Coinkite tells Coldcard Mk3 users to move funds after 594 BTC drain
Security & Exploits ·
Coinkite is urging owners of Coldcard Mk3 hardware wallets to migrate holdings without delay, citing a potential flaw in how seeds were generated on certain firmware builds.
The advisory covers devices running firmware 4.0.1 through 5.0.3, which Coinkite says may have produced seeds through a flawed process, according to Cointelegraph. The company is directing affected users to shift their bitcoin to new wallets as a precaution rather than waiting for a definitive root-cause finding.
The warning follows scrutiny of a theft totaling 594 BTC pulled from hundreds of single-signature wallets, a case investigators are still working through, as detailed by WuBlockchain. Coinkite has been explicit that no evidence yet ties the seed-generation issue to that specific theft, leaving the two matters formally unconnected even as they surface together.
Additional guidance reported by The Block has pointed affected users toward setting up new wallets with strong passphrases when migrating, adding a layer of protection beyond simply generating a fresh seed. Multiple outlets have converged on the same core details—the firmware range, the migration recommendation, and the unresolved link to the 594 BTC theft—lending consistency to the account even as the underlying cause remains under investigation.
What remains open is whether the seed-generation flaw in fact contributed to any of the funds lost in the 594 BTC theft, or whether the two developments are coincidental. Also unclear is how many Mk3 devices fall within the affected firmware range and how many users have completed migration since the warning went out. Further findings from Coinkite's investigation, along with any updated guidance on the scope of exposure, are the next things to watch.