Coinkite Warns of Possible Seed Phrase Exposure on Coldcard Mk3; Researchers Scrutinize $38.3M Bitcoin Movement

Coinkite, the Canadian maker of Coldcard hardware wallets, has released a security advisory urging users who created mnemonic seed phrases on Coldcard Mk3 units running firmware versions 4.1 through 5.3 to move funds immediately, according to Huo Xing Cai Jing. The company said an initial review suggests wallets protected with BIP39 passphrases face lower risk. Coinkite added that Coldcard Mk4, Q and Mk5 models are not affected, and that its investigation remains ongoing. Separately, security researchers are examining an unusual transfer of 594.48 BTC, worth about $38.3 million. AnchorWatch CEO Rob Hamilton said the attacker consolidated 1,324 UTXOs via roughly 500 transactions over three blocks, and suggested the incident could be tied to insufficient entropy during wallet creation. Wizardsardine CEO Kevin Loaec said a potential weakness could stem from a software library, the secure element, or a specific production batch or firmware version using a low-entropy random number generator. He added that attackers may be deploying AI-generated scripts to brute-force wallets that are vulnerable. Researchers have not found conclusive evidence linking the Bitcoin transfer directly to the reported Coldcard Mk3 issue.