Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Coldcard Advisory Ties 594 BTC Theft to a Flaw Found Only in Mk3

Coinkite's advisory scopes the risk to one hardware generation. A documented architecture change in later models may explain why, though the root cause is still under investigation.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
July 31, 2026
in Security & Hacks
0 0
Coldcard Advisory Ties 594 BTC Theft to a Flaw Found Only in Mk3

Designed by Magnific/Edited by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle
  • An attacker swept 500 Bitcoin addresses across four blocks on July 30, 2026, taking roughly 594.5 BTC (~$38M) in 15 minutes; 562 BTC sits unmoved on-chain as of this writing.
  • Coinkite’s advisory scopes the risk to Coldcard Mk3 devices on firmware 4.0.1–5.0.3 only. Mk4, Q, and Mk5 are stated as unaffected.
  • Mk3 relies on a single secure element (Microchip ATECC608A); Mk4/Q added a second, different-vendor chip specifically to hedge against single-vendor failure, a documented difference that may explain the model boundary, though Coinkite has not confirmed this as the root cause.
  • Affected users are advised to add a BIP-39 passphrase as an interim step or migrate to a new seed on unaffected hardware.
562 BTC Money Transferred
562 BTC Money Transferred

Coldcard, the Bitcoin-only hardware wallet made by Canadian manufacturer Coinkite, is at the center of one of the more surgical thefts recorded on the Bitcoin blockchain this year. In the early hours of July 30, 2026, an attacker swept 500 separate addresses across four consecutive blocks, pulling 1,324 UTXOs worth roughly 594.5 BTC, about $38 million at the time, into a single consolidation address within a 15-minute window. On-chain records confirm 562 BTC of that total sitting untouched at bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r as of this writing, with no further movement since the sweep.

COLDCARD Mk3 Security Advisory

If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk.

Mk4, Q and Mk5 are not affected based on our early analysis.

Read the advisory and migrate carefully:https://t.co/3vgPHOjMS7

— COLDCARD (@COLDCARDwallet) July 30, 2026

Hours later, Coinkite published an advisory limiting the risk to one specific model: Coldcard Mk3 devices that generated a seed on firmware 4.0.1 through 5.0.3. The company’s newer models, Mk4, Q, and Mk5, are, by its own account, unaffected. That narrower scope is the real story here, and it raises a question neither the theft itself nor Coinkite’s advisory has fully answered: why would a flaw in seed generation only show up on one generation of hardware?

Why the Damage Looks Confined to One Model

The addresses drained share a specific signature. Every one of the 1,324 stolen UTXOs came from single-signature wallets (none from taproot, none from multisig), and the affected keys dated back as far as 2021, according to on-chain tracing shared by Rob Hamilton, CEO of custody firm AnchorWatch, reviewed directly for this piece.

“At first glance, it appears there was faulty entropy in wallet generation somewhere along the way.” -Rob Hamilton, AnchorWatch

The available evidence identifies the affected model range, but it does not yet establish the exact cause of the failure. Coinkite has confirmed the Mk3 scope, while the underlying technical mechanism remains under investigation. Coinkite’s advisory draws the line at Mk3 has a hardware detail that doesn’t show up on the newer generation: it stores its seed material and generates entropy through a single secure element, the Microchip ATECC608A. That single-chip design has been part of Coldcard’s spec sheet since Mk3 launched in 2019.

One Chip vs. Two: What Changed After Mk3

Coinkite’s later hardware moved away from that single-chip model. The Mk4 and Q generation added a second secure element from a different vendor, Maxim’s DS28C36B, alongside the existing Microchip part, specifically so that a flaw discovered in one vendor’s chip wouldn’t compromise the device on its own. It’s a documented, deliberate design change, not a retroactive justification: Coinkite’s own architecture notes describe the second element as a hedge against single-vendor failure.

Model Secure element(s) Affected by this advisory?
Mk3 Single: Microchip ATECC608A Yes, firmware 4.0.1–5.0.3
Mk4 / Q Dual: Microchip ATECC608A + Maxim DS28C36B No, per Coinkite’s early analysis
Mk5 Dual (same architecture as Mk4/Q) No, per Coinkite’s early analysis

That gives the Mk3-only scope of this advisory a plausible technical anchor. If the entropy weakness Hamilton described traces back to the single ATECC608A’s random-number generation on Mk3, the dual-vendor design introduced with Mk4 would sidestep it by construction: two independent chips from two vendors are far less likely to share the same flaw. That is a real, sourced explanation for why the model line splits where it does.

It is not, however, a confirmed root cause. Coinkite has not published a technical post-mortem identifying what specifically went wrong in Mk3’s entropy generation, and its advisory explicitly describes the current guidance as “early analysis,” with a formal technical review still pending. The architecture difference explains why a Mk3-specific flaw is architecturally plausible; it does not yet explain what the flaw actually was.

What’s Confirmed, and What’s Still an Open Question

Blockchain records and Coinkite’s advisory confirm the scope of the incident, including the affected Mk3 firmware range from versions 4.0.1 through 5.0.3. What remains unclear is the exact mechanism that produced the weak seeds, whether the issue originated in the secure element itself or in firmware-level entropy handling, and whether all 500 affected addresses share the same root cause. Coinkite has not disclosed whether the weakness was exploited before this event or first surfaced through this theft. This incident lands amid broader, separate scrutiny of hardware wallets as a category: researcher ZachXBT recently criticized hardware wallets in general terms, though without pointing to any specific confirmed flaw of this kind.

Who Lost What

Victim losses, based on an on-chain breakdown reviewed for this piece but not independently reproduced address-by-address by us, show a wide spread rather than one large loss: a median of about 0.41 BTC per address (~$26,500), 110 addresses losing more than 1 BTC, and a largest single loss of 29.9 BTC. The same breakdown found one address had accumulated 200 separate UTXOs before the sweep and another 105, a pattern consistent with, though not confirmed as, automated or repeated deposits landing on the same address over time.

Community reaction escalated over several hours before Coinkite’s advisory landed. Kevin Loaec, co-founder of Bitcoin wallet developer Wizardsardine, first asked his followers with a Coldcard to check their balances, then followed up within the same window: “this is not a drill.” Bitcoin security researcher Jameson Lopp reported cases where only part of a wallet’s balance had been taken rather than the full amount, a single-source detail, not independently confirmed here, that if it holds up suggests whatever tool the attacker used didn’t always recover every key from every affected wallet.

Timeline

  • 01:36–01:51 UTC, Jul 30: 500 addresses swept across blocks 960188–960191; 562 BTC consolidated to a single address.
  • 13:19 UTC: First public report from an affected user.
  • 17:35 UTC: Kevin Loaec publicly requests Coldcard users check balances.
  • 18:10 UTC: NVK responds publicly, attributing it to a compromised/leaked seed, not a device-wide flaw.
  • Later, Jul 30: Coinkite publishes formal advisory scoping the issue to Mk3 firmware 4.0.1–5.0.3.

Coinkite’s Response, and How It Shifted

Coinkite founder and CEO Rodolfo Novak addressed the incident publicly before the company’s formal advisory went out, attributing it to individually compromised or leaked seeds rather than a device-wide flaw, and stating there was no evidence at that point of an issue with Coldcard’s random number generator. He later deleted that post and retracted it directly

“I don’t want wrong information out now that I have more updates, I don’t want people to be at risk. Blog incoming. That post is wrong.” Rodolfo Novak (NVK)

Kevin Loaec, replying in the same thread, added: “the amounts are in a weird narrow range too… could be entropy that isn’t fully broken, but just too weak. Many of the UTXOs are quite old.”

Coinkite’s formal advisory followed, acknowledging a possible RNG related flaw specific to Mk3 firmware. Affected users have two options: apply a strong, unique BIP-39 passphrase to an existing Mk3-generated seed as an interim measure, or migrate to a freshly generated seed on an unaffected Mk4, Q, or Mk5 device. An advanced dice-roll seed-generation option is also available for users staying on Mk3 hardware.

What Mk3 Holders Should Do Right Now

Anyone holding funds on a seed generated on a Coldcard Mk3 running firmware 4.0.1 through 5.0.3 has a concrete reason to act, regardless of how the root-cause investigation resolves. Coinkite’s own guidance is to treat a new BIP-39 passphrase as an interim safeguard and to plan a full migration to a seed generated on unaffected hardware, verifying every new receive address and sending a small test transaction before moving the remainder. The open question, whether the dual-secure-element design is the reason newer Coldcards weren’t touched, or simply one factor among others still under investigation, is one only Coinkite’s promised technical review can settle. Until then, the confirmed facts and the working explanation need to stay clearly marked as two different things.

AI Disclosure: Cryip uses AI-assisted tools to help refine language — correcting spelling and grammar and simplifying complex terms for readability.

We do this to make crypto topics easier to understand for readers at all experience levels. AI does not draft facts, sources, or conclusions. Every article is reviewed and approved by a human editor before publication. Read our full AI Use & Content Policy.

Disclaimer: Cryip’s content is strictly for informational purposes and does not constitute financial, legal, or investment advice. Asset references are not endorsements, and readers assume full responsibility for any financial decisions.
Tags: Crypto Hacks
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Drift Protocol Hacker Moves $44M in ETH to Tornado Cash After Three Months
Security & Hacks

Drift Exploiter Moves $44M in ETH Through Tornado Cash After Three Months of Inactivity

by Saravana Kumar Mahendran
July 24, 2026

Blockchain monitors flagged significant movement from a wallet tied to the April 2026 Drift Protocol exploit. After nearly three months...

Read moreDetails
Hackers Compromise Robinhood CEO Vlad Tenev’s X Account to Promote Unauthorized Memecoin

Hackers Compromise Robinhood CEO Vlad Tenev’s X Account to Promote Fake VLAD Token

July 24, 2026
Three Crypto Exploits Drain Over $35.5 Million in Hours as Verus, AFX, and B² Are Hit

Multiple Bridge Exploits Drain $35 Million Across Bitcoin and Ethereum Networks

July 23, 2026
VerusCoin Ethereum Bridge Exploited for $7.54 Million in Repeat Attack

VerusCoin Ethereum Bridge Exploited for $7.54 Million in Repeat Attack

July 23, 2026
SecondFi Shuts Down Following $2.6 Million ADA Security Breach

SecondFi Shuts Down Following $2.6 Million ADA Security Breach

July 22, 2026
Balance Coin Crashes 99% After $915K Exploit Hits 42DAO Protocol

Balance Coin Crashes 99% After $915K Exploit Hits 42DAO Protocol

July 22, 2026
Wanchain Cardano Bridge Loses 515M NIGHT Tokens in Exploit

Wanchain Cardano Bridge Loses 515M NIGHT Tokens in Exploit

July 21, 2026
Next Post
Strategy’s Bitcoin Sales Began a Month Before Its Q2 Earnings Call

Strategy's Bitcoin Sales Began a Month Before Its Q2 Earnings Call

Recommended

  • All
  • Crypto News Today
Coldcard Advisory Ties 594 BTC Theft to a Flaw Found Only in Mk3

Coldcard Advisory Ties 594 BTC Theft to a Flaw Found Only in Mk3

July 31, 2026
Can Samsung and Dunamu Build Stablecoin Infrastructure Before Korea Passes a Law?

Can Samsung and Dunamu Build Stablecoin Infrastructure Before Korea Passes a Law?

July 31, 2026
Photo by Zulfugar Karimov on Unsplash/Edited by Cryip

Australia’s eSafety Alleges Telegram Left 10 of 12 Reported Terror Posts Up

July 30, 2026

CZ Defends Giggle Academy’s Practice of Selling Donated Meme Coins

July 30, 2026
Ethereum Institutional's Funding Close Is the Third Backer-Aligned Move in Five Weeks

Ethereum Institutional’s Funding Close Is the Third Backer-Aligned Move in Five Weeks

July 30, 2026
Tether Signs Nairobi Securities Exchange MoU, Third African Continent Expansion Move in July

Tether Signs Nairobi Securities Exchange MoU, Third African Continent Expansion Move in July

July 29, 2026
CZ Backs ASEAN Crypto Passporting, But the Philippines’ Own Pilot Still Needed Two Licenses

CZ Backs ASEAN Crypto Passporting, But the Philippines’ Own Pilot Still Needed Two Licenses

July 28, 2026
Circle Becomes Largest U.S. Blockchain Patent Holder After IBM Deal

Circle Claims U.S. Blockchain Patent Lead With IBM Portfolio Acquisition

July 28, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Strategy’s Bitcoin Sales Began a Month Before Its Q2 Earnings Call
  • Coldcard Advisory Ties 594 BTC Theft to a Flaw Found Only in Mk3
  • Can Samsung and Dunamu Build Stablecoin Infrastructure Before Korea Passes a Law?

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.