#What is the impact of the Coldcard Mk3 firmware flaw?
The Coldcard Mk3 hardware wallets, designed to be digital asset vaults, have undergone significant scrutiny following a serious firmware vulnerability. Galaxy Research has confirmed that approximately 1,367.05 BTC, valued at around $88.6 million, was illicitly taken through a series of coordinated attacks that impacted 4,585 wallets.
The extent of the theft is alarming. Initial assessments suggested losses nearing 594 BTC across about 500 wallets. However, deeper analysis revealed a much larger and meticulously executed scheme.
#How did the attacks unfold and when did they occur?
The most impactful wave of attacks occurred on July 30, 2026, within a mere 41 minutes, resulting in the loss of 1,082.65 BTC, equivalent to roughly $70.2 million. Analysis by Galaxy highlighted the consistency of attack patterns in the first two waves, notably with identical transaction fees of 30 sat/vB and particular batching patterns. This uniformity indicates that the attacks likely stemmed from a single operator or toolkit. The third wave deviated, suggesting a different actor or a change in strategy.
A sharper way to see the markets in just 5 minutes.
Same news, different lens. We cut through the noise and hand you the overlooked ideas and the deeper read the crowd misses. Join 38,000+ investors seeing the markets differently.
#What vulnerabilities were exploited in the Coldcard Mk3 wallets?
The root cause of these issues lies in a predictable flaw in the Coldcard Mk3 firmware, evident in versions 4.0.1 and beyond, which was introduced in March 2021. This vulnerability rendered the device's random number generator unreliable, producing outputs that were susceptible to prediction. An attacker with sufficient computing power could deduce potential seeds offline and link them to actual addresses on the blockchain, allowing theft from single-signature wallets without needing physical access to the devices.
The engineering team at Block was the first to disclose the RNG issue publicly, and within approximately 30 hours of the attack's onset, Coinkite, the manufacturer of Coldcard, released an advisory explaining the situation.
#What should users of Coldcard Mk3 do now?
Fortunately, users of newer Coldcard devices, including the Mk4, Q, and Mk5, are not impacted by this security flaw. Current users of compromised Mk3 wallets are strongly advised to create new seeds on unaffected devices instead of simply transferring their funds within the same model family.
#How does this breach affect hardware wallet security and what actions should investors take?
One noteworthy aspect of the attacks includes the unusually high transaction fees; the hardcoded rate of 30 sat/vB during the first two waves was significantly higher than the median fees. This indicates that the attackers were prepared to invest significantly to expedite transaction confirmation.
For those actively holding Bitcoin, it is crucial to assess exposure. Users operating Coldcard Mk3 devices with firmware version 4.0.1 or later should consider their current seed compromised. It is advisable to transfer assets to newly generated wallets on unaffected hardware. Users should also verify their firmware version against Coinkite’s guidelines as a first step in mitigating further risks.