Community honeypot test suggests attackers still favor easiest Coldcard Mk3 RNG targets

Community honeypot test suggests attackers still favor easiest Coldcard Mk3 RNG targets

N
News Editor
2026-08-06 10:48:54
A new community honeypot test indicates that attackers are still focusing on the easiest wallets exposed by the Coldcard Mk3 RNG flaw, according to a post by Bitcoin News on X. Researcher @ColeTU funded five affected Mk3 wallets for the test: one used only the vulnerable mnemonic, three were protected by BIP39 passphrases of one, two, and three words respectively, and one used a random account number. After 14 hours, only the unprotected wallet that relied solely on the vulnerable mnemonic had been drained. Separately, @jamesob’s live tripwire dashboard showed that only 2 out of 17 honeypot wallets had been emptied so far. The wallets confirmed as drained did not include extra entropy, while wallets protected with dice rolls, passphrases, multisig, or other added complexity had not been touched. The test suggests attackers are currently spending their effort on wallets that are easiest to brute force rather than trying to crack hardened setups. Even so, affected users are still urged to move funds immediately instead of depending on temporary safeguards.
BitcoinColdcardwallet securityRNG vulnerabilityhoneypot testBIP39on-chain security

ChainCatcher reported that Bitcoin News said in a post on X that a new community honeypot test shows attackers are still prioritizing the easiest wallets to exploit in the Coldcard Mk3 RNG vulnerability.

Researcher @ColeTU funded five affected Mk3 wallets for the test. One used only the vulnerable mnemonic. Three others were protected with BIP39 passphrases of one, two, and three words respectively. A fifth wallet used a random account number. After 14 hours, only the unprotected wallet that relied solely on the mnemonic had its funds moved out.

Separately, @jamesob’s live tripwire dashboard showed that only 2 of 17 honeypot wallets have been drained so far. The wallets confirmed as emptied did not include extra entropy, while wallets protected by dice rolls, passphrases, multisig, or other added complexity remained untouched.

The test results suggest attackers are concentrating on wallets that are easiest to brute force rather than spending resources on hardened targets. Even so, affected users should move funds immediately instead of relying on temporary protection.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.