Loading market data...

Coldcard Mk3 Users Warned of $38M Bitcoin Vulnerability

Coldcard Mk3 Users Warned of $38M Bitcoin Vulnerability

Coinkite issued a security advisory Thursday warning owners of its Coldcard Mk3 hardware wallet that funds tied to certain firmware versions may be at risk. Reports indicate a $38 million Bitcoin loss associated with the vulnerability. The warning comes after long-dormant addresses began moving in a tightly coordinated pattern on July 30, prompting scrutiny from blockchain analysts.

What the advisory says

Coinkite's advisory, published Thursday, specifically flags the Mk3 model. The company urged users to check their firmware version and take immediate steps to secure funds. The exact firmware versions affected weren't detailed in the advisory, but the company said it's working on a fix. For now, the priority is preventing further losses.

The $38 million movement

On July 30, a cluster of long-dormant Bitcoin addresses began transferring funds in a coordinated manner. The pattern raised alarms among blockchain analysts, who traced the activity back to wallets associated with the Coldcard Mk3 vulnerability. The total moved so far is estimated at $38 million. That's a significant sum for a hardware wallet exploit — and the coordinated timing suggests the attacker had been planning the move for a while.

What users should do now

Coinkite recommends that Mk3 owners move their funds to a different wallet or upgrade to a newer hardware model if possible. The company said it will release a detailed post-mortem once the investigation is complete. No timeline has been given for that report, but the clock is ticking for Mk3 users still holding funds on the affected firmware. The exchange hasn't said whether it will offer compensation, and that question remains open.