Coinkite urges Coldcard Mk3 owners to enable BIP-39 passphrases and migrate funds amid 594 BTC theft reports
Coinkite advises Coldcard Mk3 users to set a strong on‑device BIP‑39 passphrase and move coins to the new wallet following reports totaling 594 BTC in thefts.

Because Bitcoin
July 31, 2026
Coinkite has issued a cautionary notice to Coldcard Mk3 users: add a unique BIP‑39 passphrase directly on the device and transfer coins to the new passphrase‑derived wallet. The company’s guidance comes as reports circulate of thefts amounting to 594 BTC across the ecosystem. They are not pointing to a confirmed root cause; they are prioritizing a user‑side mitigation that materially raises the bar for attackers.
The single point that matters here: a strong BIP‑39 passphrase (often called the “25th word”) transforms your existing mnemonic into a different wallet entirely. If a seed phrase were ever exposed—via malware, backup mishandling, or a supply‑chain touchpoint—a high‑entropy passphrase renders that exposure far less useful. Entering the passphrase on the Coldcard itself, not a connected computer, narrows keylogger and clipboard risk.
Why the passphrase pivot is effective - It adds an independent secret to the key derivation, producing a fresh keyspace without discarding your current hardware. - It’s fast to deploy and reversible only if you know the passphrase; an adversary holding just the mnemonic gets nothing from the new wallet. - It compartmentalizes risk: even if an old seed was watched, coins moved under a new passphrase become much harder to target.
Trade-offs and how to manage them - Complexity cuts both ways. A forgotten passphrase is indistinguishable from an attack; operational discipline matters. - Decoy wallets are a feature, not a crutch. Be explicit about which passphrase guards real funds, and test restores before moving size. - On‑device entry is non‑negotiable. Avoid passphrase input through a desktop or mobile app whenever possible.
A pragmatic migration flow I recommend 1) Generate a fresh, high‑entropy passphrase on paper you control or via a diceware wordlist; think 6–8 random words or >12 truly random characters. 2) Enable the passphrase on the Mk3 and confirm the device shows a different master fingerprint (XFP). 3) Receive a small test amount to the new wallet and verify spending works. 4) Migrate in increments rather than a single sweep, watching for any anomalies. 5) Back up both the mnemonic and the passphrase in separate, durable storage; practice a full restore on a spare device or simulator.
What this signals to the market This is a sober, user‑empowering response during a period of heightened theft reports, not a panic button. In widespread drain scenarios, the highest‑leverage move is to assume some seeds may have been seen somewhere and rotate protection at the wallet‑derivation layer. A properly managed BIP‑39 passphrase does exactly that, with minimal friction and no waiting on new hardware.
Users who already run passphrase‑segmented vaults can stay the course—just reassess entropy and storage practices. Those who have never used a passphrase should act promptly but methodically: test, document, and only then commit real size. In Bitcoin, mitigation that you can execute today—on your own device, under your own process—often beats waiting for perfect information.