Coldcard Mk3 warning: possible seed flaw after 594 BTC sweep
Coinkite issued a Coldcard Mk3 warning after security analysts began probing an unexplained Bitcoin wallet drain involving 594.48 BTC (about $38.3m at the time of writing). Coinkite said seed phrases generated on a Coldcard Mk3 with firmware 4.0.1 (released March 2021) or later—up through firmware 5.0.3, the last Mk3 release—may put funds at risk. Coinkite said Mk4, Q and Mk5 are not affected.
The company urged affected users to move funds only after generating a new seed on an unaffected device, verifying the backup, receiving a new address, sending a small test transaction, and then transferring the remainder. Coinkite also stated its early analysis suggests minimal risk when a BIP-39 passphrase was used (clarifying this is the passphrase, not the Coldcard PIN). It has not publicly proven that the Coldcard Mk3 issue caused the theft, but it is conducting a formal technical review.
Separately, AnchorWatch CEO Rob Hamilton analyzed a coordinated sweep: 1,324 unspent transaction outputs across 500 transactions in a three-block window, all from single-signature addresses, with 562 BTC later consolidated elsewhere. Wizardsardine CEO Kevin Loaec proposed a hypothesis that flawed entropy or a low-entropy random-number generator in certain firmware/device batches could have enabled brute-force targeting of limited derivation paths, potentially explaining why the activity clustered in native SegWit addresses and why some wallets were only partially drained.
Neutral
This is a targeted hardware-wallet security advisory (Coldcard Mk3 seed-generation risk), but the article stresses there is no definitive public proof linking the Mk3 issue to the 594 BTC sweep. For traders, the immediate implication is risk management rather than a broad market driver: potential sell/transfer of affected funds could create short-lived, localized volatility for BTC custody patterns. However, because the affected firmware range is specific and larger ecosystems (Mk4/Q/Mk5) are reportedly unaffected, systemic panic is less likely.
Historically, similar events—such as wallet generation/entropy flaws or suspected derivation-path attacks—often lead to short-term sentiment dip in BTC security narratives, but market impact fades once mitigations and confirmations emerge. In the long run, the key follow-through will be Coinkite’s technical review and whether investigators can conclusively attribute the sweep to the Coldcard Mk3 issue. Until then, the likely trader response is heightened caution (verification of backups, seed migration) with limited impact on overall BTC price trend.