00:00
The Financial Ways
The Financial Ways
USD/RUB
EUR/RUB
Cryptocurrency

Coinkite Urges Coldcard Mk3 Users to Migrate Amid Security Concerns

Nearly 600 Bitcoin worth $38 million vanished in a rapid, coordinated sweep, prompting hardware manufacturer Coinkite to issue an urgent warning. The company advised Coldcard Mk3 owners to move funds if their seed phrases were generated using firmware versions 4.0.1 through 5.0.3, citing potential vulnerabilities in key generation.

Coinkite Urges Coldcard Mk3 Users to Migrate Amid Security Concerns

While the $38.2 million drain occurred in a tight three-block window, Coinkite and independent security researchers have yet to establish a definitive link between the massive theft and the specific flaw in the Mk3 firmware. The incident involved 594.48 BTC moved across 500 transactions from single-signature addresses. AnchorWatch CEO Rob Hamilton noted the pattern suggests potential issues with entropy during wallet generation, a sentiment echoed by Wizardsardine CEO Kevin Loaec, who pointed to a possible failure in software libraries or device randomness.

Coinkite clarified that its newer models—the Mk4, Q, and Mk5—remain unaffected by this advisory. For users currently holding assets on vulnerable Mk3 devices, the company recommends migrating funds to a new seed generated on secure hardware. Those unable to switch devices immediately are encouraged to utilize a strong, unique BIP-39 passphrase, which the company claims mitigates risk, or to employ a dice-roll method to generate a new, hardware-independent seed. As the investigation continues, experts draw parallels between this event and previous entropy-related failures like the Randstorm vulnerability, though a formal technical root-cause analysis from Coinkite is still pending.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!