Bitcoin (BTC) Wallet Sweep Moves 594 BTC in Three Blocks
A three-block Bitcoin wallet sweep moved 594.48 BTC worth $38.2M, coinciding with a Coldcard Mk3 firmware warning and ongoing entropy investigation.
AI SummaryAI
- Coinkite warned Coldcard Mk3 users about seeds generated on firmware 4.0.1 through 5.0.3.
- A coordinated three-block sweep moved 594.48 BTC across 500 transactions from single-signature addresses.
- The swept Bitcoin was worth about $38.2 million when Bitcoin traded near $64,324.
- AnchorWatch's Rob Hamilton identified 1,324 unspent transaction outputs and later consolidation of 562 BTC.
A coordinated sweep of 594.48 BTC across 500 transactions in a three-block window has coincided with a Coldcard Mk3 security advisory from Coinkite. The Canadian hardware maker said on July 30 that seeds created on Mk3 firmware 4.0.1 through 5.0.3 may put funds at risk, while early analysis indicates Coldcard Mk4, Q and Mk5 models are unaffected. Seeds protected by a BIP-39 passphrase face minimal risk, and the passphrase is not the device PIN. The transferred coins were worth roughly $38.2 million when Bitcoin traded near $64,324, but no public evidence has tied the Mk3 seed warning directly to those transactions. Coinkite recommended generating a new seed on an unaffected device, confirming the backup and receiving address, sending a small test transaction, and moving the remaining balance only after the test clears. For users who still rely on an Mk3, the advisory described two fallback paths: adding a strong, unique BIP-39 passphrase as a temporary safeguard, or creating a dice-only seed on an empty Mk3 running firmware 4.1.9 with at least 99 rolls of a fair six-sided die. The company said the investigation remains active and has promised a formal technical review. The advisory framed the migration as precautionary pending the technical review. Its guidance urged users to preserve old backups until migration is complete, verify every address on the hardware screen, and avoid entering seed words on websites or untrusted devices. Each address should be checked character by character on the device display, and the old seed backup should remain stored offline until the new wallet receives the full balance. At the time of writing, the root-cause findings had not been published, leaving the relationship between the advisory and the sweep timing related but unproven. For broader coverage of the network, see our Bitcoin hub, and for background on the asset, read What is Bitcoin (BTC)? Complete Guide.
The on-chain movement drew attention after a self-reported Reddit account described a wallet funded by a Coldcard Mk3 seed that was later restored onto a Mk4, but that single claim does not establish a wider link. On-chain data reviewed by AnchorWatch CEO Rob Hamilton showed 1,324 unspent transaction outputs moving through 500 transactions inside a three-block window, sweeping 594.48 BTC from single-signature addresses. Hamilton said the pattern looked like flawed entropy during wallet generation, while cautioning that this was a preliminary read rather than a confirmed cause. Wizardsardine CEO Kevin Loaec offered a related hypothesis: a low-randomness generator, possibly inside a software library, secure element, device batch or firmware version, may have produced seeds that were easier to guess. Loaec suggested an attacker could have used an AI-generated script to search a narrow set of BIP-84 derivation paths, which would help explain why the activity concentrated in native SegWit addresses and why some wallets were only partially emptied. He warned that partially drained wallets could remain vulnerable if the assumption is correct, and that funds in other address types might face exposure if the scanning activity broadens. The sweep, valued at about $38.2 million when Bitcoin changed hands near $64,324, later saw 562 BTC consolidated into another address. No public technical report has yet identified the faulty component, measured the entropy shortfall, or shown how private keys were derived. The available evidence therefore points to a timing overlap between the Mk3 advisory and the sweep, not a proven common cause. The preliminary analyses emphasize that the sweep involved single-signature addresses, not multisignature setups, which narrows the immediate scope of the observed activity. No researcher has published a reproducible method for deriving the keys. Because wallet-generation flaws can affect automated tooling as well as hardware devices, the episode also raises questions about AI Crypto Wallet safety and key-management hygiene.
Block's Bitcoin engineering team has since published a formal technical report confirming the root cause: a defective RNG validation routine in Coldcard firmware switches off the chip's hardware entropy source, causing a fallback mechanism to construct private keys from the device serial number and internal clock — both values an attacker can predict and enumerate. Block traced the defect to a 2021 firmware update and determined that a subsequent patch released one year later still narrowed the keyspace to approximately four billion combinations, a range modern computing hardware can brute-force. The report further confirmed the vulnerability extends beyond seed generation to paper wallets and other features relying on the same entropy pool. Coinkite and Block said they continue assessing the flaw's reach across older firmware and advised owners to treat any seed created before the latest fix as potentially compromised.
Coinkite CEO NVK initially dismissed the possibility of a device-level flaw, attributing the losses to users who may have employed already-compromised or poorly secured seed phrases. That position reversed after internal investigation and external security analysis confirmed the Mk3 seed-generation defect, prompting the company to publicly disclose the affected firmware range and urge immediate migration. Operational details emerging from the investigation show the sweep unfolded over roughly 25 minutes, with most victim wallets holding between 0.15 and 0.26 BTC — many of them dormant UTXOs that had seen no on-chain activity for years. Industry observers have drawn parallels to the earlier "Milk Sad" vulnerability, another case in which a random-number-generation error enabled large-scale fund extraction, underscoring that entropy validation at the key-creation stage remains a critical security boundary for hardware wallet manufacturers.
Coinkite disclosed in a follow-up technical backgrounder that it had run its open-source firmware through "the best available AI models" weeks before the attack without flagging the defect, conceding that the same tools "only helped the bad guys." Developer Stephen DeLorme independently reproduced the vulnerability by cloning the public repository and querying Claude Opus 5, warning that "all our software is insecure" and that the industry is "painfully figuring that out in realtime." Bitcoin Core developer Gregory Sanders confirmed the exploit on Mk2 and Mk3 hardware using button-press counts, then cautioned that Mk4 "is probably not much better." Veteran developer Peter Todd argued the episode exposes insufficient independent audit of commercial hardware wallets and called for end-to-end deterministic testing on physical devices rather than blind trust in chip-level randomness.
(as of 13:31 UTC) COINOTAG's proprietary 42-indicator composite S/R scoring engine shows Bitcoin pressing against strong resistance at $63,886, scored 71/100 from Ichimoku Kijun, EMA 20, BB Middle, and SMA 20, while heavier supply sits at $65,875, scored 76/100 from Bearish Engulfing, R1, ATR Upper, and BB Upper. Immediate support at $61,757 carries 69/100, driven by Fibo 0.114, high-volume-node confluence, Supertrend, and Keltner Lower. Derivatives positioning is mixed: funding has turned slightly negative at -0.0004%, open interest stands at $12.56 billion, and the long/short account ratio is 1.89. With Fear and Greed at 25/100, a bear market sentiment zone, a close above $65,875 would favor $69,199, while losing $61,757 would shift focus to $57,800. Bitcoin's 69.6% COINOTAG-tracked market share favors altcoin caution.
Related Tags
AI-generated, AI-reviewed, under COINOTAG editorial oversight.
More From COINOTAG
Bitcoin (BTC) Treasury Firm Strategy Reports 12 Top Shareholders Raised MSTR Stakes by $1.2B
August 20, 2026 at 08:24 AM UTC
Gold Breaches JPMorgan's $4,500 Q4 Target as Bitcoin (BTC) Tracks Macro Bid
August 20, 2026 at 07:46 AM UTC
Who Decides Bitcoin's Fate? Gallego Warns on Sept. 15 CLARITY Act Vote
August 20, 2026 at 05:59 AM UTC

