Bitcoin hardware wallet maker Coinkite has warned users about a seed-generation issue affecting Coldcard devices, including every Mk3 firmware version from 4.0.1 onward. The warning emerged as security researchers investigated a coordinated sweep of 594.48 BTC, worth roughly $38 million. However, no public technical evidence has confirmed that the Coldcard issue caused the transfers.Bitcoin hardware wallet maker Coinkite has warned users about a seed-generation issue affecting Coldcard devices, including every Mk3 firmware version from 4.0.1 onward. The warning emerged as security researchers investigated a coordinated sweep of 594.48 BTC, worth roughly $38 million. However, no public technical evidence has confirmed that the Coldcard issue caused the transfers.

Coldcard Mk3 Warning Follows $38M Bitcoin Sweep, but Cause Remains Unconfirmed

2026/07/31 18:00
4 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo [email protected].
Notizie in breve
Bitcoin hardware wallet maker Coinkite has warned users about a seed-generation issue affecting Coldcard devices, including every Mk3 firmware version from 4.0.1 onward. The warning emerged as security researchers investigated a coordinated sweep of 594.48 BTC, worth roughly $38 million. However, no public technical evidence has confirmed that the Coldcard issue caused the transfers.

Why Did Coinkite Issue the Coldcard Warning?

Coinkite published a Coldcard security advisory on July 30, warning users whose wallet seeds were generated on affected firmware to move their funds to a newly generated seed.

The issue affects every Coldcard Mk3 firmware version from 4.0.1 onward. The company’s current advisory also covers seeds generated on Mk4 and Mk5 devices before firmware version 5.6.0, as well as Q devices before version 1.5.0Q.

For the affected Mk4, Mk5 and Q versions, Coinkite said the generated seeds contained approximately 72 bits of entropy instead of the expected 128 bits. Entropy refers to the randomness used when generating a wallet seed. Lower entropy can reduce the number of possible seed combinations and potentially make affected wallets easier to attack.

Coinkite said its investigation remains ongoing and that a formal technical review will be published later.

What Happened in the 594 BTC Wallet Sweep?

The warning appeared as Bitcoin security researchers examined an unexplained sweep involving 594.48 BTC from single-signature addresses.

According to a Cointelegraph report on the Bitcoin wallet drain, 1,324 unspent transaction outputs were swept through 500 transactions within a three-block window. Around 562 BTC was subsequently consolidated into another address.

Researchers have suggested that weak randomness during wallet generation could be one possible explanation. However, this remains a hypothesis. No public report has demonstrated how the affected private keys were generated, which device or software created them, or whether the Coldcard seed-generation issue was involved.

The Coldcard warning and the 594 BTC sweep should therefore be treated as related in timing, but not yet proven to share the same cause. A separate crypto.news investigation reached the same conclusion.

What Should Affected Coldcard Users Do?

Coinkite advises affected users to generate a new seed on a device running fixed firmware, record and verify the new backup, and confirm the receiving address directly on the hardware wallet screen.

Users should first send a small test transaction and confirm that the new wallet works before transferring the remaining balance. The old seed backup should be retained until the entire migration has been completed and verified.

A strong and unique BIP-39 passphrase can add an independent layer of protection, but it is different from the Coldcard device PIN. Coinkite still recommends migrating to a newly generated seed even when a passphrase was used.

Users should never enter wallet seed words or passphrases into a website, online form or untrusted device. Rushing an emergency migration may also create additional risks, including sending funds to an incorrectly recorded address.

Does This Mean Bitcoin Was Hacked?

The available evidence does not indicate a failure of Bitcoin’s blockchain, consensus rules or cryptographic protocol.

The investigation instead concerns how individual wallet software or hardware generated private keys. Bitcoin can continue processing valid transactions even when a user’s private key is exposed or generated with insufficient randomness.

The incident nevertheless raises broader questions about Bitcoin self-custody standards. Wallet providers may face greater pressure to disclose their entropy sources, audit seed-generation code, provide reproducible firmware builds and publish clearer affected-version guidance when vulnerabilities are discovered.

For users holding meaningful balances, stronger passphrases, carefully designed multisignature arrangements and clear recovery procedures may reduce dependence on a single device or key-generation process. The objective is not to make self-custody more complicated, but to make critical security assumptions easier to understand and verify.

Follow Bitcoin Markets on MEXC

The wallet investigation is a custody-security event and does not by itself establish a failure of Bitcoin’s underlying network or predict a specific BTC price direction.

Market participants can follow the live Bitcoin price and market data, access the BTC/USDT spot market, or explore BTCUSDT perpetual futures on MEXC.

Spot trading provides direct BTC market exposure on the platform, while perpetual futures allow users to take long or short positions without holding Bitcoin directly. Futures involve leverage, liquidation and funding-rate risks and may not be suitable for inexperienced users. Trading through an exchange also does not replace an independent self-custody and wallet-backup plan.

Conclusion

The Coldcard advisory shows how a wallet seed-generation issue can create serious risks even when the Bitcoin network continues operating normally.

For now, the 594.48 BTC sweep remains unexplained, and its connection to Coldcard has not been established. The immediate priority is for affected users to follow the official migration guidance carefully. The longer-term question is whether wallet makers and the wider Bitcoin ecosystem will adopt stronger standards for entropy transparency, security audits and emergency migration procedures.

Gli articoli scritti dal team editoriale di Notizie MEXC hanno esclusivamente scopo informativo generale e non costituiscono consulenza finanziaria, di investimento o di trading. I mercati delle criptovalute sono altamente volatili, ti preghiamo di condurre le tue ricerche e verificare in modo indipendente le informazioni prima di prendere decisioni finanziarie. Redatti in conformità con la nostra Politica editoriale, MEXC non si assume alcuna passività per le perdite subite facendo affidamento su questi contenuti. Per segnalare violazioni del copyright o dei diritti di terzi, contatta [email protected].

Potrebbe anche piacerti

SEC Innovation Exemption: How Tokenized Stocks Can Trade Onchain

SEC Innovation Exemption: How Tokenized Stocks Can Trade Onchain

The U.S. Securities and Exchange Commission introduced a five-year Innovation Exemption on September 17, 2026, creating a temporary regulatory pathway for certain tokenized U.S. stocks to trade onchain. Under the framework, qualifying Tokenized Securities Venues can facilitate trading in tokenized National Market System stocks through permissioned automated market makers and liquidity pools without being treated as registered exchanges under the usual definition, provided they comply with a detailed set of conditions. Liquidity providers participating in those pools can also receive limited conditional relief from the statutory definition of a dealer
Condividi
MEXC NEWS2026/09/18 14:04
U.S. Stock Perps Are Coming: Why Kalshi and Coinbase Want In

U.S. Stock Perps Are Coming: Why Kalshi and Coinbase Want In

The U.S. derivatives market may be approaching an important structural shift as Kalshi and Coinbase Derivatives both move to introduce perpetual futures linked to individual U.S. stocks. The proposals matter because perpetual futures are no longer being treated only as a crypto-native trading product. Instead, two major U.S. platforms are attempting to adapt the format to equities such as Apple, Nvidia and Tesla, potentially bringing continuous leveraged stock-price exposure into a regulated domestic market.
Condividi
MEXC NEWS2026/09/21 13:19
Nvidia FY2027 Q2 Earnings Date: Expected Report Time, Earnings Call, and AI Revenue Watchlist

Nvidia FY2027 Q2 Earnings Date: Expected Report Time, Earnings Call, and AI Revenue Watchlist

Nvidia’s fiscal Q2 2027 earnings are expected to become one of the most important AI market events of the summer. Wall Street Horizon lists Nvidia’s next earnings date as Wednesday, August 26, 2026, after market close, for Q2 fiscal 2027. This is not just another earnings date. Nvidia’s own Q1 FY2027 outlook set the bar extremely high: the company guided for $91.0 billion in Q2 revenue, plus or minus 2%, with a non-GAAP gross margin expected at about 75.0%. Nvidia also explicitly noted that its outlook assumes no Data Center compute revenue from China, making the coming report a much cleaner test of non-China AI infrastructure demand. For traders, the key question is no longer simply whether Nvidia beats expectations. The bigger issue is whether the company can consistently convert AI demand into revenue growth, margin durability, and forward guidance strong enough to defend the market’s AI infrastructure premium.
Condividi
MEXC NEWS2026/07/06 18:17