White Coinkite company name displayed on a bright orange background Image
SECURITY

Coinkite Warns Coldcard Users After Reports of 594 BTC Theft

Image Credit: Coinkite.com

Bitcoin hardware wallet maker Coinkite has warned Coldcard users to move funds from wallets created with affected firmware. The warning follows reports that about 594.5 BTC, worth roughly $38 million, was drained from 500 addresses.

The company has not confirmed that the firmware issue caused the reported theft. Its investigation remains ongoing, and Coinkite said more technical details will follow.

Coinkite Tells Users to Create New Seeds

Coinkite said updating an affected device is not enough because a firmware update cannot repair a seed that has already been generated. Users should create a new seed on a device running fixed firmware, verify a new receiving address, and first send a small test transaction. The company said:

 “Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 or any subsequent version that their funds may be at risk.”

Coinkite advised users to move the remaining balance only after confirming that the replacement wallet works. It also warned that rushing the process could create a separate risk of losing access to funds.

Reports Link 594 BTC Transfer to 500 Wallets 

About 594.5 BTC was reportedly moved from 500 single-signature addresses in a coordinated series of transactions. The transfers were recorded across several Bitcoin blocks. Much of the Bitcoin was later moved into one address.

Researchers said the activity may be linked to seeds created with weak randomness. However, Coinkite has not confirmed that every affected address came from a Coldcard wallet.

The risk depends on which firmware version was used to create the original seed. It does not depend on when the device was purchased.

Other Coldcard Models Also Need Updates

Coinkite’s latest advisory says the issue is not limited to the Mk3. Seeds created on Mk4 and Mk5 devices before firmware 5.6.0 may also be impacted. The same applies to Coldcard Q devices running versions before 1.5.0Q, although Coinkite said the issue is less serious on those models.

Users who added enough private dice rolls when creating a seed may have additional protection. A strong and unique BIP-39 passphrase can also make a wallet harder to access. Even so, Coinkite recommends moving funds to a wallet with a newly generated seed as soon as possible. Until the investigation is complete, affected users should treat old seeds as unsafe and avoid using them again.

More For You

Payward Buys Magic Labs Wallet
BUSINESS

Payward Buys Magic Labs Wallet

Payward has acquired Magic Labs' wallet business, expanding its digital asset infrastructure and strengthening…

Jul 29, 2026 3 min read
Explore More News