Coinkite issued a critical warning on July 30 for Coldcard Mk3 hardware wallet users. The company advised moving Bitcoin stored with seed phrases generated on firmware versions 4.0.1 through 5.0.3, citing potential security risks. This alert follows a recent orchestrated Bitcoin transfer that moved nearly 594 BTC, equivalent to roughly $38.2 million at the current price of about $64,324 per coin.
The massive shift occurred in a tight window, spanning just three blocks and involving 500 transactions. Single-signature addresses saw their balances swept. AnchorWatch CEO Rob Hamilton noted over 1,300 unspent outputs were consolidated into a smaller number of addresses, with 562 BTC eventually pooled into one recipient wallet. Although this activity raised concern about compromised entropy in wallet generation, no direct evidence yet links these transfers to the Coldcard Mk3 firmware vulnerabilities.
Coinkite’s Response and Recommendations
Coinkite clarified that only the Mk3 models running firmware from 4.0.1 up to 5.0.3 are affected, while newer models like the Coldcard Mk4, Q, and Mk5 appear safe based on early analysis. Users employing a BIP-39 passphrase with an affected seed face minimal risk, the company emphasized. To help users safeguard their funds, Coinkite outlined a migration process: generate a new seed on unaffected devices, verify backups and receiving addresses, send test transactions, and only then transfer remaining balances.
This unfolding situation shows the importance of firmware vigilance, especially for hardware wallets managing significant Bitcoin holdings. Whether this incident prompts enhanced security protocols remains to be seen.
This information is for educational purposes and does not constitute financial advice.



