Build with CoinStats’ all-in-one API. Learn more

Deutsch한국어日本語中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçePortfolio TrackerSwapCryptocurrenciesPricingCrypto APIIntegrationsNewsEarnBlogNFTWidgetsDeFi Portfolio TrackerCrypto Gaming24h ReportPress KitAPI Docs
CoinStats

COLDCARD Hardware Wallet Confirms High Security Risk: Next Step for Users

59m ago
bullish:

0

bearish:

0

Canadian bitcoin hardware wallet company Coinkite has warned Coldcard Mk3 users after a suspected security vulnerability was linked to the loss of approximately $38 million. The issue reportedly affected certain Mk3 devices that generated wallet seeds using a vulnerable process. 

The company has, however, assured that newer Coldcard models remain unaffected. Security researchers, however, continue to investigate how attackers exploited the weakness and gained access to millions of dollars in BTC. 

Massive $38M Bitcoin Theft Exposed

Coinkite is known for making security products for Bitcoin, including the COLDCARD hardware wallet, TAPSIGNER, SATSCARD, OPENDIME, SEEDPLATE, and BLOCKCLOCK. The recently discovered seed-generation problem only affects the COLDCARD wallet lineup.

The issue is not about hackers breaking into the devices, but rather how wallet recovery seeds were created in certain firmware versions. A wallet seed is the main recovery phrase that creates the private keys used to control Bitcoin. If an attacker can guess or recreate that seed, they can access the wallet and transfer its funds without the physical device. 

Coinkite warns that the biggest risk is with COLDCARD Mk3 devices using firmware version 4.0.1 or later, which was released in March 2021. Blockchain investigators linked the breach to the theft of 594 BTC, worth $38 million. The funds were swept from 500 single-signature addresses, making it one of the largest known losses related to hardware wallets.

Coinkite Recommends Next Step for Users

The incident has raised concerns among Coldcard users. Coinkite, however, stated that its investigation found no evidence that newer devices, such as Coldcard Mk4, Mk5, and Q models, were affected by the same problem. The company is currently working with security experts to better understand the issue and provide more technical details. 

Coinkite also mentioned that there is no firmware fix planned for the Mk3 device. The team encourages affected users to take the following measures: 

  • Verify if a COLDCARD Mk3, Mk4, Mk5, or Q generated its seed using firmware version 4.0.1 or later.
  • Transfer Bitcoin from any potentially affected wallets to a newly created secure wallet.
  • Use a strong BIP-39 passphrase as a temporary protection measure in case of any difficulties in moving the funds immediately. 
  • Never share your wallet recovery phrase or private keys with anyone.
  • Only follow official security updates and guidance from Coinkite.

The warning highlights that hardware wallets are one of the safest methods for storing Bitcoin. However, their security relies on secure seed generation and responsible user practices. As investigations continue, Coinkite urges affected users to take steps to protect their holdings to prevent further losses.

The post COLDCARD Hardware Wallet Confirms High Security Risk: Next Step for Users appeared first on CoinTab News.

59m ago
bullish:

0

bearish:

0

Manage all your crypto, NFT and DeFi from one place

Securely connect the portfolio you’re using to start.