Coinkite has urged Coldcard Mk3 users to move their funds after identifying a potential risk in the device’s seed-generation process, while Bitcoin security experts continue investigating the unexplained drain of roughly $38 million from a separate wallet.

Canadian Bitcoin hardware manufacturer Coinkite has advised users of its Coldcard Mk3 signing device to transfer funds from wallets if their seed phrases were generated using the affected firmware version.

On Thursday, Coinkite said seed phrases generated on a Coldcard Mk3 running firmware version 4.0.1, released in March 2021, or any later Mk3 firmware could place users’ funds at risk. According to the company’s preliminary analysis, the issue affects versions through 5.0.3, the final firmware released for the Mk3, while the Mk4, Q, and Mk5 models are not impacted.

The warning comes as Bitcoin security researchers investigate an unexplained, coordinated transfer of 594.48 BTC from single-signature wallets. However, no definitive public evidence has linked the Coldcard Mk3 issue to those transactions.

“Out of an abundance of caution,” Coinkite urged affected users to create a new seed phrase on an unaffected device, verify the backup and receiving address, send a small test transaction, and then transfer the remaining funds. The company said it is continuing its investigation and plans to publish a detailed technical review.

Coinkite said its preliminary analysis suggests that affected seed phrases used with a BIP-39 passphrase face only minimal risk. The company emphasized that this refers to a BIP-39 passphrase and not the Coldcard device PIN.

Experts Probe 594 BTC Wallet Sweep for Security Clues#

The incident drew attention after a Reddit user claimed funds had been drained from a wallet whose seed phrase was generated on a Coldcard Mk3 purchased in May 2021.

The user said the seed phrase was later restored onto a Coldcard Mk4 in January 2026, meaning it had also been entered into a second device. The claim is self-reported and does not establish any link between Coldcard and the broader coordinated wallet sweep.

Stay in the loop

Get crypto news before the market moves

Join thousands of investors who read our daily briefing.

No spam. Unsubscribe anytime.

In a preliminary analysis published on Friday, AnchorWatch CEO and co-founder Rob Hamilton said 1,324 unspent transaction outputs (UTXOs) were consolidated across 500 transactions within a three-block window, transferring a total of 594.48 BTC.

At the time of writing, the 594.48 BTC was valued at about $38.3 million, based on a Bitcoin price of $64,364.07, according to CoinGecko.

Hamilton said every address involved used a single-signature setup and that 562 BTC was later consolidated into another wallet address. “At a glance, this looks like there was flawed entropy in wallet generation somewhere along the way,” he wrote.

Separately, Wizardsardine CEO Kevin Loaec said his current theory is that a low-entropy random number generator—possibly within a software library, secure element, or a specific device batch or firmware version—generated wallet seed phrases with insufficient randomness.

He suggested that an attacker aware of the flaw may have used an AI-generated script to brute-force vulnerable wallets while searching only a limited range of BIP-84 derivation paths. According to Loaec, this could explain why the sweep appears concentrated in native SegWit addresses and why some wallets were only partially emptied, though he emphasized that the theory has not been confirmed.

Loaec warned that, if his theory proves correct, wallets that were only partially drained could remain vulnerable to additional theft. He also said funds stored in other address formats may be at risk if the attacker broadens the scan to cover those wallets as well.