Coinkite issued an urgent warning to Coldcard Mk3 users, instructing them to migrate their Bitcoin holdings after the hardware wallet manufacturer identified a potential vulnerability in the device's seed-generation process. The company did not disclose specific technical details about the flaw, but the warning triggered immediate concern across the Bitcoin custody community given the Mk3's widespread adoption among institutional and retail users.

The alert coincides with a separate investigation by Bitcoin security experts into an unexplained $38 million drain from a major Bitcoin wallet. Researchers are examining whether the two incidents share a common vector or represent distinct security lapses. The timing of the Coldcard warning and the large-scale wallet drain has intensified scrutiny around hardware wallet firmware integrity and seed generation mechanisms, which form the cryptographic foundation of Bitcoin custody.

Seed generation determines how private keys are created on hardware wallets. Flaws in this process can compromise the randomness required for secure key derivation, potentially exposing funds to attackers who can predict or recover the seeds. Mk3 devices generate seeds through a combination of hardware entropy and user input. If this process contains exploitable weaknesses, attackers could theoretically derive private keys without direct access to the wallet.

Coinkite recommended Mk3 users perform a complete migration by generating new seeds on updated hardware or alternative trusted devices. The company did not specify whether the vulnerability affects all Mk3 units or specific firmware versions. This blanket advisory creates friction for users managing large portfolios across multiple devices.

The $38 million wallet drain remains unexplained, with no confirmed connection to Coldcard hardware wallets established yet. Security researchers are analyzing transaction patterns and wallet metadata to determine whether the funds were stolen through seed compromise, firmware exploitation, or social engineering. The incident underscores persistent tensions in Bitcoin self-custody, where user responsibility intersects with hardware and software reliability. Both issues reinforce why custody infrastructure security demands constant vigilance and rapid response protocols.