On July 30, 2026, nearly 600 BTC, worth about $38 million, were swiftly moved from nearly 500 long-dormant single-signature wallets. The activity happened in under half an hour, raising eyebrows across the crypto community. These wallets, many untouched for years, typically held between 0.15 and 0.26 BTC, suggesting a coordinated event rather than isolated incidents.

Coinkite, the maker of the Coldcard hardware wallet, immediately issued a security advisory targeting owners of the Mk3 model running firmware versions 4.0.1 through 5.0.3. These versions date back to March 2021 and represent the final firmware updates for the Mk3 device. The company emphasized that newer models like Mk4, Q, and Mk5 appear unaffected so far.

CEO Rodolfo Novak, widely known as NVK in the crypto space, reacted promptly by assuring users that the team is fully engaged in a detailed technical investigation. He acknowledged the flood of questions on social media and promised a full blog post with findings soon. Early analysis by Coinkite and independent community researchers leans toward a vulnerability linked to weak randomness during seed generation on older Mk3 firmwares. This contrasts with theories of supply chain tampering, which haven’t been confirmed.

While the root cause remains unverified, the advisory urges owners who created seeds on the specified firmware versions to act cautiously. Despite rising concerns, Coinkite has not formally confirmed that the $38 million loss is directly tied to the Coldcard hardware or its software vulnerabilities.

This incident highlights the risk dormant addresses face, particularly when hardware wallet firmware may expose subtle flaws years after initial use. For anyone relying on Coldcard Mk3 devices released before 2022, the unfolding situation demands close attention to further announcements and security measures.

This information is for educational purposes and does not constitute financial advice.