News/Bitcoin/Coldcard Mk3 Alert: Coinkite Flags Risk…
Bitcoin

Coldcard Mk3 Alert: Coinkite Flags Risk After 594 BTC ($38M) Sweep

Coinkite warns Mk3 users to migrate funds as a 594.48 BTC sweep, worth about $38M at current prices, draws scrutiny.

Coldcard Mk3 Alert: Coinkite Flags Risk After 594 BTC ($38M) Sweep

Coinkite has told users of its Coldcard Mk3 hardware wallet to move their Bitcoin to new addresses immediately, after identifying a potential seed-generation flaw that could put funds at risk. The warning, issued Thursday, coincides with a separate, unexplained sweep of 594.48 BTC — worth roughly $38 million at Bitcoin’s current price near $64,209 — that security researchers are still trying to trace.

Coinkite said any seed phrase generated on a Coldcard Mk3 running firmware version 4.0.1 or later may be exposed. That version shipped in March 2021, and the risk window runs all the way through 5.0.3, the last firmware build the Mk3 ever received. The company’s newer devices — the Mk4, Q and Mk5 — are not affected, according to its early analysis.

What Coinkite is telling users to do

Coinkite is advising affected owners to generate a brand-new seed on a device that isn’t running the flagged firmware, verify the backup and the receive address it produces, send a small test transaction first, and only then transfer the bulk of their holdings. The company described the move as precautionary “out of an abundance of caution” while it runs a formal technical review.

One mitigating detail: Coinkite’s early findings suggest seeds combined with a BIP-39 passphrase carry minimal exposure. The company was explicit that this refers to an added passphrase layer, not the device’s standard PIN, meaning users who never set one up remain in the higher-risk category.

The 594 BTC sweep under investigation

Attention around the Mk3 issue intensified after a Reddit user reported that a wallet had been drained after its seed was originally generated on a Coldcard Mk3 purchased in May 2021, then restored onto a Coldcard Mk4 in January 2026. That account is self-reported, and no public evidence has yet linked the individual case, or the Mk3 firmware flaw broadly, to the coordinated 594.48 BTC sweep.

Rob Hamilton, CEO and co-founder of AnchorWatch, posted a preliminary analysis on Friday describing the sweep as touching 1,324 unspent transaction outputs across roughly 500 transactions, all pulled from single-signature addresses. The scale and coordination of the movement is what has drawn scrutiny from Bitcoin security specialists, even though the root cause remains unconfirmed.

Why this matters for holders

For Coldcard Mk3 owners, the practical takeaway is concrete: check your firmware version, and if it sits between 4.0.1 and 5.0.3, treat the existing seed as compromised until Coinkite’s full review lands. Single-signature wallets without a BIP-39 passphrase appear to be the highest-risk category flagged so far.

More broadly, a $38 million sweep spread across 1,324 UTXOs is large enough to matter regardless of whether it ties back to Coldcard specifically. Investors self-custodying Bitcoin through any single-signature hardware setup should treat this as a reminder to audit seed generation practices and firmware provenance rather than assume hardware wallets are immune to systemic flaws.

Sources

Related articles