Coinkite has warned some owners of its Coldcard Mk3 hardware wallet that funds may be exposed if their wallet seed was generated on certain older firmware versions, after reports that hundreds of long-dormant bitcoin wallets were drained in a short period.

Security advisory follows unusual wallet activity

The advisory was issued on July 30, 2026, after reports that about 594 BTC, valued at roughly $38 million at the time, moved out of around 500 single-signature addresses within about 25 minutes. The wallets had reportedly been inactive for years, with balances commonly in the 0.15 BTC to 0.26 BTC range.

The pattern quickly drew attention because the addresses appeared to move in a coordinated way rather than as isolated transactions. Even so, Coinkite has not said the transfers were definitively caused by the issue covered in its warning, and it has not confirmed a root cause.

Which devices may be affected

Coinkite said the advisory applies to users who created a seed on a Coldcard Mk3 running firmware from version 4.0.1 through 5.0.3, which was the final release supporting the Mk3. Version 4.0.1 was released in March 2021.

The company said its early analysis indicates the newer Mk4, Q and Mk5 models do not appear to be affected. It described the advisory as based on preliminary findings and said a fuller technical review will be published as the investigation continues.

Coinkite CEO Rodolfo Novak, also known as NVK, said the company was treating the reports urgently. In posts on X, he said the team was conducting a deep investigation and preparing a technical update, adding that company communication channels had been flooded with questions after the reported wallet movements.

Passphrases and migration guidance

According to Coinkite, wallets protected by a BIP-39 passphrase appear to face minimal risk under its early analysis. The company said users who rely on a passphrase should continue safeguarding it and should not enter it into untrusted devices or websites.

For Mk3 owners who did not use a passphrase, Coinkite recommended moving funds to a new seed created on an unaffected device. It cautioned against rushing the process. Instead, the company said users should first send a small test transaction, verify the new wallet and receiving address on the device screen, and keep the old backup until the migration has been confirmed.

Interim options while the investigation continues

For users whose Mk3 is their only wallet device, Coinkite listed two temporary alternatives. One is to add a strong, unique BIP-39 passphrase and move funds to that newly protected wallet. The other is to create a replacement seed using the Mk3 dice-roll import method, which does not depend on the device’s random number generator. Coinkite described that route as more advanced and said it requires careful verification.

Discussion among community researchers has focused on the possibility of weak randomness in seed generation on some older Mk2 and Mk3 firmware versions, rather than a supply chain compromise. That remains unconfirmed. For now, the company says its review is ongoing, and the reported transfers of nearly 600 BTC have intensified scrutiny of older Coldcard devices across the Bitcoin community.

Source: news.bitcoin.com