Key Takeaways
Coinkite issued a safety advisory for Coldcard Mk3 customers on July 30, 2026.Studies present about 594 BTC, close to $38 million, left roughly 500 dormant wallets.Coinkite’s advisory covers Mk3 firmware 4.0.1 by 5.0.3, its ultimate supported launch.
{Hardware} pockets incidents not often unfold as remoted occasions. When long-dormant addresses start shifting in a tightly coordinated sample, the timing alone warrants scrutiny. That was the case on July 30, 2026, when an alleged 594 BTC, price about $38 million, moved from roughly 500 single-signature addresses inside roughly 25 minutes.
Lots of the wallets had remained inactive for years, with balances sometimes starting from 0.15 to 0.26 BTC. On the time of writing, regardless of widespread discussions on-line, the corporate has not confirmed whether or not the switch of practically 600 BTC is immediately related to the Coldcard safety advisory.
What Coinkite Says
Coinkite CEO Rodolfo Novak, recognized within the trade as NVK, stated the corporate is treating the studies with urgency. “We’re all fingers on deck doing a deep dive on all the things, technical submit quickly,” Novak stated on X. He added that the corporate’s communication channels have been “bombarded” with inquiries following the studies. In a separate replace, Novak burdened, “We’ve accomplished alot of investigation concerning the COLDCARD studies, weblog submit incoming.”
The corporate’s safety advisory weblog submit names a selected vary of affected gadgets. Anybody who generated a seed on a Mk3 operating firmware model 4.0.1, launched in March 2021, by model 5.0.3, the ultimate launch supporting the Mk3, could also be affected. Coinkite defined that its early evaluation reveals the Mk4, Q and Mk5 fashions usually are not affected.

Coinkite described the advisory as reflecting early findings, and stated a proper technical overview will comply with because the investigation continues. Neighborhood researchers have been reviewing onchain exercise tied to the studies. Dialogue has centered on the potential for weak randomness in seed era on sure older Mk2 and Mk3 firmware variations, reasonably than a provide chain compromise. On the time of publication, Coinkite has not confirmed a root trigger.
Passphrase Customers Face Decrease Danger
Based on the advisory, wallets protected with a BIP-39 passphrase, a user-added phrase distinct from the gadget PIN, seem to hold minimal threat underneath Coinkite’s early evaluation. The corporate suggested passphrase customers to maintain defending that phrase and keep away from getting into it on untrusted gadgets or web sites.
For Mk3 homeowners who didn’t use a passphrase, Coinkite really useful migrating to a brand new seed generated on an unaffected gadget. The corporate stated the method shouldn’t be rushed. It suggested sending a small take a look at transaction first, verifying the brand new pockets and obtain handle on the gadget display, and holding onto the outdated backup till the migration is confirmed.
Interim Choices
Coinkite outlined two interim steps for homeowners whose Mk3 is their solely gadget:
Add a robust, distinctive BIP-39 passphrase and transfer funds to the newly protected pockets. Generate a alternative seed utilizing the Mk3’s dice-roll import path, which doesn’t depend on the gadget’s random quantity generator, although Coinkite described this as a complicated process requiring cautious verification.
Coinkite revealed full technical steps in its advisory, obtainable on the corporate’s weblog. The corporate defined its investigation is ongoing and that further particulars will comply with. Coldcard has constructed a fame as a security-focused, air-gapped {hardware} pockets possibility since its launch, and the studies have drawn vast consideration throughout the Bitcoin group as homeowners assess their very own gadgets.









