mimile
Back to feed
This event is part of a larger story
Франция, Казахстан, Польша: кибератаки раскрыли данные сотен тысяч
Read briefing

Coinkite warns Coldcard Mk3 owners of seed flaw, urges Bitcoin migration

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Coinkite warns Coldcard Mk3 owners of seed flaw, urges Bitcoin migration

Coinkite has warned owners of Coldcard Mk3 hardware wallets about a flaw in seed generation that allows attackers to recreate private keys. The company urges affected users to generate new seeds and move all Bitcoin to new wallets immediately. Affected firmware versions include Mk3 on 4.0.1+, as well as Mk4, Mk5, and Q devices on older firmware.

The Seed Generation Flaw

The vulnerability stems from a weakness in the seed generation process on affected Coldcard devices, allowing an attacker to predict the seed phrase. Bitcoin Core contributor instagibbs confirmed he was able to recreate a vulnerable seed on a newly initialized Mk3. The flaw undermines the wallet’s air gap security, as weak randomness narrows the field of possible seeds, enabling an attacker to derive candidate addresses and monitor them for deposits from another computer. Once a match is found, the attacker can spend the funds without physical access to the device. Coinkite has not yet disclosed the root cause but plans a formal technical review.

Affected Devices and Mitigations

The primary risk affects Mk3 devices with seeds generated on firmware 4.0.1 or later, especially those using single-signature wallets with no additional entropy sources. Mk4 and Mk5 devices are affected before firmware 5.6.0, and Q devices before 1.5.0Q, although the impact is less severe. Coinkite states that a strong, unique BIP-39 passphrase adds an independent barrier, but common or short passphrases remain guessable. Multisig setups can limit exposure if spending requires independent keys, and user-supplied dice entropy (at least 99 fair rolls) provides an external randomness source. However, the company advises all affected users to migrate funds to newly generated seeds regardless of existing protections.

What's Next

Coinkite is expected to release a detailed technical report on the root cause in the coming weeks. It remains unclear how many users are affected or whether any funds have been stolen due to the flaw.

1 source

Coinkite warns Coldcard Mk3 owners of seed flaw, urges Bitcoin migration