A major wave of concern has swept through Thailand's digital asset community after an investor came forward to share a cautionary tale: more than 71,824,487 sats (approximately 0.718 BTC, or around 46,000 US dollars) vanished from a Coldcard Mk3 hardware wallet — the very model for which manufacturer Coinkite had just issued a critical security vulnerability warning. A key detail drawing close attention is that the outgoing transaction occurred on 26 July 2026, before the manufacturer's official public disclosure, suggesting the alarming possibility that hackers were already aware of the attack vector and had swept the funds before any warning reached consumers. The incident has also sparked in-depth debate about physical security standards, the failure to use a Passphrase, and seed-copying practices that may have compounded risks without the owner realising it.
The incident came to light through a post in a public Facebook group, where an anonymous user shared a deeply distressing first-hand account of 71,824,487 sats (a sub-unit of Bitcoin) — valued at approximately 46,000 US dollars at current market prices — disappearing without explanation, sending shockwaves through the cryptocurrency community.
Manageronline has not been able to independently verify the accuracy of the transactions or the precise cause of the incident. This report is compiled primarily from empirical evidence found in the victim's post and their responses in the comment section.
The post's author recorded their feelings of devastation: "Today I checked … this morning … I'm still numb. I won't survive this round. I couldn't make it through the bear market. I kept it in a Hardware Wallet, but I wrote down the Seed in 3–4 copies and spread them around. I suspect it leaked from one of those copies somewhere."
They also revealed the backstory: the digital assets represented income earned from selling NFT work, which had been gradually accumulated and converted into Bitcoin for the future. The post closed with a note of despair:
"I don't think I'll ever be able to save up the same amount again from my own earnings. I'm worn out." A screenshot of the Sparrow Wallet showed a balance of 0 sats following a sweep transaction on 26 July 2026.
The detail that generated the most alarm and suspicion in Thailand's crypto community arose in the comments, when another user asked whether the seed in question had been generated on a Coldcard Mk3 device. The victim confirmed straightforwardly: "Yes, but that device has since broken down. I'm now using a 4" (meaning the Coldcard Mk4). When another user repeated the question to link the incident to the recently disclosed critical security vulnerability, the post's author confirmed the connection.
The crucial detail that digital finance commentators and analysts have seized upon is the transaction date shown in the screenshot, which is 26 July 2026 — before Coinkite, the device manufacturer, publicly disclosed the vulnerability on approximately 30–31 July 2026. If this timeline is accurate, it could be clear evidence that a proactive attack took place in the dark web before the manufacturer had a chance to alert consumers.
Digging deeper into the cause, Facebook user Bwebmass Bee joined the discussion and posed several technical questions to help narrow down the point of compromise — covering the method used to store seed word copies, the computer's usage history, whether the account had been shared, the risk of email being hacked, whether the additional Passphrase security feature had been enabled, and questions about a desktop screenshot despite the victim having mentioned using a mobile phone as well.
The victim's answers painted a picture of security management that was entangled with multiple risk factors. They stated that the seed had been generated directly from the hardware wallet and written down on paper, then copied from that paper to create additional copies. The computer used was approximately 4–5 years old, had never had its account shared with anyone else, and had been used alongside multiple wallet software applications, both Trezor Suite and Sparrow Wallet, with funds sent to a new address each time a transaction was made. Smaller amounts had been consolidated into 4 UTXOs as shown in the screenshot.
However, the victim admitted to not having enabled the Passphrase — the single most important additional layer of protection — and felt that even if their email had been compromised at some point, it was unlikely to be related to this incident. As for the desktop screenshot, it was taken by opening the application on a computer at the time of checking, even though the wallet had also been connected to a mobile phone at some point.
Based on these answers, analysts concluded that the overall cause remains shrouded in uncertainty and cannot be determined with 100% certainty, given that multiple risk factors overlap. These include the failure to set a Passphrase to create a second layer of defence, copying the seed onto paper multiple times which unnecessarily increased physical risk, and the deeply embedded hardware-level vulnerability in the Coldcard Mk3 itself — making it impossible to definitively state whether the primary breach stemmed from human error or a technological flaw.
Amid the loss, another Facebook user offered sympathy and shared their perspective: "This is not your fault at all. We didn't make a mistake. The mistake was the manufacturer having a vulnerability in seed generation that allowed thieves to randomly search for our seed. If they were sophisticated enough, there was nothing more we could have done." They also sent words of encouragement for the victim to get back up and fight again.
The Coldcard Mk3 user crisis
NVK, Chief Executive Officer of Coinkite, had previously issued a warning statement: "If you ever generated a seed with a Coldcard wallet, move your funds out immediately using the company's updated best practices," because the technical facts confirm that a firmware update alone cannot eliminate the risk posed by a seed that was originally generated under that vulnerability. Coldcard Mk3 holders who have not yet moved their assets therefore need to transfer their funds out as soon as possible, and should consider installing a Passphrase as an additional security layer to close the vulnerability over the long term.


