Reports of 594 $BTC in stolen funds have surfaced alongside a formal warning from Coinkite, the maker of the Coldcard hardware wallet, directed at users of its Mk3 model. The company says funds may be at risk and has issued a specific remediation step: generate a strong, unique BIP-39 passphrase on the Mk3 device and transfer holdings to the wallet that passphrase creates.

What the warning requires

Coinkite's guidance is narrow and action-oriented. Create a strong, unique BIP-39 passphrase. Do it on the device. Move funds to the resulting wallet. What the company has not specified, at least per the available disclosure, is the precise vulnerability or failure mode that produced the reported losses. Mk3 users are therefore weighing a formal security advisory against an incomplete technical picture. Acting on the stated remediation is the rational response to that gap.

Why the passphrase specification matters

The BIP-39 passphrase is an optional but significant protection layer in hardware wallet security. Applied to an existing seed phrase, it produces an entirely separate wallet. Coinkite's instruction to generate the passphrase on the Mk3 device itself, rather than on a connected computer or another surface, limits the points at which the passphrase could be intercepted or logged before it is used.

The counterargument

Coinkite's fix requires no firmware update and no hardware swap. That strongly suggests the Mk3's core seed generation is intact and that the attack surface is the absence of a strong passphrase. Taken at face value, this frames the reported losses as a configuration failure rather than a device flaw. That distinction matters for users deciding whether to follow the stated remediation or replace their hardware entirely.

On balance

The case for acting on Coinkite's recommendation stands regardless of that open question. The risk for any Mk3 holder who delays is that the 594 $BTC in reported thefts reflects a pattern that remains active. The line to watch is whether Coinkite publishes a technical disclosure naming the attack vector and clarifying whether the Mk3's hardware played any role in those losses.

Related reading