Coinkite Warns Coldcard Users After 594 BTC Wallet Sweep

Coinkite Warns Coldcard Users After 594 BTC Wallet Sweep

Coldcard manufacturer Coinkite issued an urgent security advisory after an automated operation swept approximately 594.5 BTC, worth about $38 million, from 500 Bitcoin addresses. The incident exposed a critical weakness in the randomness used to generate certain Coldcard wallet seeds.

The affected addresses were drained across four consecutive Bitcoin blocks on July 30, 2026. On-chain analysis found that the operation moved 1,324 unspent transaction outputs in about 15 minutes, making the theft a highly coordinated attack against weakly generated private keys.

Weak Seed Entropy Put Wallet Keys at Risk

Coinkite said its most serious warning applies to seeds generated on Coldcard Mk3 devices running firmware versions 4.0.1 through 4.1.9. Those releases were available from March 2021 until June 2023, creating a multiyear exposure window for wallets created with affected device-generated entropy.

The vulnerability reduced the unpredictability available during seed creation. Instead of receiving the expected level of cryptographic randomness, affected seeds could be drawn from a substantially smaller search space, giving attackers a realistic path to reconstruct private keys through large-scale computation.

Security analysis linked the coordinated sweep to weak key generation rather than physical theft of the devices or exposure of recovery phrases through connected computers. Several reported victims said their seeds had remained offline, reinforcing the conclusion that the weakness existed from the moment the wallets were created.

Coinkite’s updated advisory expanded the scope beyond the Mk3. Seeds generated on Mk4 and Mk5 devices before firmware 5.6.0, and on Coldcard Q devices before version 1.5.0Q, may contain about 72 bits of entropy rather than the expected 128 bits.

The company described the impact on newer models as less severe than the Mk3 issue but still serious. TAPSIGNER, OPENDIME and SATSCARD are not affected because they use different codebases, making seed origin and firmware history the key factors in determining exposure.

On-chain investigators observed no multisignature or Taproot wallets among the 500 swept addresses. Most were native SegWit addresses, and the absence of multisignature losses strengthens the case for separating key generation across independent devices and vendors.

Firmware Updates Do Not Repair Existing Seeds

Coinkite released fixed firmware on July 31. Mk3 users should install version 4.2.0 or later, Mk4 and Mk5 users need version 5.6.0 or later, and Q users need version 1.5.0Q or later before generating a replacement wallet.

Updating the device alone is not enough. A seed created under vulnerable firmware remains weak after the update, meaning affected users must generate a new seed and transfer their Bitcoin to new addresses.

Coinkite advised users to verify the new recovery phrase, wallet fingerprint and receiving address before moving funds. A small test transaction should be completed first, followed by the remaining balance only after the new wallet has been confirmed.

Users who added at least 50 fair, independent and private dice rolls while creating the final seed may have supplied sufficient external entropy to avoid the vulnerability. Anyone unsure about the number, privacy or independence of those rolls should treat the wallet as exposed and complete the migration.

A strong, unique BIP-39 passphrase may provide an additional barrier because it creates a separate derivation path. Coinkite stressed, however, that a passphrase is not a permanent remedy and that short, reused or predictable phrases may still be vulnerable to guessing.

The company also offers an advanced dice-only option for Mk3 users running fixed firmware. That method requires at least 99 independent rolls of a fair six-sided die, but the normal wallet-generation process in version 4.2.0 has also been corrected.

The event highlights the hidden systemic risk of defective entropy inside hardware-security products. A wallet can remain air-gapped, never expose its seed online and still fail if its private keys were predictable at creation.

Institutional controls should therefore extend beyond device possession. Multisignature policies, independent key-generation sources, firmware inventories, cryptographic testing and documented migration procedures can prevent one vendor-level randomness failure from compromising an entire treasury.

Coinkite said its investigation remains ongoing and that a formal technical review will follow. Until the full cause and attacker methodology are documented, affected users should prioritize deliberate key migration over improvised fixes, because the security of existing funds depends on replacing the vulnerable seed itself.

Follow Us

Ads

Main Title

Sub Title

It is a long established fact that a reader will be distracted by the readable

Ads
banner 900px x 170px