Hardware Wallet Maker Alerts Users to Seed Generation Vulnerability Following $38 Million Bitcoin Sweep
Coinkite urges Coldcard Mk3 users to move funds after discovering a potential security flaw affecting seed generation, as security experts investigate a coordinated theft of hundreds of Bitcoin addresses.
Coinkite Issues Urgent Hardware Wallet Security Warning
Canadian Bitcoin hardware manufacturer Coinkite has issued a critical advisory to users of its Coldcard Mk3 signing device, urging them to relocate funds due to a discovered vulnerability in the seed-generation process. The company identified a potential security risk affecting wallets whose seed phrases were created on specific Mk3 firmware versions. Users whose devices ran firmware version 4.0.1 or any later Mk3 version through 5.0.3—the final version supporting the Mk3—may face potential fund exposure, the manufacturer warned. Importantly, the Mk4, Q, and Mk5 hardware models remain unaffected by this vulnerability.
The affected firmware traces back to March 2021, when version 4.0.1 was released. Coinkite recommends that affected users exercise caution by generating a new seed phrase on an unaffected device, carefully verifying the backup and receiving address, conducting a test transaction with a small amount, and only subsequently transferring remaining holdings. The company stressed that wallets using a BIP-39 passphrase face minimal risk—an important distinction between a passphrase, which adds additional security layers, and the device’s standard PIN protection.
$38 Million Bitcoin Drain Prompts Analysis and Speculation
Cryptocurrency security specialists are examining a coordinated and unexplained sweep involving 594.48 BTC—approximately $38 million in value—from single-signature addresses. The theft occurred within a compressed three-block window across 500 separate transactions, with 562 BTC subsequently consolidated into another address. Though one Reddit user reported their Mk3-generated wallet seed was drained after being restored to an Mk4 device, no definitive public evidence has established a causal connection between the Coldcard vulnerability and the broader sweep.
AnchorWatch CEO Rob Hamilton offered preliminary analysis, observing that the scale and coordination suggested “flawed entropy in wallet generation somewhere along the way.” Wizardsardine CEO Kevin Loaec theorized the attack may have originated from a low-entropy random-number generator—potentially embedded in a software library, secure element, or a specific device batch or firmware version—that generated seeds with insufficient randomness.
Attack Methodology and Lingering Vulnerabilities
Loaec’s analysis suggested an attacker with knowledge of the flaw may have deployed an artificial intelligence-powered script to brute-force compromised wallets, though the targeting appeared narrowly focused on a limited range of BIP-84 derivation paths. This constraint could explain why the drain concentrated in native SegWit addresses and why certain wallets experienced only partial drainage. If this hypothesis proves correct, wallets showing partial drainage may remain exposed to future theft, and funds held in alternative address formats could become vulnerable if attackers expand their methodology.
Hardware wallet vulnerabilities affecting entropy and seed generation represent an existential threat to any cryptocurrency holder, regardless of whether they hold Bitcoin, Ethereum, XRP, or other digital assets stored on compromised devices.
Source: Cointelegraph. Not financial advice.