Coinkite has announced a critical security vulnerability in its Coldcard Mk3 hardware wallets, resulting in significant Bitcoin losses for users. This revelation comes after a major exploit that occurred on July 30, 2026, and the report expresses concern that it may undermine trust in the safety of cryptocurrency storage solutions.
Security Flaw and Attack Overview
The security flaw allowed attackers to siphon off approximately 594 BTC from around 500 wallets in a mere 25 minutes. Coinkite suspects that the breach was facilitated by an attacker utilizing artificial intelligence to identify the vulnerability, which had previously gone undetected by the company's own AI review process weeks prior to the incident.
Response and Mitigation Measures
In response to the breach, Coinkite has issued an advisory for users affected by the exploit and has rolled out an emergency hotfix for its newer Mk4 and Mk5 models. However, owners of the Mk3 wallets, which are no longer supported, are being directed to a separate migration path to help secure their funds and mitigate potential losses.
In light of the recent security breach affecting Coinkite's Coldcard wallets, users should also be aware of the SparkKitty malware campaign that targets cryptocurrency holders. For more details, see the report on the SparkKitty malware.








