Loading IndicatorLoading Indicator

Coinkite Issues Coldcard Mk3 Security Warning as $38.3 Million Bitcoin Transfer Is Investigated

Source
YM Lee

Forecast Trend Report by Period

Loading IndicatorLoading Indicator
Photo: Shutterstock
Photo: Shutterstock

Coinkite said seed phrases generated on Coldcard Mk3 devices running firmware version 4.0.1 or later, released in March 2021, may be at risk of theft, Cointelegraph reported on July 31. Affected versions extend through 5.0.3, the final supported release for the Mk3. The warning does not apply to the Mk4, Q or Mk5.

The alert came as security researchers investigate the unexplained transfer of 594.48 Bitcoin from a single-signature address. The holdings were worth about $38.3 million based on CoinGecko prices. So far, there is no official evidence that an Mk3 flaw caused the transfer.

Coinkite advised affected users to generate a new seed on an unaffected device as a precaution. Users should verify backups and receiving addresses, send a small test transaction first, and then move the rest of their funds. The company added that the investigation is continuing and that it plans to release the results of an official technical review later.

The case drew attention after a Reddit user reported that funds had been drained from a wallet created with a seed generated on an Mk3 purchased in May 2021. The user said the seed was restored to an Mk4 in January 2026. That statement alone does not prove a link to an Mk3 flaw.

AnchorWatch Chief Executive Officer Rob Hamilton wrote that 1,324 unspent transaction outputs were swept across 500 transactions within three blocks. Of those, 562 Bitcoin was later consolidated into a single address. At first glance, the wallet creation process appears to have suffered from an entropy flaw at some point, he added.

Wizardsardine Chief Executive Officer Kevin Loaec said a low-entropy random number generator in a software library, secure element, specific device batch or firmware version may have produced seeds with insufficient randomness. If that hypothesis is correct, wallets that were only partially drained could remain at risk of further losses. Funds held in other address types could also be exposed if the attacker broadens the scope of scanning.

#Cold Wallet
YM Lee

YM Lee

20min@bloomingbit.ioCrypto Chatterbox_ tlg@Bloomingbit_YMLEE

What do you think about this news?








PiCK News






Hashtag News