Skip to content

Coldcard Warning: Mk3 Hardware Wallet Vulnerability Exposes Seed Risk, Security Experts Investigate $38.3 Million Worth of BTC Abnormal Transfer Event

Jul 31, 10:46

July 31st, Canadian hardware wallet manufacturer Coinkite issued a security advisory, recommending users who generated their seed phrase using Coldcard Mk3 firmware versions 4.0.1 to 5.0.3 to migrate their assets as soon as possible. The company stated that preliminary analysis indicates wallets using a BIP-39 passphrase have lower risk, Mk4, Q, and Mk5 devices are unaffected, and the investigation is ongoing.

Meanwhile, security researchers are investigating an anomaly involving the transfer of 594.48 BTC (approximately $38.3 million). AnchorWatch CEO Rob Hamilton stated that within 3 blocks, the attacker moved 1324 UTXOs through 500 transactions and speculated that the issue may stem from insufficient entropy during wallet generation.

Wizardsardine CEO Kevin Loaec suggested the vulnerability may be linked to a specific software library, secure element, or a low-entropy random number generator in a particular batch of devices or firmware version, allowing attackers or AI-generated scripts to brute force affected wallets. Currently, there is no conclusive evidence linking this fund transfer directly to the Coldcard Mk3 vulnerability.

Source