Coinkite, the Canadian hardware wallet maker behind Coldcard, issued a security warning on July 31 urging users of the Coldcard Mk3 to move funds if their seed phrases were generated on firmware versions 4.0.1 through 5.0.3. The company said its preliminary analysis suggests wallets protected with a BIP-39 passphrase face lower risk, while Mk4, Q and Mk5 devices are not affected. At the same time, security researchers are examining an unusual transfer involving 594.48 BTC, worth about $38.3 million. AnchorWatch CEO Rob Hamilton said the attacker moved 1,324 UTXOs through 500 transactions within three blocks and suggested the issue may stem from insufficient randomness during wallet generation. Wizardsardine CEO Kevin Loaec said the flaw could be tied to a software library, a secure chip, or a low-entropy random number generator linked to a specific device batch or firmware version. He also said AI-generated scripts may have been used to brute-force affected wallets. No conclusive evidence has yet linked the transfer directly to a Coldcard Mk3 flaw.
Coinkite, the Canadian hardware wallet maker, issued a security warning on July 31 and urged users to move funds if they use a Coldcard Mk3 and generated their seed phrases on firmware versions 4.0.1 through 5.0.3.
Scope of the warning
The company said its preliminary analysis suggests wallets using a BIP-39 passphrase face lower risk. It added that Mk4, Q and Mk5 devices are not affected. The investigation is still ongoing.
Researchers review unusual 594.48 BTC movement
At the same time, security researchers are looking into an unusual transfer involving 594.48 BTC, worth about $38.3 million.
AnchorWatch CEO Rob Hamilton said the attacker moved 1,324 UTXOs through 500 transactions within three blocks. He suggested the issue may trace back to insufficient entropy during wallet generation.
Wizardsardine CEO Kevin Loaec said the flaw may be related to a software library, a secure chip, or a low-entropy random number generator tied to a specific device batch or firmware version. He also said the attacker may have used AI-generated scripts to brute-force affected wallets.
So far, there is no conclusive evidence linking the fund movement directly to a Coldcard Mk3 vulnerability.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.