Polylog
The Polylog Crypto Intelligence Brief

Morning Edition · Friday, July 31, 2026Published at 1:29 AM EDT · New York

Coldcard Mk3 Owners Told to Move Coins After 594 Bitcoin Swept From Dormant Wallets

Analysts trace the roughly $38 million drain to faulty randomness in seed generation, which turned supposedly unguessable private keys into guessable ones.

Coldcard Mk3 Owners Told to Move Coins After 594 Bitcoin Swept From Dormant Wallets

On July 30, roughly 594 bitcoin, worth about $38 million, moved out of approximately 500 single-signature addresses within about 25 minutes, draining some 1,324 unspent outputs across a three-block window. Many of the drained coins had not moved since 2021. The pattern points not to a stolen password or a phishing attempt but to a flaw in how the keys were created.

Coinkite, the maker of the Coldcard hardware wallet, issued a warning to owners of its older Mk3 device running firmware versions 4.0.1 through 5.0.3, saying seeds generated on those units may be at risk from a flaw in the device's random-number generator. On-chain investigators reached the same early conclusion, that faulty entropy in wallet generation is the most likely root cause. When the randomness that seeds a private key is predictable, an attacker can regenerate the key space and reconstruct addresses that their owners believed were mathematically impossible to guess.

The attack vector here is cryptographic, not a smart-contract bug and not a server breach. Because the coins were self-custodied bitcoin moving in valid signed transactions, no protocol or exchange can freeze or reverse them, and none of the funds have been recovered or attributed. Coinkite says its newer Mk4, Q and Mk5 devices are not affected, and that wallets protected by a separate optional passphrase (a BIP-39 passphrase) face minimal risk. Developers on Bitcoin's technical forums are still examining whether every drained wallet shares the Mk3 as a common origin, so the link between the specific firmware warning and the full sweep remains probable rather than proven.

Veracity: Corroborated
81/100
If true, who benefits

Coinkite competitors and passphrase-first custody advocates, plus the narrative that self-custody's real weak point is entropy at seed creation, not exchanges.

The nuance

The 594-bitcoin sweep is firmly documented, but the load-bearing link to the Mk3 random-number generator is a preliminary analyst conclusion, and no public on-chain evidence yet proves every drained wallet shares that device as its origin.

An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.

What this means

The loss falls on long-term self-custodial holders, the population most confident that hardware wallets removed counterparty risk. The mechanism is the weakest assumption in all of self-custody, that the device generated true randomness. If a single hardware generation produced guessable seeds, the exposure sits in dormant coins that owners rarely touch and therefore rarely migrate, which is why 2021-era addresses were drained first. It also intensifies a debate custodians are already having about post-quantum key risk, since both threats end the same way, with keys that were assumed unbreakable becoming reconstructable.

What to watch

  • Whether forensic teams confirm the Coldcard Mk3 as the single common source or find drained wallets from other devices, which would widen the affected population beyond one firmware line.
  • Movement of the stolen 594 bitcoin toward mixers or exchanges, which would show whether the attacker can cash out or gets frozen at fiat off-ramps.

Observations to monitor, not financial advice.

3 sources

Synthesized from: CoinDesk · crypto.news · Bitcointalk

Part of a tracked trend

Quantum Risk Moves From Theory to Crypto Roadmaps

Over the next 3-6 months, quantum-resistance becomes a concrete design and custody concern across major chains and institutional custodians, driving opt-in post-quantum schemes and 'long-dormant coin' risk discussion.