Hardware wallet incidents rarely occur as isolated events. When long-dormant addresses begin acting according to a highly coordinated script, the timing alone warrants a thorough investigation. This is precisely what happened on July 30, 2026, when approximately 594 $BTC worth about $38 million were transferred from roughly 500 single-signature addresses over a period of about 25 minutes.

What Coinkite Says
Coinkite CEO Rodolfo Novak, known in the industry as NVK, stated that the company is prioritizing these reports. "We are all hands on deck, thoroughly examining every detail; a technical post is forthcoming," Novak wrote on X. He added that the company's communication channels have been "flooded" with inquiries following these reports. In a separate message, Novak emphasized: "We have conducted a thorough investigation regarding the COLDCARD reports, a blog post is coming soon."
In a security advisory blog post, the company specified a particular range of vulnerable devices. The issue may affect anyone who generated a seed on the Mk3 with firmware versions from 4.0.1, released in March 2021, up to version 5.0.3—the last version supporting the Mk3. Coinkite clarified that preliminary analysis findings indicate Mk4, Q, and Mk5 models are not affected.

Passphrase Users at Lower Risk
According to the advisory, wallets secured with a BIP-39 passphrase (a user-added phrase distinct from the device PIN) appear to be at minimal risk based on Coinkite's preliminary analysis. The company recommended that users employing a passphrase should continue to protect it and avoid entering it on untrusted devices or websites.
For Mk3 owners who did not use a passphrase, Coinkite recommended moving to a new seed generated on a device unaffected by the incident. The company noted that this process should not be rushed. It advised first sending a small test transaction, verifying the new wallet and receive address on the device's screen, and keeping the old backup until the migration is confirmed.
Interim Measures
Coinkite suggested two interim steps for owners whose Mk3 is their only device:
- Set up a strong, unique BIP-39 passphrase and move funds to a new secured wallet.
- Generate a backup seed via the "dice roll" import path on the Mk3, which is independent of the device's random number generator, although Coinkite characterized this procedure as complex, requiring careful verification.
Coinkite published full instructions with technical steps in its advisory post, available on the company's blog. The company explained that the investigation is ongoing and that further details will be published later. Since its launch, Coldcard has built a reputation as an air-gapped hardware wallet focused on security, and these reports have drawn widespread attention across the entire Bitcoin community as owners check their own devices.
end-content







