Crypto加密$BTC

Coldcard issues Mk3 warning as $38M Bitcoin wallet drain draws expert scrutiny

Hardware wallet security is under examination across the Bitcoin custody sector. Coinkite, the maker of the Coldcard signing device, has urged all Mk3 model users to migrate their funds after identifying a potential risk in seed…

By Yuki Tanaka·July 31, 2026·二〇二六年七月三十一日·2 min read

Key takeaways

  • Coinkite, maker of the Coldcard signing device, has urged all Coldcard Mk3 users to migrate their funds after identifying a potential flaw in how the device generates seed phrases.
  • Because seed generation happens once at setup, a flaw would expose every address derived from it regardless of how carefully the device was handled afterward.
  • Bitcoin security experts are separately investigating an unexplained $38 million wallet drain that currently has no publicly attributed cause or named attack vector.
  • There is no confirmed link between the $38 million drain and Coinkite's Mk3 disclosure.
  • Coinkite's recommended migration requires generating a fresh wallet on a different device or model and moving BTC on-chain, which costs transaction fees and takes time.

Hardware wallet security is under examination across the Bitcoin custody sector. Coinkite, the maker of the Coldcard signing device, has urged all Mk3 model users to migrate their funds after identifying a potential risk in seed generation. Bitcoin security experts are separately investigating an unexplained $38 million wallet drain that has no publicly attributed cause.

What Coinkite identified on the Mk3

The affected product is the Coldcard Mk3. Coinkite's concern is a potential flaw in how the device generates seed phrases. A seed phrase is the master credential for a Bitcoin wallet: whoever can reproduce it controls the funds, completely and irreversibly. Coinkite's instruction to Mk3 holders is to move the funds to a different wallet.

Seed generation happens once, at setup. If that process carries a flaw, every address derived from it carries the same exposure, regardless of how securely the device has been handled since.

The $38 million drain, a separate thread

Security experts are examining a distinct event: an unexplained $38 million Bitcoin wallet drain. The source provides no confirmed link between that incident and Coinkite's disclosure. No attack vector has been publicly named.

These two developments arriving in the same news cycle will invite comparisons. Whether the drain is connected to any hardware wallet vulnerability is a question the current record does not answer.

The read-through for self-custody

Against the backdrop of continuing questions about centralized custody risk, hardware wallets carry a specific promise: the user controls the seed, so the user controls the funds. A disclosed seed-generation flaw from a named product cuts at that premise.

For Mk3 users, the migration Coinkite recommends means generating a fresh wallet on a different device or model, then broadcasting transactions to move $BTC on-chain. That process costs transaction fees and takes time. It also requires users to trust that the destination wallet does not carry the same kind of flaw.

The question of whether similar risks exist sector-wide, across hardware wallet models, is now in the air. Coinkite's advisory names the Mk3 specifically. The $38 million drain remains under expert examination with no confirmed cause.

Related reading

Source · 來源

cointelegraph.com

Share · 分享

Frequently asked

Which Coldcard model is affected by Coinkite's warning?

The warning specifically names the Coldcard Mk3, citing a potential flaw in how the device generates seed phrases.

What does Coinkite recommend Mk3 users do?

Coinkite recommends Mk3 holders move their funds by generating a fresh wallet on a different device or model and broadcasting on-chain transactions to transfer their BTC.

Is the $38 million wallet drain linked to the Coldcard Mk3 flaw?

No confirmed link has been established; the source provides no attributed cause for the drain and no publicly named attack vector.

Why is a seed-generation flaw considered serious?

A seed phrase is the master credential for a Bitcoin wallet, so anyone who can reproduce it controls the funds completely and irreversibly, and a generation flaw affects every derived address.

Does the migration Coinkite recommends have any downsides?

Yes, it costs transaction fees and takes time, and it requires users to trust that the destination wallet does not carry the same kind of flaw.