Coinkite warns Coldcard Mk3 users of seed flaw as 594 BTC theft reports surface
Coinkite says funds may be at risk on its Mk3 hardware wallet after reports of a 594 BTC theft, reviving scrutiny of self-custody security.

Coinkite, maker of the Coldcard hardware wallet, has issued a security notice warning that “funds may be at risk” for owners of its Mk3 model, after reports emerged of a theft involving 594 BTC, a sum worth roughly $38.3 million at prevailing prices. The advisory has intensified scrutiny of how self-custody hardware generates and protects seed phrases, the cryptographic secret underpinning control of a Bitcoin wallet.
Coinkite has framed the issue as a potential weakness in seed generation on the Mk3 device rather than a confirmed, demonstrated exploit, according to reporting by Coincu and The Block. No proven causal link between the flagged vulnerability and the 594 BTC transfer has been established, and the company’s own language stops short of confirming an active compromise.
Coinkite’s recommended response
Coinkite is advising Mk3 users to generate a strong, unique BIP-39 passphrase directly on the device and to migrate their holdings to the new wallet that results from applying it. A BIP-39 passphrase acts as an additional secret layered on top of a standard seed phrase, effectively creating a distinct wallet that would not be reachable even if the underlying seed generation were compromised.
The advisory does not specify how many devices are affected, nor does it confirm whether the 594 BTC theft is connected to the flagged seed-generation issue. Reports of the theft circulated through social media commentary before being picked up by trade outlets, and analysts have cautioned that the wallet address involved is publicly viewable on-chain, allowing independent verification of the transfer separate from second-hand accounts.
Operational security back in focus
The episode lands at a moment when both retail holders and institutions with substantial bitcoin positions are under pressure to treat seed hygiene and hardware provenance as core operational risks rather than a one-off setup step. Hardware wallets are widely marketed as the gold standard for self-custody precisely because they are meant to isolate private key material from internet-connected systems, so any doubt over seed integrity strikes at the core value proposition of the product category.
Coldcard users have been urged to verify device authenticity, confirm that backups have never touched a connected system, and avoid entering seed phrases into any untrusted software or website — a standing rule in self-custody security that becomes more pressing whenever a manufacturer flags an open review. Coinkite’s notice leaves several questions unresolved, including how widely the seed-generation issue extends across the Mk3 line and whether any signing environment tied to the 594 BTC wallet was itself exposed.
For an industry increasingly courting institutional custodians and treasury managers holding bitcoin on balance sheet, incidents of this kind add to a recurring theme: that trust in self-custody infrastructure can be disrupted abruptly, regardless of a product’s market reputation, and that hardware-level security reviews are likely to draw closer attention from both retail holders and compliance teams overseeing larger positions.
Read more: Citadel’s $5.5bn rescue of Aschenbrenner’s AI fund exposes bitcoin miner leverage


