Build with CoinStats’ all-in-one API. Learn more

Deutsch한국어日本語中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçePortfolio TrackerSwapCryptocurrenciesPricingCrypto APIIntegrationsNewsEarnBlogNFTWidgetsDeFi Portfolio TrackerCrypto Gaming24h ReportPress KitAPI Docs
CoinStats

Coinkite Warns Coldcard Mk3 Users As Block Traces Up To 1,083 BTC In Drains

bullish:

0

bearish:

0

Coldcard Mk3 seeds created on firmware 4.0.1 through 5.0.3 may be exposed as Block examines up to 1,083 BTC in drains.

Coinkite has warned every user who generated a seed on a Coldcard Mk3 running firmware 4.0.1 through 5.0.3 to treat the wallet as potentially exposed and migrate its bitcoin. The security advisory followed research by Block’s Bitcoin engineering and security teams, which identified weak seed-generation behavior while investigating remotely drained wallets.

Coinkite’s immediate warning covers Mk3 firmware released from March 2021 onward. The company’s early analysis says Mk4, Q and Mk5 devices are not affected by the issue behind its advisory, while Block researchers described two weaknesses reaching Coldcard generations at different severity levels. Block said no Bitkey or other Block products are affected.

Developers Reproduce Predictable Mk3 Seed Generation

Bitcoin Core developer Gregory Sanders, known as instagibbs, reproduced the Mk3 weakness on a freshly initialized device using only the number of keypad presses made during setup. He said Mk2 and Mk3 users should treat the exposure as urgent, while the Mk4’s status had not been confirmed through his test.

Developer Antoine Poinsot identified a hardware difference in the newer model: Mk4 seed generation uses the microcontroller’s true random number generator, while Mk3 firmware did not use that source in the same way. Coinkite’s March 2021 release notes show version 4.0.0 replaced all cryptographic and BIP-39 code with new equivalents. Foundation Devices CEO Zach Herbert traced the apparent entropy defect to the same 120-file rewrite, while stressing that no evidence ties the error itself to the licensing change.

Block Traces Potential Drain Scope To 1,083 BTC

The first identified sweep moved 594.48 BTC from 500 single-signature addresses across Bitcoin blocks 960188 to 960191. Atlas21 counted 1,324 spent UTXOs and found that 562 BTC was consolidated into another address before the sequence ended.

Block engineer Clay Garrett later flagged 695 earlier transactions carrying the same full fingerprint as the known set. Those transfers moved another 488.10957948 BTC, lifting the potential combined scope to 1,082.58680432 BTC if both groups belong to the same operation. The total was worth about $69.6 million with bitcoin trading near $64,247.

Coinkite has not established that the firmware weakness caused every transaction in either set. Block’s team said the attack was likely ongoing, and the broader transaction group remains under verification.

Affected Seeds Must Be Replaced, Not Reimported

Moving an affected recovery phrase into another hardware or software wallet does not repair it because the underlying seed remains predictable. The defect concerns seed creation, unlike SparkKitty malware searching phone images for recovery phrases or BlueNoroff campaigns profiling wallets through fake meeting calls.

Coinkite recommends generating a fresh seed on an unaffected device, recording and verifying the backup, checking a receive address, sending a small test transaction and only then moving the remaining balance. Users unable to migrate immediately can create a strong, unique BIP-39 passphrase as an interim measure. Advanced users may generate a dice-only seed on an empty Mk3 running firmware 4.1.9 with at least 99 independent rolls.

The post Coinkite Warns Coldcard Mk3 Users As Block Traces Up To 1,083 BTC In Drains appeared first on Crypto Adventure.

bullish:

0

bearish:

0

Manage all your crypto, NFT and DeFi from one place

Securely connect the portfolio you’re using to start.