Coldcard Mk3 Vulnerability Used to Steal 594 BTC ($38M) From 500 Wallets
AI Market Summary
An exploit tied to a Coldcard Mk3 seed-generation entropy flaw reportedly enabled theft of ~594 BTC (~$38M) from ~500 wallets in minutes, undermining confidence in Bitcoin self-custody and hardware-wallet operational security. While passphrases and multisig mitigations appear effective, the urgency to migrate funds elevates risks of user error and phishing, likely increasing near-term caution around self-custody practices and custody-provider scrutiny.
Impact level
● High
Affected assets
BTC/USDT-2.99%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
On July 30, Bitcoin self-custody suffered a sharp real-world shock: an attacker siphoned roughly 594 BTC—valued at more than $38 million—from about 500 Coldcard wallets in an estimated 15–25 minutes.
On-chain investigators say the theft hinged on a weakness in Coldcard Mk3 seed generation that made certain recovery phrases more predictable due to insufficient entropy. Hardware wallets are designed to produce seeds using high-quality randomness, creating a vast search space. In this case, the flaw reportedly reduced that search space dramatically—shifting from roughly 340 undecillion possible combinations to only a few billion. The seed phrases appeared normal and used the standard word list, but the reduced randomness made brute-force attempts far more feasible.
Coldcard maker Coinkite has drawn criticism following the incident, even though it had previously warned Mk3 users that their funds were not safe. Coinkite said users who protected their seeds with a BIP39 passphrase faced minimal risk.
The company also noted that seeds generated on Mk4, Q, and Mk5 devices prior to the fixed firmware release may be affected as well. Its advisory stated: If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk. Coinkite added that other hardware signers in its lineup—TAPSIGNER, OPENDIME, and SATSCARD—were not impacted.
Coinkite urged Mk3 users to move funds, recommending migration to a newly generated seed on an unaffected device. It also suggested using a strong BIP39 passphrase or a dice-only seed. Still, shifting funds under time pressure can introduce fresh risks, including user mistakes, phishing attempts, and rushed operational errors.
The incident has rattled parts of the Bitcoin community, but the broader ecosystem remains intact. Reports indicate the attack primarily affected single-signature hardware wallet setups, reinforcing the case for additional safeguards such as passphrases, multisig, and user-generated entropy via dice rolls.
Final summary: An attacker exploited a Coldcard Mk3 flaw to drain about 594 BTC worth roughly $38 million in under half an hour. While the episode exposed weaknesses in certain self-custody practices, wallets using extra security layers such as multisig were not similarly compromised.