Attackers Exploit Coldcard Mk3 Bug, Recreate Recovery Phrases, Steal 594 BTC
Image: Yellow

Attackers Exploit Coldcard Mk3 Bug, Recreate Recovery Phrases, Steal 594 BTC

03 August, 2026.Crypto.33 sources

Approximately 594 BTC worth $38M stolen from about 500 Coldcard wallets in ~25 minutes. Firmware flaw allowed seeds to be reconstructed without device, enabling attackers to steal funds.

33 outlets2 divides1 fact unevenly covered

Beat 1 · The verdict

scale of losses is reported very differently across outlets

Read them yourself

Do not take our word for it. Here is what they published.

All 33 outlets

Full story

Coldcard seed flaw exploited

A software bug in Coldcard hardware wallets allowed attackers to recreate wallet recovery phrases and steal bitcoin from users who believed their funds were securely self-custodied.

"If you generated a seed using a Coldcard wallet, move your funds now"

@coindesk@coindesk

Coinkite CEO NVK urged affected customers to act immediately, writing, "If you generated a seed using a Coldcard wallet, move your funds now," and he said the fix protects new seeds going forward but does not fix seeds already generated on vulnerable firmware.

Image from @coindesk
@coindesk@coindesk

AMBCrypto said an attacker drained about 594 BTC worth over $38 million from 500 Coldcard wallets within about 15–25 minutes, exploiting a Coldcard Mk3 seed generation flaw that made some Mk3 recovery phrases predictable due to weak entropy.

The incident has been described as a key-generation stage compromise, with Blockaid co-founder and CEO Ido Ben-Natan saying, "Coldcard fits that pattern, with the exposure originating at the key generation stage."

Calls to migrate, blame

In the wake of the exploit, Coinkite’s guidance emphasized that updating firmware alone does not eliminate the risk for seeds already generated on vulnerable devices, and it advised users to create entirely new wallets and move funds onchain.

Bitcoin Magazine reported that Coinkite’s updated advisory said, "Fixed firmware is now available," and it specified that Mk4 and Mk5 users must update to version 5.6.0 or later while Mk3 users must update to version 4.2.0 or later.

Image from @coindesk
@coindesk@coindesk

Taproot developer Udi Wertheimer argued that security is not something holders can set up once and forget, writing on X, "The idea of your bitcoin resting easy in some secret location while you enjoy life not worrying about it is currently unrealistic."

Galaxy Research’s analysis, as summarized by Forbes, said it identified 1,596 bitcoin valued at about $102 million as of Tuesday that had been stolen from more than 7,300 crypto wallets across three confirmed waves and 14 smaller incidents.

Losses mount, legal risk

As investigators continued to compile victim addresses, multiple outlets put different totals on the theft, with Fox Business citing roughly $70 million in less than an hour and saying researchers at Galaxy Research drained more than 1,000 bitcoin from 1,196 digital wallets in just 41 minutes on July 30.

drained more than 1,000 bitcoin from 1,196 digital wallets in just 41 minutes

Fox BusinessFox Business

Cointribune said losses estimated at more than $88 million in Bitcoin prompted victims to prepare a legal response, adding that Coinkite could face a class action after the loss of more than 1,300 BTC attributed to the vulnerability.

The same Cointribune report quoted Thomas Braziel, founder and managing partner of 117 Partners, coordinating the collection of information from victims across several countries to assess legal options including a product liability action or a class action against Coinkite.

For affected users, the immediate consequence described across coverage was the need to migrate funds to newly generated wallets, because Coinkite warned that "Updating the firmware does not repair a seed that was generated by affected firmware" and that "A new seed must be generated and the funds migrated to the new wallet."