Coldcard warns of potential seed risks in the Mk3 hardware wallet, as security experts investigate an abnormal transfer incident involving $38.3 million in BTC
Canadian hardware wallet manufacturer Coinkite has issued a security warning, advising users who generated mnemonic phrases with Coldcard Mk3 firmware versions 4.1 to 5.3 to migrate their assets as soon as possible. The company stated that preliminary analysis shows wallets using BIP-39 passphrases are at lower risk, and Mk4, Q, and Mk5 devices are not affected; the investigation is still ongoing.
Meanwhile, security researchers are investigating an anomalous transfer event involving 594.48 BTC (approximately 38.3 million USD). AnchorWatch CEO Rob Hamilton stated that attackers transferred 1,324 UTXOs through 500 transactions within three blocks and speculated that the issue may stem from insufficient random number entropy during the wallet generation process. Wizardsardine CEO Kevin Loaec believes the vulnerability may be related to a specific software library, secure chip, or a particular batch of devices, as well as low-entropy random number generators in firmware versions, with attackers possibly using AI-generated scripts to brute-force the affected wallets. There is currently no conclusive evidence linking this fund transfer to a direct vulnerability in Coldcard Mk3.






