Coldcard Mk3 key flaw drains 594 BTC from about 500 wallets
Security & Exploits ·
An attacker exploited a seed-generation weakness in Coldcard's Mk3 hardware wallets to sweep roughly $38 million in bitcoin within a 25-minute window.
The theft removed 594 BTC, worth approximately $38 million, from around 500 single-signature wallets, according to a report from cryptopotato.com. The attacker then consolidated 562 of those BTC into a single address, which has not moved since the sweep.
The flaw traces to key generation on Coldcard Mk3 devices running firmware version 4.0.1 or later, according to decrypt.co, which reported that the device's maker believes an AI tool played a role in surfacing the issue. Coinkite has issued an advisory acknowledging the seed-generation problem and says that, based on its early analysis, the Mk4, Q, and Mk5 models are not affected. Passphrase-protected wallets are described as being at minimal risk from this specific defect.
Coverage of the incident has produced varying loss estimates across the cluster of reporting, with some accounts describing losses exceeding 1,000 BTC and figures ranging as high as $70 million, including a estimate attributed to Galaxy Research. coindesk.com put the core figures at 594 BTC swept in the 25-minute window, consistent with the initial disclosure.
The advisory instructs affected users to remain calm, verify their holdings carefully, and migrate to a new seed generated on an unaffected device if necessary. The exact root cause of the weak key generation, the scope of devices and firmware versions beyond the Mk3 line, and the total financial toll once all reporting converges remain unresolved, as does whether the consolidated 562 BTC address will be moved or linked to further activity.