Security researchers have identified a seed-generation flaw in the Coldcard Mk3 hardware wallet that may allow attackers to derive private keys and drain funds. A separate on-chain investigation is tracking an unexplained $38 million Bitcoin wallet drain potentially connected to the vulnerability. Coldcard's manufacturer has issued a formal warning advising Mk3 owners to add a strong BIP-39 passphrase and transfer holdings to a freshly generated wallet immediately.
This is a direct custody risk for anyone holding Bitcoin on a Coldcard Mk3 device. Hardware wallets are the standard self-custody tool for serious Bitcoin holders, so a confirmed seed-generation flaw raises questions about the broader assumption that cold storage is inherently safe. Other hardware wallet makers and their users will face scrutiny, and short-term sentiment around Bitcoin self-custody could soften.
Ongoing: Coldcard manufacturer patch or public post-mortem disclosure. Ongoing: On-chain investigator updates on the $38M drain attribution. Watch for any scheduled security audits published by competing hardware wallet vendors in the weeks following this disclosure.
Full analysis · Subscribers
The deep dive (bull case, bear case, and the data point that decides which side wins), the cause-and-effect chain behind the move, plain-English explainers for every block, and the live update timeline (3 updates so far).
Aggregated reads dozens of sources in five languages and turns the day into plain-English cards like this one.
Educational analysis of public information, not investment advice. Report an error · Corrections policy
← Today's brief