The cryptocurrency community is on high alert following a massive $38 million Bitcoin wallet drain that has left security experts searching for answers. In response to the growing concerns, Canadian Bitcoin hardware manufacturer Coinkite has issued an urgent warning to its users. The company is advising anyone using specific older versions of the Coldcard Mk3 signing device to immediately migrate their funds due to a potential seed-generation vulnerability. While investigators are still working to confirm the exact cause of the multi-million dollar sweep, the hardware maker is taking proactive steps to ensure user security.
Coinkite Issues Urgent Coldcard Mk3 Warning
Coinkite’s official advisory states that Bitcoin seeds created on a Coldcard Mk3 running firmware version 4.0.1 (released in March 2021) through version 5.0.3 may be at risk. Fortunately, the company’s preliminary analysis confirms that newer hardware models, including the Mk4, Q, and Mk5, remain completely unaffected by this vulnerability. Out of an abundance of caution, Coinkite urges affected Mk3 users to generate a brand new seed phrase on a secure, unaffected device. To ensure safety, users should verify their backup and receiving address, send a small test transaction, and only then transfer the remaining cryptocurrency to the new wallet.
Interestingly, Coinkite noted that users who secured their affected seeds with a BIP-39 passphrase face a significantly lower risk of compromise. It is crucial to distinguish that this extra layer of protection refers to a dedicated, custom passphrase, not just the standard Coldcard PIN. This situation gained broader attention after a Reddit user reported losing funds from a wallet originally generated on a Coldcard Mk3 purchased in May 2021. The user had later restored that same seed onto a newer Mk4 device in early 2026. While this single self-reported incident does not definitively link the hardware maker to the broader hack, it has fueled ongoing investigations and prompted Coinkite’s promise of a formal technical review.
Security Experts Investigate the $38 Million Bitcoin Sweep
As Coinkite conducts its internal review, independent Bitcoin security specialists are diving deep into the on-chain data behind the massive wallet drain. Rob Hamilton, CEO and co-founder of AnchorWatch, revealed that a highly coordinated attack swept 594.48 BTC from single-signature addresses. The attacker moved 1,324 unspent transaction outputs across 500 transactions within a brief three-block window. With Bitcoin trading around $64,364, the stolen assets were valued at roughly $38.3 million before being consolidated into a new address. Hamilton suspects that flawed entropy—essentially a lack of true randomness—during the initial wallet generation process is the most likely culprit for the breach.
Adding to this analysis, Kevin Loaec, CEO of Wizardsardine, shared a compelling hypothesis regarding how the vulnerability was exploited. He suggested that a low-entropy random-number generator, possibly located within a specific software library or firmware batch, produced wallet seeds that were easy to guess. Loaec theorizes that an attacker aware of this cryptographic flaw used automated AI scripts to brute-force the vulnerable wallets. Because the attack currently appears concentrated on native SegWit addresses and left some wallets only partially drained, experts warn that the threat is far from over. If this hypothesis holds true, any remaining funds in partially drained wallets, or assets held in other address types, remain at severe risk of future theft until they are moved to secure locations.