Bitcoin

594 BTC disappear in 15 minutes: Coldcard users among the victims of the coordinated attack

By Kim03 | Kim Blog News | 3 hours ago


A coordinated attack drained approximately 594 BTC (US$37–40 million) from roughly 500 different addresses in just 15 minutes this Thursday (30) — all single-signature , many inactive for years, none with Taproot. Hours later, Coinkite officially confirmed a flaw in the seed generation of the COLDCARD Mk3 , affecting seeds created from firmware 4.0.1 (March 2021). The Mk4, Q, and Mk5 models are not affected , and the use of the BIP-39 passphrase reduces the risk to a minimum. The link between the flaw and the theft is likely, but has not yet been confirmed by the manufacturer.

 

What happened this Thursday (30)

The Bitcoin community was surprised on Thursday morning (30) by one of the most unusual episodes in recent years: a coordinated attack drained around 594 BTC — between US$37 and US$40 million at the current exchange rate — from approximately 500 different addresses , in a window of just 15 minutes , according to a survey published by the Livecoins portal.

What makes this case atypical is not just the amount, but the pattern . The funds were distributed across 1,324 UTXOs (unspent transaction outputs), many of which had been inactive for years . All the addresses hit were single-signature —protected by a single private key—and none used Taproot . This is not a one-off attack against a single victim: it is a simultaneous sweep of hundreds of seemingly unrelated wallets, with a coordinated destination—the classic signature of an attacker who already possessed the private keys , or the ability to derive them.

Reports from victims began to accumulate on Reddit and X , and—drawing enormous attention—many were from users of Coldcard wallets , the Bitcoin-only hardware wallet manufactured by the Canadian company Coinkite. Well-known names in international security, such as Jameson Lopp (Casa), developer James O'Beirne , Kevin Loaec (Wizardsardine), and Rob Hamilton (AnchorWatch), as well as Brazilian profiles, began to publicly analyze the on-chain pattern of the attack.

Immediate warning: incidents like this attract scammers offering "verification" or "recovery" of funds. Never enter your recovery phrase (seed) on any website, app, form, or message —not even to "check if you've been affected." No legitimate verifier asks for a seed, private key, or signature.  

Coinkite confirms bug in Mk3 seed generation.

Hours after the initial movements, the most important confirmation came — and from the strongest possible source. Coinkite itself published an official security statement on its blog, warning, “out of an abundance of caution,” all users who generated a seed on a COLDCARD Mk3 running firmware version 4.0.1 (March 2021) or any later version that their funds may be at risk .

The main points of the statement:

  • The problem persists up to firmware version 5.0.3 , the last one that supported the Mk3.
  • According to the company's preliminary analysis, the Mk4, Q, and Mk5 models are not affected .
  • If the affected seed was used with a BIP-39 passphrase (the 25th word — not to be confused with the device PIN), the risk is minimal .
  • This is an initial analysis ; the investigation is ongoing , and a formal technical review will be released soon.

"Out of an abundance of caution, Coinkite is warning all users who generated a seed using an Mk3 version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk. Mk4, Q, and Mk5 are not affected based on our initial analysis."— Coinkite, official security statement (July 30, 2026)

The seriousness of the situation is evident: when the manufacturer itself issues such a warning about its product, the defect in seed generation ceases to be speculation and becomes a recognized fact . What is still lacking is the complete technical detail—which Coinkite has promised to publish.

 

What does this mean (and what is still unknown)?

It's important to separate what is confirmed from what is still inference:

Status What Confirmed by Coinkite There is a flaw in the seed generation of COLDCARD Mk3 (firmware 4.0.1+); funds may be at risk; Mk4/Q/Mk5 out; passphrase reduces risk to a minimum. Confirmed on-chain Approximately 594 BTC were drained from ~500 single-signature addresses, without Taproot, in ~15 minutes. Not yet confirmed. The possibility that the Mk3 flaw was the specific cause of the 594 BTC theft is strongly suggested by the timing and pattern, but Coinkite hasn't definitively established the link—it depends on a formal technical review. Not yet confirmed. The exact technical details of the vulnerability (mechanism, total scope, number of vulnerable wallets).

 

One point worth emphasizing: none of this involves breaking Bitcoin's cryptography . The network continues to function exactly as designed. The weak link, as is almost always the case, lies in how the keys were generated —in this case, within a specific device model, on a specific firmware track.

 

It's not the first time: Randstorm, Milk Sad and Ill Bloom

Randomness failures in portfolio creation have a well-documented history, and the Mk3 episode adds to that lineage:

  • Randstorm (2023): randomness flaw in wallets generated via browser with BitcoinJS between 2011 and 2015 — the only possible fix is ​​to move the funds to a new wallet.
  • Milk Sad (2023, CVE-2023-39910): vulnerability in the Libbitcoin Explorer tool, which generated seeds from weak randomness; attackers drained millions in a coordinated manner.
  • Ill Bloom (2026): disclosed by Coinspect in early July, it affects mobile wallets and older extensions with weak randomness; a scan on May 27 drained approximately US$3.1 million from 431 wallets in a few hours. Important: according to Coinspect, seeds generated within hardware wallets are not affected by this specific vulnerability.

The background highlights the scale of the problem: according to a survey by CertiK reported by Livecoins, compromised wallets were the leading cause of losses in the crypto sector in the first half of 2026 , with US$444.5 million in just 33 incidents — more than phishing and code flaws.

 

KriptoBR's positioning

KriptoBR has been working with a rigorous brand curation process since June 2017: it is an official reseller and direct importer of Trezor, Ledger, and SecuX hardware wallets, as well as digital security products such as Key-ID and Yubico . Coldcard has never been part of the company's portfolio , and KriptoBR's CEO, Jefferson Rondolfo , has always been clear about this: the brand has never been among his recommendations .

“Since 2017, our job has been precisely to filter what reaches the Brazilian investor. Coldcard has never been part of KriptoBR's portfolio and has never been a recommendation of mine — I have always been very clear about that. We only work with brands with which we maintain an official and direct relationship with the manufacturer, an auditable supply chain, and structured customer support in Brazil. Today's episode reinforces Bitcoin's oldest lesson: the security of your funds begins with where and how your seed is born.”— Jefferson Rondolfo, CEO of KriptoBR

A note of transparency: the above statement refers to the commercial and support criteria that KriptoBR has adopted for almost a decade. And it's only fair to say that, by issuing a public warning about its own product, Coinkite adopted a responsible disclosure stance—which doesn't erase the seriousness of the problem, but it is the correct behavior in the face of it.

 

Do you have a Mk3? What to do now?

If you generated the seed on a COLDCARD Mk3 with firmware 4.0.1 or later, the recommendation is to migrate your funds to a new seed, generated on an unaffected device and purchased from an official channel. In summary:

  1. Don't panic and don't rush. Hasty migration can create a greater risk than the one you're trying to avoid.
  2. Do not enter your seed anywhere and ignore offers of "recovery"—it's the classic post-incident scam.
  3. Generate a new seed on an unaffected device (Mk4/Q/Mk5 or other unaffected brand), verify the backup, and test with a small transaction before moving everything.
  4. Do not reuse the old seed — importing it onto another device will not solve the problem; the phrase needs to be entirely new.

Complete step-by-step guide: We've prepared a detailed guide to secure migration — including how to check if you're affected, the step-by-step procedure, and options for unaffected devices. Read the guide: How to migrate your COLDCARD Mk3 securely → (Update this URL to the final permalink of the guide article.)

How do you rate this article?

3


Kim03
Kim03

I am a content producer. I also publish news content.


Kim Blog News
Kim Blog News

General news blog. Cryptocurrency news.

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?