< Back to all clusters
[TECHNOLOGY] · Canada · 27 sources

Coldcard Mk3 security advisory after $38 million Bitcoin theft

Coinkite, the Canadian maker of Coldcard hardware wallets, issued an urgent security advisory on July 30‑31 2026 warning that seeds generated on Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3 may be vulnerable. The advisory follows a coordinated on‑chain sweep that moved roughly 594 BTC (about $38 million) from around 500 single‑signature addresses within three Bitcoin blocks. About 562 BTC was later consolidated into a single address and has not moved since. The company stresses that no definitive public evidence links the seed‑generation flaw to the theft. Models Mk4, Q and Mk5 are reported as not affected. Coinkite advises users to generate a fresh seed on an unaffected device, verify backups, test a small transaction and then transfer the remaining funds. Bitcoin was trading near $64 000 per BTC at the time, and the incident has caused little immediate price movement but raises broad concerns about hardware‑wallet security.

The vulnerability stems from a software fallback random‑number generator that replaced the hardware RNG during seed creation, reducing entropy to as low as 40‑72 bits. Block Security independently confirmed the RNG issue. Coinkite’s CEO Rodolfo Novak said the company is conducting a deep technical review, while AnchorWatch CEO Rob Hamilton noted the rapid on‑chain activity. The advisory also clarifies that other Coinkite products such as Tapsigner, Opendime and Satscard are not affected.

Entities: AnchorWatch · Bitcoin · Block (blockchain infrastructure company) · Block (security firm) · Block Security · Coinkite · Coldcard Mk3 · Coldcard Mk3 hardware wallet · Mk4 · Rob Hamilton · Rodolfo Novak

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

  • [● 11 SOURCES] Coldcard models Mk4, Q and Mk5 are not affected by the flaw. (existing)
  • [● 16 SOURCES] Approximately 594.48 BTC (about $38 million) were transferred from about 500 single‑signature addresses within three Bitcoin blocks on July 30‑31 2026. (Coinkite advisory, on‑chain analysis)
  • [● 11 SOURCES] Block performed an independent analysis that identified the RNG issue in Coldcard devices. (Block Security report)
  • [● 15 SOURCES] Approximately 562 BTC were later consolidated into a single address and have not moved since. (Coinkite advisory, on‑chain analysis)
  • [● 11 SOURCES] Approximately 562 BTC were consolidated into a single address and have not moved since. (existing)
  • [● 15 SOURCES] Bitcoin’s price remained largely unchanged, staying above $64,000 per BTC at the time of the theft. (Market data cited in articles)
  • [● 4 SOURCES] Coinkite has issued a security warning to users of affected Coldcard devices. (All articles)
  • [● 11 SOURCES] The theft occurred on 30 July 2026. (existing)
  • [● 11 SOURCES] Coinkite issued a security advisory warning users of the Coldcard Mk3 seed‑generation vulnerability. (new)
  • [● 3 SOURCES] Bitcoin was trading near $64 000 per BTC at the time of the theft. (abbad952-3914-42f6-9ebf-32ce0d2b61cb,3066e715-982b-4a56-8777-2a11f2e80875,78bad479-43ec-4c03-9d5f-3055ffbd6591)
  • [● 4 SOURCES] Coinkite advises users to generate a new seed on an unaffected device, verify backups, test a small transaction, and then move remaining funds; a BIP‑39 passphrase or manual dice‑roll method can be a (1e973f6f-f608-4fe7-8080-57a4a5fd3a21,3066e715-982b-4a56-8777-2a11f2e80875,8089b2ba-c3b7-415b-bfca-4b6240f5a70b)
  • [● 15 SOURCES] Coinkite issued a security advisory warning that seeds generated on Coldcard Mk3 firmware versions 4.0.1 through 5.0.3 may be compromised. (eb404e3a-2f01-4bbf-8247-c88fda73bbeb,9aba4b3d-06f6-4638-8daf-794a4b424e6b,2b93a100-eafc-476a-91c5-b9c0b968f61a,17fd434e-)

Sources

about 5 hours ago
about 14 hours ago
about 15 hours ago
about 2 hours ago
about 15 hours ago