Various electronic components and tools on a
Crypto

Coinkite warns Coldcard Mk3 users to migrate funds over seed-generation risk

The alert hit as investigators analyzed a tightly timed 594.48 BTC sweep from single-sig wallets with no proven link.

By AI News Crypto Editorial Team5 min read

Coinkite told Coldcard Mk3 users to move funds after flagging a potential seed-generation risk tied to Mk3 firmware v4.0.1 through v5.0.3. The warning arrived as security researchers dissected an unexplained 594.48 BTC sweep from single-signature addresses, with no definitive public evidence connecting the two events.

Key Takeaways

  • Seeds generated on Coldcard Mk3 devices running firmware v4.0.1 through v5.0.3 were flagged by Coinkite as potentially putting funds at risk, prompting a migration advisory.
  • Coinkite’s early assessment said Coldcard Mk4, Q, and Mk5 devices are not affected, narrowing the risk window to Mk3 hardware and its final firmware line.
  • A coordinated sweep moved 594.48 BTC (about $38.3 million at $64,364.07 per CoinGecko) from single-signature addresses over a short time window.
  • Preliminary on-chain breakdowns described 1,324 UTXOs swept via 500 transactions within three blocks, with 562 BTC later consolidated into another address.

Coinkite Flags a Coldcard Mk3 Seed-Generation Risk

Coinkite issued a warning to Coldcard Mk3 users after identifying a potential risk tied to how some wallet seeds were generated on specific Mk3 firmware versions. The company said seeds created on an Mk3 running firmware v4.0.1, released in March 2021, or any later Mk3 version may put funds at risk.

Coinkite framed the finding as an “early analysis” and said the issue extends through v5.0.3, the final firmware supporting the Mk3. In the same update, the company said Mk4, Q, and Mk5 devices are not affected based on its current assessment.

For operators, that scope matters more than the speculation. The actionable edge is operational: a defined firmware window, a defined device family, and a clear instruction to rotate away from seeds generated inside that window until the technical review lands.

The Migration Playbook Coinkite Told Users to Follow

Coinkite’s guidance was explicit and process-driven. “Out of an abundance of caution,” the company urged affected users to generate a new seed on an unaffected device, verify the backup and receive address, send a small test transaction, and only then move the remaining funds.

The warning also drew a line between a BIP-39 passphrase and a device PIN. Coinkite said its early analysis indicates affected seeds used with a BIP-39 passphrase face “minimal risk,” emphasizing that the passphrase is an additional secret layered on top of the seed phrase, not the Coldcard PIN.

The practical takeaway is that this is a rotation workflow, not a firmware-update story. If the seed is the root of trust, the mitigation is to replace it and validate the new receive path with a test spend before migrating size.

Inside the 594.48 BTC Sweep: Three Blocks, 500 Transactions, 1,324 UTXOs

In parallel, Bitcoin security specialists examined an unexplained sweep totaling 594.48 BTC from single-signature addresses. AnchorWatch CEO and co-founder Rob Hamilton posted a preliminary analysis describing 1,324 UTXOs swept across 500 transactions within a three-block window.

At the time of writing, 594.48 BTC was valued at about $38.3 million using a BTC price of $64,364.07, according to CoinGecko data. Hamilton said all involved addresses were single-signature and that 562 BTC was later consolidated into another address.

The compression into three blocks and the high UTXO and transaction counts make the event read more like an automated, coordinated drain than discretionary manual movement. That said, the public record still does not establish that the sweep originated from the Coldcard Mk3 seed issue.

Hamilton’s initial hypothesis pointed at seed quality: “At a glance, this looks like there was flawed entropy in wallet generation somewhere along the way,” he wrote, suggesting weak randomness during seed creation as a plausible mechanism.

Signals to Monitor as the Investigation Develops

The next hard catalyst is Coinkite’s promised formal technical review. Any update that changes the affected firmware range (v4.0.1–v5.0.3) or revises the “not affected” status of Mk4/Q/Mk5 would immediately reprice operational risk for self-custody setups.

On-chain, the 562 BTC consolidation address is the obvious tripwire. Further movement from that cluster, or additional sweeps showing the same three-block timing and high UTXO density, would strengthen the case for a repeatable playbook rather than a one-off.

The key unresolved question remains linkage. New public evidence that ties the Mk3 seed-generation issue to the 594.48 BTC transfers, or credibly rules it out, is what would convert this from a broad risk-management alert into a specific incident attribution.

What This Means for Self-Custody Risk Right Now

I treat this as two overlapping signals with one shared implication: rotate risk out of the known window. Coinkite has drawn a bright line around Mk3 seeds generated on v4.0.1 through v5.0.3 and provided a conservative migration workflow. That is the only part traders and operators can act on with high confidence today.

The 594.48 BTC sweep looks like a machine-driven drain based on its three-block compression and UTXO counts, but the market should resist forcing a single narrative until the technical review and stronger attribution evidence arrive. The threshold that matters is whether the investigation produces a reproducible mechanism that expands beyond Mk3 seeds in that firmware range, because that is what would turn this from a contained operational cleanup into a broader self-custody repricing event.

Sources