Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Hackers Steal $38 Million in Bitcoin from Over 500 Coldcard Mk3 Wallets

Hackers Steal $38 Million in Bitcoin from Over 500 Coldcard Mk3 Wallets

By: Jordan Vector Cybersecurity Expert

Last updated: July 31, 2026

Human Written
Hackers Steal $38 Million in Bitcoin from Over 500 Coldcard Mk3 Wallets
  • Around 594 BTC, worth about $38 million, has reportedly been taken from more than 500 Coldcard Mk3 wallets.

  • Coinkite warned users who created seeds on affected Coldcard Mk3 firmware that their funds may face risk.

  • Researchers linked the incident to a possible weakness in seed randomness, but the full cause remains under investigation.

A security incident involving Coldcard Mk3 hardware wallets has reportedly drained around 594 Bitcoin from hundreds of wallets. The stolen coins are worth about $38 million, according to Decrypt’s report on the incident.

The incident has led Coldcard maker Coinkite to warn users who may have created wallet seeds with affected firmware. The company has urged potentially exposed users to take steps to protect their funds.

The affected wallets reportedly stayed inactive for long periods before attackers moved the Bitcoin. The reported activity involved more than 500 wallets, according to coverage of the incident. The main concern centers on how some wallet seeds were created.

A seed phrase acts as the starting point for creating the private keys that control Bitcoin funds. If the random data used to create a seed is weak, attackers may have a better chance of finding the keys linked to that seed.

The Crypto Times reported that Coinkite issued an urgent security warning after hundreds of wallets showed signs of being drained. The warning focused on seeds created with certain Coldcard Mk3 firmware.

Possible Firmware Weakness Linked to Seed Generation

Early technical reports have linked the incident to a problem with entropy, which means the randomness used when creating new wallet seeds. Litchwire reported that the suspected problem may trace back to a firmware change made in 2021.

The report said a configuration mistake may have affected a part of the system responsible for creating random numbers. Attackers are using diverse methods to steal crypto, from exploiting firmware weaknesses to using fake Zoom links to trick victims.

However, researchers have not yet established the exact way the flaw worked. They also have not fully explained how an attacker found and used the weakness. The reported issue appears to involve some single-signature wallets. These wallets may have been created without extra protections, such as a BIP-39 passphrase or a multisignature setup.

Community discussions referencing Coinkite’s advisory said users who created seeds with affected Mk3 firmware should take precautions. Users who added extra security measures may face different risks, according to the discussions.

The incident also highlights an important point about firmware updates. Updating a Coldcard device does not automatically make an old seed safe if the seed itself was created using weak randomness.

Coldcard’s official documentation explains that the seed forms the base for the Bitcoin wallets created by the device. The company’s documentation also explains how BIP-39 passphrases can create additional wallets from the same seed.

Coinkite Warns Users to Protect Their Funds

Users who believe their wallets may be affected have been advised to follow Coinkite’s official security guidance. Security reports have also urged potentially exposed users to move their funds to a newly created wallet.

Cryptopolitan reported that affected users should secure their funds and respond to the warning. The report also stressed the need for users to take the possible exposure seriously.

The reported theft involves a large number of Bitcoin wallets. The funds also moved after some wallets had remained inactive, according to reports about the incident. The full technical investigation is still ongoing.

Reports have pointed to weak randomness as a possible cause, but the precise details remain unclear. The available reports also do not establish that every Coldcard Mk3 wallet faces the same risk. The concern mainly involves wallets created through potentially affected seed-generation processes.

Users should therefore check Coinkite’s official guidance to determine whether their wallets fall within the affected group. They should avoid relying on unconfirmed claims when deciding what action to take.

Security Concerns Grow After Reported Wallet Drains

The incident shows how software problems can affect hardware wallets. These devices aim to protect private keys, but their security still depends on the processes used to create and manage those keys.

A weakness in seed generation can create serious problems because the seed controls access to the wallet. If someone can reproduce or predict the data behind a seed, they may be able to access funds linked to it. The reported Coldcard incident has already involved around 594 BTC. That amount makes the case significant for users who may have created seeds with affected Mk3 firmware.

Coldcard users should follow official updates from Coinkite as the investigation continues. They should also be careful with messages that claim to offer help with the incident. Users should never share their seed phrases or private keys with anyone claiming to provide security support.

The reports provided do not say that such scams are taking place, but users should rely on official Coinkite guidance when checking their wallets or deciding what action to take.

Share this article

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.