Technology

Coinkite Issues Mk3 Security Warning After 594 BTC Swept in Minutes

Coinkite has issued an urgent security advisory for Coldcard Mk3 devices running firmware 4.0.1 through 5.0.3, warning that seeds generated under those versions may be compromised due to a possible RNG flaw, coinciding with a 594 BTC sweep from roughly 500 single-sig addresses.

4 min read
Close-up of a small hardware device on a wooden desk next to a notebook with handwritten words, soft natural light, no logos or text visible
Share

Coinkite's formal advisory flags a possible RNG flaw in Coldcard Mk3 firmware; if your seed has no BIP-39 passphrase, your funds are at elevated risk right now.

Key takeaways

  • Coinkite has issued an urgent security advisory: seeds generated on Coldcard Mk3 devices running firmware 4.0.1 through 5.0.3 may be compromised due to a possible flaw in the device's random number generator.
  • Roughly 594 BTC (approximately $38 million) was swept from around 500 single-signature addresses; the theft mechanism has not been officially confirmed as RNG-related, and Coinkite's advisory is precautionary.
  • Mk3 holders without a BIP-39 passphrase should add one immediately and migrate to a fresh seed on Mk4, Q, or Mk5 as soon as practical; Mk4, Q, and Mk5 are confirmed unaffected.

Coinkite published a formal security advisory on July 31, 2026 warning that seeds generated on Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3 may be compromised due to a possible flaw in the hardware's random number generator. The timing is not coincidental: roughly 594 BTC, worth approximately $38 million at the time, was swept from around 500 single-signature addresses in a tightly coordinated attack.

On-chain analysis by AnchorWatch CEO Rob Hamilton identified 1,324 UTXOs swept across the affected addresses. Hamilton noted on X that "at first glance, it appears there was faulty entropy in wallet generation somewhere along the path." Many of the drained UTXOs had been dormant since 2021, suggesting long-term holders who set up their wallets years ago and never revisited their operational security were the primary victims. Kevin Loaec, co-founder of Wizardsardine, was among the first to publicly raise the alarm.

What Coinkite Is and Isn't Saying

Coinkite has not officially confirmed the RNG flaw was the direct cause of this specific theft. NVK, Coinkite's founder, said on X that the sweep involved compromised or weak seeds across keys from different wallets, and rejected claims of a device-wide cryptographic breach. The advisory is explicitly precautionary.

That distinction matters. The causal link between the Mk3 RNG issue and the 594 BTC theft remains unestablished. What Coinkite has confirmed is that the RNG flaw exists in the affected firmware range, that it creates meaningful risk for single-sig wallets without a passphrase, and that the fix is available right now.

The advisory states directly: "If the affected Mk3 seed was used with a BIP-39 passphrase, our early analysis indicates that your funds are at minimal risk from this issue." Coinkite recommends two immediate actions: add a strong, unique BIP-39 passphrase on the device and move funds to the resulting wallet, then migrate to a new seed on Mk4, Q, or Mk5 as soon as practical. The advisory also describes a dice-roll seed generation option for Mk3 users who want to generate a new seed without relying on the device's RNG.

The Passphrase Is Not Your PIN

This is the part most Mk3 holders are going to get wrong. The PIN controls physical access to the device. The BIP-39 passphrase is entirely separate: it is an additional word or phrase appended to the seed that derives a completely different wallet. An attacker who reconstructs a weak seed off-device, whether through an entropy flaw or any other vector, cannot access funds protected by a passphrase they do not know. The passphrase is never generated by the device, which means it survives an entropy failure.

Most Mk3 users know their PIN. Far fewer have a BIP-39 passphrase configured. That gap is the attack surface.

The theft pattern reinforces the broader case for self-custody setups that layer defense: single-sig cold storage is only as strong as its entropy source. Every address swept in this attack was a single-sig legacy address. No multisig UTXOs. No Taproot. The on-chain fingerprint is a near-perfect illustration of what happens when users treat hardware wallet setup as a one-time event rather than an ongoing security practice.

A live alternative vector also remains on the table. Fake Sparrow Wallet applications were reportedly circulating on the Apple App Store in the weeks prior. That vector has not been ruled out and should not be dismissed, though no causal link to this theft has been established.

Coinkite's Disclosure Is the Right Call

One thing worth stating plainly: publishing a prominent advisory rather than quietly patching and hoping nobody notices is the correct behavior for a hardware manufacturer. Coinkite put the warning front and center. That is what honest companies in this space do, and it is worth recognizing without inflating it into something it is not.

The ecosystem matures through events like this, not despite them. The fix is entirely within the user's control. That is the point.

Mk3 holders should treat the advisory as urgent. Mk4, Q, and Mk5 users are confirmed unaffected. The full remediation path is in the Coinkite advisory.

What to Watch

The critical open question is whether a post-mortem technical disclosure from Coinkite confirms the RNG flaw as deterministic, meaning an attacker could compute any Mk3 seed using only public on-chain data. If that finding emerges, the severity escalates materially beyond the current framing and warrants a follow-up. If forensics show the theft had no connection to the Mk3 RNG and was caused entirely by compromised seed backups or fake software, the advisory remains precautionary, but the passphrase argument holds regardless of the vector.

Watch NVK's X account and the Coinkite blog for technical follow-up. If you hold funds on a passphrase-free Mk3 seed, do not wait for the post-mortem.

Sources

Frequently Asked Questions

The advisory explicitly covers only Mk3 devices running firmware 4.0.1 through 5.0.3. Coinkite has confirmed the Mk4, Q, and Mk5 lines are not affected by this RNG issue.

No. The PIN controls physical access to the device. The BIP-39 passphrase is an additional word or phrase appended to your seed that derives a completely separate wallet. An attacker who reconstructs your seed off-device has no path to your funds without also knowing the passphrase, because the passphrase is never stored or generated by the device.

If the wallet generated by your Mk3 is empty and you have migrated to a fresh seed on different hardware, you are not at risk from this advisory. The concern applies only to live wallets still holding funds under a seed generated by the affected firmware range.

News and analysis, not financial, investment, legal, or tax advice. Figures and quotes are verified against primary sources where possible. See our editorial and financial disclosures.

Keep reading

All of TFTC

The Bitcoin Brief

Bitcoin, markets, energy, and the tech reshaping all three.

A daily brief on the freedom tech building a parallel economy, written for the curious and the convicted alike. Signal, not noise. Truth for the Commoner.

Free, daily. Unsubscribe anytime.