
Coinkite published a security advisory on Thursday, warning of an ongoing issue affecting seeds generated on Coldcard Mk3 devices.
"Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk," the crypto hardware maker wrote.
Coinkite said the issue exists through firmware version 5.0.3, which is the final release that supported the Mk3. "Mk4, Q and Mk5 are not affected based on our early analysis of the issue," the company said.
Users who applied a BIP-39 passphrase to an affected Mk3 seed face limited exposure, Coinkite added.
594 BTC
The advisory post followed multiple online and social media reports earlier on July 30 of bitcoin being drained from users' Coldcard wallets. According to a report from Atlas 21, approximately 594.5 BTC ($38.3 million) was swept from 500 single-signature addresses in a coordinated series of transactions spanning Bitcoin blocks 960188 to 960191.
While Coinkite has not confirmed the link between the theft and the security issue, some blockchain experts have associated the drains with weak entropy in seeds generated on Coldcard Mk3 devices.
Bitcoin developer James O'Beirne wrote on X that users whose bitcoin was secured by a single key generated on a Coldcard Mk3 between 2021 and 2023 — without dice rolls, a passphrase, or multi-signature — need to move funds as soon as possible. While Coinkite's early analysis excludes Mk2 and Mk4, O'Beirne said those models may also be affected.
Separately, Clay Garrett of Block's engineering and security team wrote that the company identified an additional set of transactions that could form part of a Coldcard-related drain.
"There are 695 earlier transactions with the same full fingerprint that transactions in the known set had," Garrett said. "These transactions moved another 488.10957948 BTC. If this is part of the same attack, it'd bring the total to 1,082.58680432 BTC."
Recommendations
In its latest advisory note, Coinkite recommended that Mk3 users create a strong, unique BIP-39 passphrase on the device and move funds to the resulting wallet.
As an advanced option, users may generate a replacement seed on an empty Mk3 running firmware 4.1.9 via the dedicated dice-roll path, entering at least 99 independent rolls of a fair six-sided die. This method hashes the roll sequence directly and does not use the device's random-number generator.
Coinkite said the preferred long-term approach is migration to a new seed generated on an unaffected Coldcard model. The team advised: "When migrating to a new key, calm and care should be applied. Rushing a wallet migration can create a more immediate risk than the issue you are trying to address."
The exact cause of the security issue has yet to be confirmed by the team. "We are continuing to investigate. More details will follow," Coinkite added.
'Funds may be at risk': Coinkite issues warning for Coldcard Mk3 users amid 594 BTC theft reports Coinkite published a security advisory on Thursday, warning of an ongoing issue affecting seeds generated on Coldcard Mk3 devices. "Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk," the crypto hardware maker wrote. Coinkite said the issue exists through firmware version 5.0.3, which is the final release that supported the Mk3. "Mk4, Q and Mk5 are not affected based on our early analysis of the issue," the company said. Users who applied a BIP-39 passphrase to an affected Mk3 seed face limited exposure, Coinkite added. 594 BTC The advisory post followed multiple online and social media reports earlier on July 30 of bitcoin being drained from users' Coldcard wallets. According to a report from Atlas 21, approximately 594.5 BTC ($38.3 million) was swept from 500 single-signature addresses in a coordinated series of transactions spanning Bitcoin blocks 960188 to 960191. While Coinkite has not confirmed the link between the theft and the security issue, some blockchain experts have associated the drains with weak entropy in seeds generated on Coldcard Mk3 devices. Bitcoin developer James O'Beirne wrote on X that users whose bitcoin was secured by a single key generated on a Coldcard Mk3 between 2021 and 2023 — without dice rolls, a passphrase, or multi-signature — need to move funds as soon as possible. While Coinkite's early analysis excludes Mk2 and Mk4, O'Beirne said those models may also be affected. Separately, Clay Garrett of Block's engineering and security team wrote that the company identified an additional set of transactions that could form part of a Coldcard-related drain. "There are 695 earlier transactions with the same full fingerprint that transactions in the known set had," Garrett said. "These transactions moved another 488.10957948 BTC. If this is part of the same attack, it'd bring the total to 1,082.58680432 BTC." Recommendations In its latest advisory note, Coinkite recommended that Mk3 users create a strong, unique BIP-39 passphrase on the device and move funds to the resulting wallet. As an advanced option, users may generate a replacement seed on an empty Mk3 running firmware 4.1.9 via the dedicated dice-roll path, entering at least 99 independent rolls of a fair six-sided die. This method hashes the roll sequence directly and does not use the device's random-number generator. Coinkite said the preferred long-term approach is migration to a new seed generated on an unaffected Coldcard model. The team advised: "When migrating to a new key, calm and care should be applied. Rushing a wallet migration can create a more immediate risk than the issue you are trying to address." The exact cause of the security issue has yet to be confirmed by the team. "We are continuing to investigate. More details will follow," Coinkite added. #Bitcoin #BTC #Coldcard #Coinkite #HardwareWallet #CryptoSecurity #CyberSecurity #Blockchain #CryptoNews #Animalverse