Coinkite warned Coldcard Mk3 users to move funds following a 594.5 Bitcoin(BTC) sweep from 500 addresses and evidence of weak seed generation. Key Points: Every Mk3 firmware release since ver
Coinkite warned Coldcard Mk3 users to move funds following a 594.5 Bitcoin(BTC) sweep from 500 addresses and evidence of weak seed generation.
Key Points:
- Every Mk3 firmware release since version 4.0.1 may have generated vulnerable seeds.
- Mk4, Mk5 and Q users with older firmware must update their devices, generate new seeds and migrate funds.
- No multisig or Taproot wallets appeared among the reported victims.
Coldcard Seed Risk
Coinkite said in a security advisory that every Mk3 firmware version since 4.0.1, released in Mar. 2021, is affected by an entropy problem tied to device-generated wallet seeds. Seeds created on Mk4 and Mk5 before version 5.6.0, or on Q before 1.5.0Q, also face serious risk.
The company said affected seeds contained about 72 bits of entropy instead of the expected 128 bits, although the impact differs by model. TAPSIGNER, OPENDIME and SATSCARD are not affected because they use separate codebases. A firmware update cannot repair an existing seed.
Users should install fixed firmware before generating a replacement seed, then back it up, verify a receive address on the device and send a small test transaction.
Mk3 owners without another device can temporarily use a strong, unique BIP-39 passphrase, but Coinkite still recommends moving to a newly generated seed.
Also Read:Bitcoin ETFs Absorb $233.1M As A Single Fund Supplies Most Of It
Bitcoin Theft Impact
Atlas21reported that an automated operation swept 500 single-signature addresses across blocks 960188 through 960191 on Jul. 30. The transactions consumed 1,324 UTXOs and moved 594.5 BTC, valued near $38 million, while costing about 0.044 BTC in fees. No multisig or Taproot addresses were identified.
The median victim lost 0.41 BTC, while 110 addresses lost more than one Bitcoin and the largest loss reached 29.9 BTC. Atlas21 said the transaction pattern pointed to weak private keys generated when the wallets were created. The first public report came from a user whose 24-word seed was generated on a Coldcard in 2021 and never entered on a computer.
The incident matters because offline storage cannot protect funds when the underlying seed lacks sufficient randomness. Coinkite’s warning covers wallets created over more than five years, leaving owners exposed until they migrate, while Bitcoin’s market price remained near $64,000 after the sweep.
Read Next:Polymarket Traders Give Spider-Man A 91% Shot At A Historic Debut