Coinkite Issues Mk3 Security Warning After 594 BTC Swept in Minutes
Coinkite has issued an urgent security advisory for Coldcard Mk3 devices running firmware 4.0.1 through 5.0.3, warning that seeds generated under those versions may be compromised due to a possible RNG flaw, coinciding with a 594 BTC sweep from roughly 500 single-sig addresses.

Coinkite's formal advisory flags a possible RNG flaw in Coldcard Mk3 firmware; if your seed has no BIP-39 passphrase, your funds are at elevated risk right now.
Key takeaways
- Coinkite has issued an urgent security advisory: seeds generated on Coldcard Mk3 devices running firmware 4.0.1 through 5.0.3 may be compromised due to a possible flaw in the device's random number generator.
- Roughly 594 BTC (approximately $38 million) was swept from around 500 single-signature addresses; the theft mechanism has not been officially confirmed as RNG-related, and Coinkite's advisory is precautionary.
- Mk3 holders without a BIP-39 passphrase should add one immediately and migrate to a fresh seed on Mk4, Q, or Mk5 as soon as practical; Mk4, Q, and Mk5 are confirmed unaffected.
Coinkite published a formal security advisory on July 31, 2026 warning that seeds generated on Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3 may be compromised due to a possible flaw in the hardware's random number generator. The timing is not coincidental: roughly 594 BTC, worth approximately $38 million at the time, was swept from around 500 single-signature addresses in a tightly coordinated attack.
On-chain analysis by AnchorWatch CEO Rob Hamilton identified 1,324 UTXOs swept across the affected addresses. Hamilton noted on X that "at first glance, it appears there was faulty entropy in wallet generation somewhere along the path." Many of the drained UTXOs had been dormant since 2021, suggesting long-term holders who set up their wallets years ago and never revisited their operational security were the primary victims. Kevin Loaec, co-founder of Wizardsardine, was among the first to publicly raise the alarm.
What Coinkite Is and Isn't Saying
Coinkite has not officially confirmed the RNG flaw was the direct cause of this specific theft. NVK, Coinkite's founder, said on X that the sweep involved compromised or weak seeds across keys from different wallets, and rejected claims of a device-wide cryptographic breach. The advisory is explicitly precautionary.
That distinction matters. The causal link between the Mk3 RNG issue and the 594 BTC theft remains unestablished. What Coinkite has confirmed is that the RNG flaw exists in the affected firmware range, that it creates meaningful risk for single-sig wallets without a passphrase, and that the fix is available right now.
The advisory states directly: "If the affected Mk3 seed was used with a BIP-39 passphrase, our early analysis indicates that your funds are at minimal risk from this issue." Coinkite recommends two immediate actions: add a strong, unique BIP-39 passphrase on the device and move funds to the resulting wallet, then migrate to a new seed on Mk4, Q, or Mk5 as soon as practical. The advisory also describes a dice-roll seed generation option for Mk3 users who want to generate a new seed without relying on the device's RNG.
The Passphrase Is Not Your PIN
This is the part most Mk3 holders are going to get wrong. The PIN controls physical access to the device. The BIP-39 passphrase is entirely separate: it is an additional word or phrase appended to the seed that derives a completely different wallet. An attacker who reconstructs a weak seed off-device, whether through an entropy flaw or any other vector, cannot access funds protected by a passphrase they do not know. The passphrase is never generated by the device, which means it survives an entropy failure.
Most Mk3 users know their PIN. Far fewer have a BIP-39 passphrase configured. That gap is the attack surface.
The theft pattern reinforces the broader case for self-custody setups that layer defense: single-sig cold storage is only as strong as its entropy source. Every address swept in this attack was a single-sig legacy address. No multisig UTXOs. No Taproot. The on-chain fingerprint is a near-perfect illustration of what happens when users treat hardware wallet setup as a one-time event rather than an ongoing security practice.
A live alternative vector also remains on the table. Fake Sparrow Wallet applications were reportedly circulating on the Apple App Store in the weeks prior. That vector has not been ruled out and should not be dismissed, though no causal link to this theft has been established.
Coinkite's Disclosure Is the Right Call
One thing worth stating plainly: publishing a prominent advisory rather than quietly patching and hoping nobody notices is the correct behavior for a hardware manufacturer. Coinkite put the warning front and center. That is what honest companies in this space do, and it is worth recognizing without inflating it into something it is not.
The ecosystem matures through events like this, not despite them. The fix is entirely within the user's control. That is the point.
Mk3 holders should treat the advisory as urgent. Mk4, Q, and Mk5 users are confirmed unaffected. The full remediation path is in the Coinkite advisory.
What to Watch
The critical open question is whether a post-mortem technical disclosure from Coinkite confirms the RNG flaw as deterministic, meaning an attacker could compute any Mk3 seed using only public on-chain data. If that finding emerges, the severity escalates materially beyond the current framing and warrants a follow-up. If forensics show the theft had no connection to the Mk3 RNG and was caused entirely by compromised seed backups or fake software, the advisory remains precautionary, but the passphrase argument holds regardless of the vector.
Watch NVK's X account and the Coinkite blog for technical follow-up. If you hold funds on a passphrase-free Mk3 seed, do not wait for the post-mortem.
Update, July 31, 2026
The scale of this theft is larger than the initial reports captured. Galaxy Research mapped the on-chain flow and found 1,196 addresses drained in full for 1,082.65 BTC, roughly $70.2 million, between 01:10:20 and 01:51:26 UTC on July 30, a 41-minute window spanning blocks 960,183 through 960,191. That attack preceded Coinkite's public advisory by approximately 30 hours. Every sweep paid an identical hardcoded 30.0 sat/vB fee, a 30-to-75x overpay versus the 0.4-to-1.0 sat/vB median that week, and left no change output.
That looks like an automated tool spending keys it already held, not owners moving funds. Galaxy also warned that "the nature of the vulnerability means that future attacks are possible on any Coldcard-generated address and those do not need to match this pattern."
The technical root cause is now fully documented. The vulnerability, introduced in firmware 4.0.0 in March 2021, caused devices to skip their hardware randomness generator and fall back to predictable software-based key generation seeded by nonsecret chip data. Firmware fell back to Yasmarang, a MicroPython pseudo-random number generator never meant for real-world cryptographic protection.
Bitcoin Core developer Gregory Sanders reproduced the attack using setup button-press counts and confirmed its impact on Mk3 and Mk2 models. Coinkite has now named a likely culprit for how the flaw was found in the first place: NVK said on X the company has to assume someone used AI to review previous versions of its open-source firmware to uncover the weakness, calling it "a sober reality of the new AI paradigm" and warning that AI-assisted code review can identify latent bugs faster than even experienced security experts. Coinkite's own AI sweep of the same codebase weeks earlier found nothing.
Security engineer Clay Garrett identified 695 earlier transactions matching the same on-chain fingerprint, suggesting the attack footprint is still growing. Galaxy identified 1,196 addresses containing approximately 1,082.65 BTC, valued at around $70.2 million, drained over that 41-minute period, while Chainalysis put its confirmed figure at over $38 million, with the two firms measuring different transaction sets and methodologies. Block's independent analysis confirmed the flaw could allow attackers to reconstruct private keys, and Block's hardware lead Max Guise urged anyone exposed to move funds immediately. Trezor told its own users their funds are safe, and noted that a seed created on an affected Coldcard stays weak even after being restored to another brand's device.
Coinkite has since expanded the advisory to include certain Mk4, Mk5, and Coldcard Q firmware versions and released emergency firmware updates for all affected models.
Those updates are version 4.2.0 or later for Mk3, 5.6.0 or later for Mk4 and Mk5, and 1.5.0Q or later for the Coldcard Q. The critical point has not changed: a firmware update alone does not secure existing seeds. Users must generate an entirely new recovery phrase on the fixed firmware and migrate their BTC.
NVK apologized and said the company took "full accountability for the firmware bug," acknowledging that its review process had failed to catch it.
Update, August 2, 2026
The theft total keeps climbing. The estimated total has now reached roughly 1,359.8820 BTC, per stats collected by the Coldcard Sweep Watch dashboard, with most of the identified coins remaining in a handful of addresses under the attacker's control. Galaxy Research has since mapped the damage further: the firm identified two additional suspected waves of sweeps beyond the original, raising its observed estimate to 1,367.05 BTC, worth about $88.6 million, across 4,585 addresses, with Waves 1 and 2 possibly sharing an operator based on transaction patterns, though Galaxy warned Wave 3 should not be assumed to involve the same attacker.
Galaxy said the activity remains ongoing and that it has reported roughly 600 suspected attacker-controlled addresses to federal investigators, compliance firms, and cybersecurity investigators.
Someone on-chain decided to make the situation stranger. On August 1, a public bitcoin transaction offered laundering services to the thief behind one of the largest self-custody bitcoin thefts ever recorded.
One of the attacker's holding addresses received an unusual transaction containing an OP_RETURN message -- a special Bitcoin transaction output that stores permanent text on the blockchain rather than transferring spendable funds. The Bitcoin.com News report puts the terms of the solicitation at a 10% cut. The attacker has not responded publicly.
The emergency firmware rollout has created its own problem. Users reported that emergency firmware updates are leaving some hardware wallets unusable.
Whether Coinkite issues additional guidance for customers experiencing firmware failures is now being watched just as closely as whether the stolen bitcoin eventually moves. Anyone who has not yet applied the patched firmware and is waiting on clarity from Coinkite before doing so should at minimum add a strong BIP-39 passphrase now -- that step does not depend on the firmware update and remains the fastest way to close your exposure window while the bricking reports get sorted out.
Update, August 4, 2026
A fourth organized wave of sweeps hit Coldcard-vulnerable addresses on August 3. Galaxy Research head Alex Thorn flagged hundreds of transactions impacting 709 potential victim addresses, moving 448.7 BTC, with activity averaging 13.8 sweeps per block -- around 45 times the rate observed in a pre-incident control window.
If the fourth wave holds, the running total across all waves reaches about 1,816 bitcoin, near $114 million, from more than 5,200 addresses since July 30. The $130 million figure referenced in some outlets reflects current BTC prices applied to that same on-chain count and is not a new Galaxy figure.
Wave 4 has one tactical wrinkle the earlier waves did not. Unlike earlier waves, the latest transactions appear to use bitcoin's replace-by-fee feature, meaning victims who spot their coins in the mempool may still be able to outbid the attacker and move their funds first -- until a transaction confirms, a victim who finds their address in the queue can pay a higher fee and move the coins out ahead of the sweep.
The pattern continues to suggest the flaw affects single-key Coldcard seeds and not multisignature setups, with the attacker sending funds to previously unused addresses that are harder to trace than in prior waves.
Coinkite has halted shipments and destroyed all remaining Coldcard devices carrying the vulnerable firmware; Satscard, Opendime, and Tapsigner products are unaffected. The pipeline attacking these keys is automated, it is running against a pre-computed list, and it is not finished. Anyone whose seed was generated on the affected firmware range without a BIP-39 passphrase has one job: get off that seed before Wave 5 confirms.
Sources
Frequently Asked Questions
The advisory explicitly covers only Mk3 devices running firmware 4.0.1 through 5.0.3. Coinkite has confirmed the Mk4, Q, and Mk5 lines are not affected by this RNG issue.
No. The PIN controls physical access to the device. The BIP-39 passphrase is an additional word or phrase appended to your seed that derives a completely separate wallet. An attacker who reconstructs your seed off-device has no path to your funds without also knowing the passphrase, because the passphrase is never stored or generated by the device.
If the wallet generated by your Mk3 is empty and you have migrated to a fresh seed on different hardware, you are not at risk from this advisory. The concern applies only to live wallets still holding funds under a seed generated by the affected firmware range.


