Coldcard Issues Mk3 Firmware Warning Amid Bitcoin Wallet Drains

Canadian Bitcoin hardware manufacturer Coinkite has issued a warning to users of its Coldcard Mk3 signing device, advising them to transfer funds from wallets whose seed phrases were generated on specific firmware versions.

Coinkite stated on Thursday that seed phrases created on an Mk3 device running firmware version 4.0.1, released in March 2021, or any subsequent Mk3 version up to and including version 5.0.3, may compromise funds. The company's initial analysis indicates that the Mk4, Q, and Mk5 models are not affected by this issue.

The company recommended that affected users generate a new seed on an unaffected device, verify its backup and receive address, conduct a small test transaction, and then move the remaining funds. Coinkite noted that its investigation is ongoing and a formal technical review is anticipated.

Table of content

Mk3 Firmware Issue and Broader Sweep

This advisory coincides with an unexplained, coordinated sweep of 594.48 BTC from single-signature addresses, which Bitcoin security specialists are currently examining. However, no definitive public evidence has yet linked the Mk3 firmware issue to these specific transfers.

Coinkite's preliminary assessment suggests that affected seeds used with a BIP-39 passphrase face minimal risk, clarifying that this refers to a passphrase distinct from the Coldcard PIN.

Analysis of the 594.48 BTC Sweep

The 594.48 BTC sweep garnered attention after a Reddit user reported that funds were drained from a wallet whose seed was generated on a Coldcard Mk3 purchased in May 2021. The user indicated that the seed was subsequently restored onto a Coldcard Mk4 in January 2026.

This self-reported account does not definitively establish a connection between Coldcard and the broader sweep. Rob Hamilton, CEO and co-founder of AnchorWatch, provided a preliminary analysis on Friday, stating that 1,324 unspent transaction outputs were swept across 500 transactions within a three-block window, moving 594.48 BTC.

At the time of analysis, this amount was valued at approximately $38.3 million, based on a Bitcoin price of $64,364.07. Hamilton observed that all involved addresses were single-signature and that 562 BTC was later consolidated into another address, suggesting a potential flaw in wallet generation entropy.

Hypothesized Cause and Ongoing Vulnerability

Separately, Kevin Loaec, CEO of Wizardsardine, hypothesized that a low-entropy random-number generator, potentially within a software library, secure element, specific device batch, or firmware version, could have produced wallet seeds with insufficient randomness.

He proposed that an attacker, aware of such a flaw, might have employed an AI-generated script to brute-force affected wallets, focusing on a limited range of BIP-84 derivation paths. This could account for the apparent concentration of the sweep in native SegWit addresses and why some wallets were only partially drained.

Loaec emphasized that this theory remains unconfirmed and warned that partially drained wallets may still be vulnerable to further theft. He also cautioned that funds in other address types could be exposed if the attacker expands their scanning parameters.

Simonas Brazionis

Blockchain Expert

Simonas is a crypto and blockchain expert with 6 years of experience. Passionate about the industry he educates others on blockchain technology, and continuously expands his knowledge. He has helped many newcomers understand crypto, navigate investments, and stay informed about trends like DeFi and NFTs.