Sometime after 1:31am UTC on July 31, someone worked through roughly 500 bitcoin wallets created on Coldcard Mk3 hardware devices. In under 25 minutes, 594 BTC — about $38 million — moved out, much of it from addresses that had sat untouched for years.
Coinkite, the maker of Coldcard, says the likely culprit is buried in its own firmware. Starting with version 4.0.1, released in March 2021, and continuing through 5.0.3 — the last build the Mk3 ever shipped — the device could skip its hardware random-number generator during key creation and fall back on predictable inputs instead: the chip's serial number and clock data. Coinkite hasn't formally confirmed this caused the theft, but independent blockchain researchers have already tied the drain to that same weak entropy.
Only Mk3 owners who never set a BIP-39 passphrase are exposed — that extra "25th word" that turns a predictable key into something an attacker can't guess. The newer Mk4, Q and Mk5 models aren't affected at all.
Coinkite's advice mixes urgency with caution:
- add a strong, unique BIP-39 passphrase to the device right away;
- move funds to a fresh seed generated on an unaffected model;
- advanced users can regenerate a seed using 99-plus dice rolls on firmware 4.1.9.
"Rushing a wallet migration can create a more immediate risk than the issue you're trying to address," the company warned. That's the uncomfortable part of this story: hardware wallets are supposed to be the safest way to hold bitcoin precisely because key generation never leaves the chip. A firmware bug quietly undercut that promise for five years before anyone noticed.



