Key facts
- Coinkite issued a warning for its Coldcard Mk3 hardware wallet due to a potential seed-generation risk.
- The risk is associated with firmware versions 4.0.1 up to 5.0.3 on the Mk3 model; Mk4, Q, and Mk5 are unaffected.
- Users are advised to migrate funds to wallets generated on unaffected devices.
- Security experts are investigating a recent sweep of approximately $38.3 million worth of Bitcoin from single-signature addresses.
- The drained Bitcoin was consolidated into a single address, with some wallets only partially drained.
Canadian Bitcoin hardware manufacturer Coinkite has issued a warning to users of its Coldcard Mk3 signing device, advising them to migrate funds due to a potential risk in seed phrase generation. The company indicated that seeds created on Mk3 devices running firmware version 4.0.1 (released March 2021) through version 5.0.3, the final version for the Mk3, may be at risk. Devices like the Mk4, Q, and Mk5 are not affected, according to Coinkite's initial analysis.
This warning coincides with an ongoing examination by Bitcoin security specialists into a coordinated sweep of approximately $38.3 million worth of Bitcoin (594.48 BTC) from single-signature addresses. While the sweep has drawn attention, no definitive link has been publicly established between the Coldcard Mk3 firmware issue and these specific transfers.
Coinkite recommends that affected users generate a new seed on an unaffected device, verify its backup, send a small test transaction, and then transfer the remaining funds. The company stated its investigation is continuing and a formal technical review will be provided. Early analysis suggests that seeds used with a BIP-39 passphrase have minimal risk, distinguishing this from the Coldcard PIN.
Security experts are exploring potential causes for the large Bitcoin sweep. Rob Hamilton, CEO of AnchorWatch, noted that 1,324 unspent transaction outputs were swept across 500 transactions within a three-block period. He suggested a potential flaw in wallet generation entropy. Kevin Loaec, CEO of Wizardsardine, hypothesizes that a low-entropy random-number generator, possibly within a specific device batch or firmware version, could have produced insufficient randomness in wallet seeds. Loaec further suggested that an attacker aware of such a flaw might have used an AI-generated script to brute-force wallets, potentially explaining the concentration in native SegWit addresses and partial drains observed in some cases. He cautioned that partially drained wallets might still be at risk.