# Coldcard Mk3 Owners Told to Move Coins After 594 Bitcoin Swept From Dormant Wallets

Analysts trace the roughly $38 million drain to faulty randomness in seed generation, which turned supposedly unguessable private keys into guessable ones.

- Published: 2026-07-31T05:29:19.625Z
- Canonical: https://polylog.news/crypto/2026-07-31/coldcard-mk3-owners-told-to-move-coins-after-594-bitcoin-swe
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [CoinDesk](https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep), [crypto.news](https://crypto.news/coldcard-mk3-warning-follows-38m-bitcoin-drain/), [Bitcointalk](https://bitcointalk.org/index.php?topic=5589945.0)

On July 30, roughly 594 bitcoin, worth about $38 million, moved out of approximately 500 single-signature addresses within about 25 minutes, draining some 1,324 unspent outputs across a three-block window. Many of the drained coins had not moved since 2021. The pattern points not to a stolen password or a phishing attempt but to a flaw in how the keys were created.

Coinkite, the maker of the Coldcard hardware wallet, [issued a warning](https://crypto.news/coldcard-mk3-warning-follows-38m-bitcoin-drain/) to owners of its older Mk3 device running firmware versions 4.0.1 through 5.0.3, saying seeds generated on those units may be at risk from a flaw in the device's random-number generator. On-chain investigators reached the same early conclusion, that [faulty entropy in wallet generation](https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep) is the most likely root cause. When the randomness that seeds a private key is predictable, an attacker can regenerate the key space and reconstruct addresses that their owners believed were mathematically impossible to guess.

The attack vector here is cryptographic, not a smart-contract bug and not a server breach. Because the coins were self-custodied bitcoin moving in valid signed transactions, no protocol or exchange can freeze or reverse them, and none of the funds have been recovered or attributed. Coinkite says its newer Mk4, Q and Mk5 devices are not affected, and that wallets protected by a separate optional passphrase (a BIP-39 passphrase) face minimal risk. Developers on Bitcoin's technical forums are [still examining](https://bitcointalk.org/index.php?topic=5589945.0) whether every drained wallet shares the Mk3 as a common origin, so the link between the specific firmware warning and the full sweep remains probable rather than proven.

## What this means

The loss falls on long-term self-custodial holders, the population most confident that hardware wallets removed counterparty risk. The mechanism is the weakest assumption in all of self-custody, that the device generated true randomness. If a single hardware generation produced guessable seeds, the exposure sits in dormant coins that owners rarely touch and therefore rarely migrate, which is why 2021-era addresses were drained first. It also intensifies a debate custodians are already having about post-quantum key risk, since both threats end the same way, with keys that were assumed unbreakable becoming reconstructable.

## What to watch

- Whether forensic teams confirm the Coldcard Mk3 as the single common source or find drained wallets from other devices, which would widen the affected population beyond one firmware line.
- Movement of the stolen 594 bitcoin toward mixers or exchanges, which would show whether the attacker can cash out or gets frozen at fiat off-ramps.
