Breaking Brazil’s Central Bank Orders 24-Hour Delay on Large Crypto Transfers Abroad
Crypto Market News

Coldcard Mk3 Firmware Flaw Traced to $38 Million Bitcoin Wallet Drain

By Mr Whale · July 31, 2026 · 3 min read
Share: X FB TG

A hardware wallet built specifically to keep Bitcoin safe just became the reason hundreds of holders lost it.

Hardware wallet maker Coinkite has warned owners of its Coldcard Mk3 device that any Bitcoin seed phrase generated since March 2021 may be predictable, after roughly 594 BTC — worth about $38 million — was swept from around 500 single-signature wallets in a single 25-minute window on July 30.

The root cause traces back to firmware version 4.0.0, released in March 2021. Instead of relying on the device’s dedicated hardware randomness generator to create new seed phrases, that firmware and the versions that followed it (up through 5.0.3) quietly fell back to a software-based method seeded by non-secret data already stored on the chip. In practice, that means an attacker who understood the flaw could potentially reconstruct the same unpredictable-looking seed a device would have generated, without ever touching the physical wallet.

What makes this drain unusual is the pattern: roughly 500 separate wallets, all emptied within the same short window, all seemingly unrelated to each other except for sharing the same vulnerable firmware. That’s consistent with an attacker who had already computed a large batch of predictable seeds in advance and simply checked which ones held a balance — then swept all of them at once rather than picking off wallets one at a time, which would have raised suspicion far earlier.

Coinkite says Mk4, Q, and Mk5 devices use a different key-generation design and aren’t affected by this specific bug, though the company noted those newer models were separately found to generate only 72-bit entropy in some configurations — weaker than the industry-standard 128-bit or 256-bit randomness, though not necessarily exploitable in the same direct way as the Mk3 flaw.

The practical advice for anyone who owns an affected Mk2 or Mk3 device is blunt: move funds to a brand-new wallet with a freshly generated seed, ideally on non-vulnerable hardware, and don’t wait to see if your specific wallet gets targeted. A BIP-39 passphrase — an extra word or phrase added on top of the standard seed — appears to have protected some holders even on vulnerable firmware, since it changes the final private key even if the underlying seed itself was predictable.

It’s a sharp reminder that cold storage isn’t a single guarantee — it’s only as strong as the randomness behind the seed phrase it was built on, and that randomness is exactly the kind of detail most users never think to verify.

New to how seed phrases and private keys actually work? Learn the fundamentals in the Bitcoin Academy.

Share: X FB TG
Written by Mr Whale

Mr Whale has been active in the crypto market since 2020 and leads content and research at Coin680. More about our editorial team →

Get the Coin680 Daily Brief

Bitcoin news, market moves, and Academy lessons -- straight to your inbox, no spam.

Leave a Comment