Morning Edition · Friday, July 31, 2026Published at 1:29 AM EDT · New York
Coldcard Mk3 Owners Told to Move Coins After 594 Bitcoin Swept From Dormant Wallets
Analysts trace the roughly $38 million drain to faulty randomness in seed generation, which turned supposedly unguessable private keys into guessable ones.

On July 30, roughly 594 bitcoin, worth about $38 million, moved out of approximately 500 single-signature addresses within about 25 minutes, draining some 1,324 unspent outputs across a three-block window. Many of the drained coins had not moved since 2021. The pattern points not to a stolen password or a phishing attempt but to a flaw in how the keys were created.
Coinkite, the maker of the Coldcard hardware wallet, issued a warning to owners of its older Mk3 device running firmware versions 4.0.1 through 5.0.3, saying seeds generated on those units may be at risk from a flaw in the device's random-number generator. On-chain investigators reached the same early conclusion, that faulty entropy in wallet generation is the most likely root cause. When the randomness that seeds a private key is predictable, an attacker can regenerate the key space and reconstruct addresses that their owners believed were mathematically impossible to guess.
The attack vector here is cryptographic, not a smart-contract bug and not a server breach. Because the coins were self-custodied bitcoin moving in valid signed transactions, no protocol or exchange can freeze or reverse them, and none of the funds have been recovered or attributed. Coinkite says its newer Mk4, Q and Mk5 devices are not affected, and that wallets protected by a separate optional passphrase (a BIP-39 passphrase) face minimal risk. Developers on Bitcoin's technical forums are still examining whether every drained wallet shares the Mk3 as a common origin, so the link between the specific firmware warning and the full sweep remains probable rather than proven.
- If true, who benefits
Coinkite competitors and passphrase-first custody advocates, plus the narrative that self-custody's real weak point is entropy at seed creation, not exchanges.
- The nuance
The 594-bitcoin sweep is firmly documented, but the load-bearing link to the Mk3 random-number generator is a preliminary analyst conclusion, and no public on-chain evidence yet proves every drained wallet shares that device as its origin.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The loss falls on long-term self-custodial holders, the population most confident that hardware wallets removed counterparty risk. The mechanism is the weakest assumption in all of self-custody, that the device generated true randomness. If a single hardware generation produced guessable seeds, the exposure sits in dormant coins that owners rarely touch and therefore rarely migrate, which is why 2021-era addresses were drained first. It also intensifies a debate custodians are already having about post-quantum key risk, since both threats end the same way, with keys that were assumed unbreakable becoming reconstructable.
What to watch
- Whether forensic teams confirm the Coldcard Mk3 as the single common source or find drained wallets from other devices, which would widen the affected population beyond one firmware line.
- Movement of the stolen 594 bitcoin toward mixers or exchanges, which would show whether the attacker can cash out or gets frozen at fiat off-ramps.
Observations to monitor, not financial advice.
Synthesized from: CoinDesk · crypto.news · Bitcointalk
Part of a tracked trend
Quantum Risk Moves From Theory to Crypto Roadmaps
Over the next 3-6 months, quantum-resistance becomes a concrete design and custody concern across major chains and institutional custodians, driving opt-in post-quantum schemes and 'long-dormant coin' risk discussion.
More from this edition
- BIS Moves Real Central-Bank and Commercial-Bank Money On-Chain in 28-Lender Payments Test
- CLARITY Act Heads Toward August Recess Without the Votes to Pass
- Strategy Books $8.22 Billion Quarterly Loss as Bitcoin Falls Below Its Cost Basis
- Privacy Layer-2s Push Confidential Smart Contracts Onto Ethereum as Aztec and Miden Ship
- Aave Proposes to Shut Deployments on Six Chains That Earn Almost No Revenue
- Blockstream's Simplicity Goes Live on Liquid Mainnet With Post-Quantum Signatures
- DeFi Total Value Locked Fell $43.4 Billion in the First Half of 2026, Binance Research Says
- DeFi Exploit Drains Roughly $578,000 as Seoul Police Break Up $19 Million Staking Fraud
- Coinbase Falls After Posting a Second-Quarter Loss and Lower Revenue
- US Sanctions Iranian Firms Accused of Taking Bitcoin for Strait of Hormuz Passage
- Bitchat Mesh App Keeps Running in India After a Cybercrime Notice, Spreading Peer to Peer