594 BTC Gone: Coinkite Just Issued an Emergency Warning for Coldcard Mk3 Users

Coinkite has told Coldcard Mk3 users their funds may be at risk, following reports of 594 BTC stolen from wallets linked to the hardware device.

That's not a theoretical vulnerability. That's roughly $57 million in Bitcoin, already gone, from users who likely believed their cold storage was untouchable. If you own a Mk3, this is the story you cannot afford to scroll past.

What Coinkite Is Actually Saying

The company's warning is direct: Mk3 users need to act now. Coinkite's recommended fix is to generate a strong, unique BIP-39 passphrase directly on the device, then move all funds into the resulting wallet. This creates a new layer of protection that the base Mk3 setup does not provide on its own.

The BIP-39 passphrase functions as a 25th seed word. Even if an attacker has somehow compromised or extracted your 24-word seed phrase, the passphrase creates an entirely separate wallet that the seed alone cannot access. It is one of the most powerful protections available in Bitcoin self-custody and, critically, it is not enabled by default.

Why This Should Alarm Every Self-Custody Holder

The Coldcard is not a cheap or casual product. It is marketed specifically to security-conscious Bitcoiners who take self-custody seriously. These are not users who clicked a phishing link or kept funds on an exchange. These are people who bought hardware precisely to avoid scenarios like this.

The nature of the attack vector has not been fully disclosed publicly, which is the detail that should be making every hardware wallet user nervous right now. When 594 BTC disappears from cold storage and the manufacturer responds with an emergency passphrase recommendation, it suggests something more systematic than individual user error.

Coinkite has not confirmed whether the Mk4, its current flagship model, carries any similar exposure. That silence is worth watching.

What You Need to Do Right Now

If you hold funds on a Coldcard Mk3, stop reading and go enable a BIP-39 passphrase on your device today, then transfer your Bitcoin to the new passphrase-protected wallet. Do not reuse a passphrase from another account or service. Make it long, random, and stored securely offline.

For holders on other hardware wallets, this is a well-timed reminder to audit your own setup. BIP-39 passphrase protection is available on most major devices and remains one of the most underused security layers in self-custody.

The broader implication is uncomfortable but important: cold storage is only as strong as its configuration. Watch for further disclosure from Coinkite on how these funds were compromised. That explanation, when it comes, will matter to the entire Bitcoin self-custody ecosystem.