Incident Overview
Published 7/31/2026, 4:38:11 AM
Coldcard Mk3 users are advised to urgently migrate funds to a new seed phrase generated on a different device or via high-entropy methods (such as dice rolls). This recommendation follows a massive security incident on July 30, 2026, where approximately 594.5 BTC (~$38.3 million) was drained from roughly 500 single-signature addresses in under 25 minutes [Source: https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/].
Incident Overview
The drain targeted single-signature wallets that had been dormant for years, specifically those with seeds generated on Coldcard Mk3 devices. While the exact root cause is still under investigation, preliminary findings suggest a weak entropy vulnerability in the seed generation process of specific Mk3 firmware versions [Source: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/].
| Metric | Details |
|---|---|
| Total Drained | ~594.5 BTC [Source: https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/] |
| Affected Model | Coldcard Mk3 [Source: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/] |
| Affected Firmware | 4.0.1 (March 2021) through 5.0.3 (Final Mk3 release) [Source: https://www.lookonchain.com/feeds/66268] |
| Drain Window | July 30, 2026, 01:31 – 01:56 UTC [Source: https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/] |
| Primary Theft Address | bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0 [Source: https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/] |
Risk Assessment
- High Risk: Users who generated a seed phrase on a Coldcard Mk3 between 2021 and 2023 without using a BIP-39 passphrase or multi-signature setup [Source: https://cryptobriefing.com/coinkite-coldcard-mk3-firmware-rng-security-warning/].
- Lower Risk: Users who utilized a strong BIP-39 passphrase or generated their seed using physical dice rolls, which bypasses the device's internal random number generator (RNG) [Source: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/].
- Unaffected Models: Coinkite has indicated that Mk4, Mk5, and Q models are not affected by this specific vulnerability [Source: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/].
Recommended Actions
- Immediate Migration: If your seed was generated on Mk3 firmware versions 4.0.1 to 5.0.3, move funds to a new address generated on a secure device (e.g., Mk4, Mk5, or a different hardware provider) [Source: https://x.com/BitcoinNewsCom/status/2082967178043613387].
- Use Dice Rolls: When setting up a new wallet, use the "Dice Roll" entropy method to ensure the seed is not dependent on hardware or software RNG flaws [Source: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/].
- Add a Passphrase: If you cannot migrate immediately, adding a strong BIP-39 passphrase provides an additional layer of security, though full migration to a new seed is the only way to eliminate the underlying risk [Source: https://cryptobriefing.com/coinkite-coldcard-mk3-firmware-rng-security-warning/].
Current Status of Investigation
The situation remains contested regarding the exact technical flaw. Coinkite CEO Rodolfo Novak (NVK) has denied a "device-wide" vulnerability, suggesting some affected users may have imported compromised seeds, but confirmed the company is "all hands on deck" conducting a deep dive [Source: https://www.reddit.com/r/Bitcoin/comments/1vb6nqg/coldcard_ceo_denies_walletwide_vulnerability/]. A formal technical post from Coinkite is pending to clarify the root cause and the full scope of the entropy issue [Source: https://www.spendnode.io/blog/coldcard-mk3-seed-warning-594-btc-theft-july-2026/].