigation remains a broader pattern that researchers are still trying to attribute.

    What to watch next for affected users

    If Coinkite’s risk assessment is accurate, the most important variable for users is whether their seed phrase originated from the affected firmware range and whether it was protected with a BIP-39 passphrase. The company’s preliminary statement that BIP-39 passphrase seeds face “minimal risk” provides some comfort, but it does not eliminate the need for verification and safe migration steps.

    Going forward, readers should watch for Coinkite’s promised formal technical review and for further independent analysis that either strengthens or weakens the suspected link between the Mk3 seed-generation issue and the 594.48 BTC sweep. Until that picture is clarified, the prudent takeaway remains the same: treat potentially affected wallets as exposed, and move funds using newly generated seed material on unaffected hardware.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Schumer Backs Anti-Corruption Agency, Targets Crypto Disclosure Issues

    Schumer Backs Anti-Corruption Agency, Targets Crypto Disclosure Issues

    1 hour ago
    Pavel Durov Responds As Russia Flags Telegram Over Terrorism

    Pavel Durov Responds as Russia Flags Telegram Over Terrorism

    2 hours ago
    World Cup Drives $20b In Blockchain Prediction Market Volume: Chainalysis

    World Cup Drives $20B in Blockchain Prediction Market Volume: Chainalysis

    3 hours ago
    Pavel Durov Responds After Russia Labels Telegram Ties To Terrorism

    Pavel Durov Responds After Russia Labels Telegram Ties to Terrorism

    4 hours ago
    Chainalysis: World Cup Boosted Blockchain Prediction Markets To $20b

    Chainalysis: World Cup Boosted Blockchain Prediction Markets to $20B

    5 hours ago
    Coinbase Q2 Profit Falls Short As Crypto Trading Share Hits Record

    Coinbase Q2 Profit Falls Short as Crypto Trading Share Hits Record

    6 hours ago

    Search Crypto News

    Featured Crypto News

    Win 3 Free Ga Passes To Bitcoin Asia 2026 In Hong Kong With Cryptobreaking

    Win 3 Free GA Passes to Bitcoin Asia 2026 in Hong Kong With CryptoBreaking

    24 July 2026

    Latest News

    • Coldcard Mk3 Alert as Experts Investigate $38M Bitcoin Wallet Drain
    • Schumer Backs Anti-Corruption Agency, Targets Crypto Disclosure Issues
    • Pavel Durov Responds as Russia Flags Telegram Over Terrorism
    • World Cup Drives $20B in Blockchain Prediction Market Volume: Chainalysis
    • Pavel Durov Responds After Russia Labels Telegram Ties to Terrorism
    • Chainalysis: World Cup Boosted Blockchain Prediction Markets to $20B
    • Coinbase Q2 Profit Falls Short as Crypto Trading Share Hits Record
    • Ripple-Backed Evernorth Completes Executive Agreements Ahead of XRP Treasury Listing
    • Schumer Pushes New Agency for Corruption Oversight, Targets Crypto Ties
    • Tokenized Gold Clears DeFi Stress Test as Collateral Use Stays <2%

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    eToro Crypto 300x300
    Bitcoin Asia 2026

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    📞 +971 50 449 2025
    ✉️ info@cryptobreaking.com
    📍Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!