Coinkite, the company behind the Coldcard hardware wallet, has issued a security warning to owners of its older Mk3 devices after a theft of 594 BTC drew fresh scrutiny to how hardware wallets generate and protect seed phrases. The warning was flagged in a July 31, 2026 report from WuBlockchain, which cited Coinkite's advisory to review seed handling on legacy units.
At current prices, 594 BTC is worth roughly $38.5 million, with Bitcoin trading near $64,766 as of July 31, 2026. The size of the loss, tied to a single device generation, is why an otherwise routine vendor notice is getting attention across the self-custody community.
The warning and what prompted it
Coinkite's advisory centers on the Mk3, an earlier Coldcard model that has since been superseded by newer hardware. The company urged Mk3 holders to review how their seed was created and stored, rather than assume older devices carry the same guarantees as current ones. The 594 BTC theft is the trigger for the notice, though the full chain of events that led to those coins moving has not been detailed in the initial report.
This is a single-source story at the time of writing. The primary basis is Coinkite's own warning as relayed by WuBlockchain. The exact technical path of the theft, including whether it stemmed from a device flaw, a compromised seed, or user error, is not yet independently confirmed. We will treat the mechanism as unresolved until Coinkite or an independent security researcher publishes a fuller post-mortem.
Seed generation is the weak point
A hardware wallet's entire security model rests on one assumption: the 12 or 24 words that make up your seed phrase were generated with real, unpredictable randomness and were never exposed to anything connected to the internet. If that randomness is weak, or if the seed was ever typed, photographed, or backed up to a synced device, the physical wallet stops mattering. An attacker who can reconstruct or find the seed does not need to touch the hardware at all.
That is the uncomfortable lesson behind incidents like this one. The threat to self-custody rarely comes from someone cracking a secure element in a lab. It comes from the seed leaking through a side channel: a screenshot in a phone gallery, a photo in cloud backup, a seed generated on a compromised machine, or a phrase entered into a fake recovery prompt. Malware such as SparkKitty has been caught scanning phone galleries specifically for seed-phrase screenshots, which shows how much attackers focus on the backup rather than the box.
Steps for Mk3 and other legacy hardware owners
If you hold Bitcoin on a Coldcard Mk3 or any older hardware wallet, a few concrete checks are worth doing now:
- Confirm how your seed was generated. If it was created fully on-device with dice or the wallet's own entropy and never entered anywhere else, your exposure is lower. If it ever touched a phone, computer, or cloud backup, treat it as potentially compromised.
- Check for any digital copy of your seed. Search photo libraries, notes apps, email drafts, and cloud storage. A seed phrase should exist only on paper or metal, offline.
- If there is any doubt, move funds to a freshly generated wallet on current hardware and a clean seed. Migrating coins to a new seed is the only reliable fix when the old one may be exposed.
- Watch for official guidance from Coinkite before acting on secondhand summaries. A vendor post-mortem will define who is actually affected.
For anyone weighing custody choices more broadly, this is a reminder that spending and holding from your own wallet shifts full responsibility for key security onto you. That trade removes counterparty risk, the kind that freezes balances when a custodian fails, but it replaces it with the risk that a single leaked seed ends the story. Neither model is free of risk; they just move the risk to different places.
The broader signal for self-custody
One theft does not condemn a product line, and Coldcard remains a widely used cold-storage option. The takeaway is narrower and more useful: hardware generation matters, older devices are not automatically as safe as current ones, and the seed backup is almost always the real attack surface. A device that is years old deserves a fresh look at how its seed was made and where any copy of it might still live.
Bitcoin is up 1.3% over the past 24 hours, and the market's Fear and Greed Index sits at 38, in "Fear" territory, as of July 31, 2026. Price action is unrelated to this incident, but the timing is a prompt for long-term holders to audit their setups while the market is quiet rather than during a scramble.
Overview
Coinkite warned Coldcard Mk3 owners to review their seed security after a 594 BTC theft, worth about $38.5 million at July 31, 2026 prices, put legacy hardware wallets under scrutiny. The mechanism behind the theft is not yet confirmed, and this remains a single-source report. The practical response for any older-hardware holder is the same regardless of the final cause: verify how your seed was generated, hunt down any digital copy of it, and migrate to a clean seed on current hardware if there is doubt.



