The Coldcard hack is every bitcoiner’s worst nightmare come true: roughly 594.5 BTC — about $38.3 million — vanished from around 500 “safe” cold-storage wallets in a coordinated sweep that took barely 25 minutes, spanning just four Bitcoin blocks (960188–960191). The coins didn’t move because someone stole a device or fell for a phishing link. They moved because, for years, an entire generation of hardware wallets may have been generating guessable keys. Coldcard’s maker Coinkite has issued a formal warning that seeds created on its Mk3 device since March 2021 "may be at risk." The link between that flaw and the theft is not yet officially confirmed — but if you hold bitcoin on an older Coldcard, you need to read this now.
Key takeaways: ~594.5 BTC drained from ~500 wallets in ~25 minutes · Mk3 seeds created on firmware 4.0.1 (March 2021) through 5.0.3 flagged · Mk4, Q and Mk5 unaffected per early analysis · BIP-39 passphrase users face limited exposure · Root cause not yet officially confirmed.
What Happened: $38M Gone in 25 Minutes

On July 30, reports started stacking up on Reddit: bitcoin disappearing from wallets whose seeds were generated on Coldcard hardware. On-chain analysis showed approximately 594.5 BTC swept from 500 single-signature addresses in one synchronized operation. The pattern is chilling: every victim wallet was single-sig, held more than 0.15 BTC, and many had sat untouched for years — exactly what you would expect from an attacker who quietly precomputed private keys and waited for the right moment to strike everything at once.
Who Is at Risk From the Coldcard Hack

Within hours, Coinkite published an official Mk3 seed generation warning. The scope, straight from the company: any seed generated on a Coldcard Mk3 running firmware 4.0.1 (released March 2021) through 5.0.3, the final Mk3 release. Mk4, Q and Mk5 are not affected based on early analysis, and anyone who protected an affected seed with a BIP-39 passphrase faces limited exposure. The exact cause "has yet to be confirmed" and the investigation is ongoing.
Some respected voices in Bitcoin development are drawing the circle wider — urging anyone with a single key generated on an Mk3 between 2021 and 2023, without dice rolls, a passphrase or multisig, to move funds immediately, and warning that other models could yet be pulled in. Treat that as expert caution, not a confirmed finding.
Could It Be Even Bigger Than $38M?
Possibly — and this is the scary part. Security researchers have identified 695 earlier transactions carrying the same fingerprint as the known theft set, moving a further ~488 BTC. If those belong to the same campaign, the true haul climbs to roughly 1,082 BTC — over $69 million — and it means this sweep was running quietly long before anyone noticed. That attribution is provisional, but dormancy clearly protected no one.
How to Stay Safe Right Now
If your seed was born on an Mk3 in the affected window, act — but act calmly. The official guidance, in order: add a strong, unique BIP-39 passphrase on the device and move funds into that new wallet; advanced users can generate a replacement seed on an empty Mk3 (firmware 4.1.9) using the dice-roll path with at least 99 rolls of a real die, which bypasses the device’s random number generator entirely; and the preferred long-term fix is a fresh seed on an unaffected model. One warning deserves emphasis: rushing a migration — mistyped addresses, unverified backups, fake "support" accounts sliding into your DMs — can lose your coins faster than the flaw itself. Verify your backup, send a small test transaction first, then move the rest.
How to Store Crypto Safely From Now On

The uncomfortable lesson of the Coldcard hack is that "cold storage" was never the whole answer — the randomness of your seed and the structure of your setup matter just as much as keeping keys offline. Five rules cover most of the risk. One: never type your seed phrase into any website, app, or "checker" — no legitimate service will ever ask. Two: use a strong, unique BIP-39 passphrase, which acts as a 13th/25th word and just proved its worth as cheap insurance. Three: for serious amounts, use multisig across different devices from different vendors, so no single flaw can empty you. Four: verify your backups physically and always send a test transaction before moving size. Five: when you buy a new hardware wallet, generate a brand-new seed on it — never restore an old seed you are trying to escape, and consider dice-roll generation if you want randomness you can verify yourself. For more custody hygiene, see our crypto security toolbox and our report on physical-access crypto theft.
What It Means
This is the nightmare scenario for hardware wallets: not a stolen device, not a phished user, but entropy quietly failing at the moment of seed creation — years before the theft. Three implications stand out. First, the "cold storage = safe" equation always depended on the seed’s randomness, and single-sig concentrates that risk. Second, dormancy is not protection; these coins sat still for years while keys were being derived. Third, for institutional and family-office custody — including the growing Gulf cohort we cover — this strengthens the case for multi-vendor multisig over any single device, however respected. Coldcard’s quick, transparent advisory is to its credit; the open questions are the final root-cause report and whether other models or firmware windows get pulled in.
FAQ
Am I affected by the Coldcard hack?
You are potentially exposed if your seed was generated on a Coldcard Mk3 running firmware 4.0.1 or later (March 2021 onward), especially single-sig without a passphrase. Seeds made with dice rolls, protected by a BIP-39 passphrase, or created on Mk4, Q or Mk5 are considered low-risk per current analysis.
Should I move my bitcoin right now?
If you fall in the affected group, yes — carefully. Add a passphrase wallet or migrate to a new seed on an unaffected device, verify backups and addresses, and send a small test transaction first. Never type your seed into any website, and ignore anyone offering to "help" in DMs.
This article is for informational purposes only and does not constitute investment or security advice. Facts reflect information available as of July 31, 2026; the investigation is ongoing.