Coinkite issued a security advisory Thursday warning owners of its Coldcard Mk3 hardware wallet that funds tied to certain firmware versions may be at risk.
Key Takeaways
Coinkite issued a security advisory for Coldcard Mk3 users on July 30, 2026.Reports show about 594 BTC, near $38 million, left roughly 500 dormant wallets.Coinkite’s advisory covers Mk3 firmware 4.0.1 through 5.0.3, its final supported release.Coinkite described the advisory as reflecting early findings, and said a formal technical review will follow as the investigation continues. Community researchers have been reviewing onchain activity tied to the reports. Discussion has centered on the possibility of weak randomness in seed generation on certain older Mk2 and Mk3 firmware versions, rather than a supply chain compromise. At the time of publication, Coinkite has not confirmed a root cause.
Passphrase Users Face Lower RiskAccording to the advisory, wallets protected with a BIP-39 passphrase, a user-added phrase distinct from the device PIN, appear to carry minimal risk under Coinkite’s early analysis. The company advised passphrase users to keep protecting that phrase and avoid entering it on untrusted devices or websites.
Interim OptionsCoinkite outlined two interim steps for owners whose Mk3 is their only device:
Add a strong, unique BIP-39 passphrase and move funds to the newly protected wallet. Generate a replacement seed using the Mk3’s dice-roll import path, which does not rely on the device’s random number generator, though Coinkite described this as an advanced procedure requiring careful verification.Coinkite published full technical steps in its advisory, available on the company’s blog. The company explained its investigation is ongoing and that additional details will follow. Coldcard has built a reputation as a security-focused, air-gapped hardware wallet option since its release, and the reports have drawn wide attention across the Bitcoin community as owners assess their own devices.


















