Mk3

BitBox
2026-08-18 21:06:52

BitBox tells users to update after finding severe firmware vulnerabilities

BitBox, the Swiss hardware wallet maker, said it has fixed multiple severe security issues in its firmware and told users to update through the official BitBoxApp. The company said there have been no reports of stolen funds and that users should not panic, but it still urged all customers to install the latest firmware carefully. According to BitBox, one flaw could have allowed an attacker to manipulate users into installing firmware that could lead to theft. Another severe issue involved memory corruption in the BitBox Multi edition, which could have enabled arbitrary code execution, malicious firmware installation, and potential fund loss. BitBox said its Bitcoin-only edition was not affected because the relevant code is not present in that firmware. The disclosure comes as the Bitcoin wallet sector is still dealing with fallout from a separate Coldcard firmware bug disclosed by Coinkite. In that case, users were told to move funds after weak seed generation exposed wallets to theft. BitBox said its situation is different: users do not need to migrate funds, only update their device firmware.

30
BitBox tells users to update after finding severe firmware vulnerabilities
Bitcoin
2026-08-15 18:20:48

Prince Filip says he learned of COLDCARD hack while on vacation

Bitcoin News said in a post on X that Prince Filip learned about a hack involving COLDCARD while he was on vacation. According to the post, he was using the Mk3 model at the time and faced the risk that all of his bitcoin could have been stolen at any moment. The brief report, cited by ChainCatcher, did not include additional details on the incident, the scope of the attack, or any follow-up response. No further information was provided in the source text beyond the statement posted on X and the reference to Prince Filip’s status as an Mk3 user.

60
Prince Filip says he learned of COLDCARD hack while on vacation
Trezor
2026-08-14 11:06:07

Trezor says 13,689 customers were exposed in ShipMonk breach as shipping label practices draw new scrutiny

Trezor disclosed on Aug. 13 that its logistics partner ShipMonk suffered unauthorized access to a system holding customer information, affecting 13,689 people. The exposed data fell into two groups: 11,742 customers had their full names, email addresses, phone numbers and full shipping addresses exposed, while 1,947 had their names, city and email addresses exposed. Trezor said its own systems, products and services were not compromised, and that hardware wallets, private keys and wallet backups were not part of the incident. The disclosure came two days after a user posted that the outer label on a domestically shipped Trezor Safe 3 package explicitly read "Trezor Safe 3 Bitcoin Only" instead of a generic product description. There is no confirmed direct link between the shipping-label complaint and the ShipMonk breach, but together they highlight the same problem: a hardware wallet may protect private keys, while purchase, fulfillment and delivery processes can still connect the device to a real-world identity. The episode has also fed a broader debate over hardware-wallet risk. Recent incidents involving Trezor, Coldcard and Ledger did not stem from the same failure point. Some relate to device or firmware security, while others involve third-party commerce, logistics or packaging exposure. For affected users, the most immediate concern is targeted phishing and social-engineering attempts that use real names, addresses, order details and device information to appear credible.

60
Trezor says 13,689 customers were exposed in ShipMonk breach as shipping label practices draw new scrutiny
SlowMist
2026-08-12 07:26:48

SlowMist says ColdCard private key flaw may trace back to build setting that disabled hardware RNG

SlowMist said ColdCard, a hardware wallet maker, was hit by a major private key vulnerability that led to losses of about 1,719 BTC. Using Mk3 firmware version 4.1.9 as an example, the security team said it fully reproduced the attack chain and traced the issue to a build configuration error. According to SlowMist, the setting "MICROPY_HW_ENABLE_RNG" was set to 0, which disabled the STM32 hardware true random number generator. That forced the random number path to fall back to the Yasmarang software pseudo-random number generator, which SlowMist described as not cryptographically secure. The team said its state was almost entirely predictable, cutting effective entropy to about 40 bits on Mk2 and Mk3 devices, or about 72 bits on Mk4, Mk5, and Q models. SlowMist said attackers could model keypress consumption patterns, use GPU clusters to brute-force the candidate space, derive private keys, and then match single-signature P2WPKH addresses across the network to steal funds. The firm urged affected users to upgrade to fixed firmware, create a new mnemonic, and move funds only after confirming the new address works properly.

490
SlowMist says ColdCard private key flaw may trace back to build setting that disabled hardware RNG
Policy and Re
2026-08-12 02:01:39

SEC Set to Review Crypto Fundraising Exemption as Judge Limits CFTC Reach in Kalshi Sports Contracts

The U.S. Securities and Exchange Commission is set to hold a public meeting on Aug. 14 to consider a proposed "Regulation Crypto" framework that would let some crypto projects raise capital without completing a full securities registration process. If advanced for public comment, it would become the SEC’s first formal, durable rulemaking effort aimed specifically at the crypto sector. The proposal would also outline a route for projects to exit SEC oversight once developers stop actively managing the network and the project becomes decentralized. SEC Chair Paul Atkins has previously said the exemption period could last as long as four years, though no fundraising cap was disclosed. On the litigation front, a federal judge in Connecticut ruled that Kalshi’s sports-event contracts are not swaps under the Commodity Exchange Act, meaning the Commodity Futures Trading Commission did not obtain exclusive jurisdiction on that basis. The decision lands as Kalshi remains under pressure in New York, where the CFTC said it used “emergency powers” to require the prediction-market operator to continue operating after the company sought assistance following a lawsuit from New York Attorney General Letitia James. Elsewhere, the market snapshot showed broad declines among major tokens over the past 24 hours, while project, funding, security and AI headlines spanned Bitwise layoffs, a reported COLDCARD Mk3 wallet flaw, Hyperliquid and Robinhood Chain user metrics, and a string of new financings across crypto, AI and financial infrastructure.

640
SEC Set to Review Crypto Fundraising Exemption as Judge Limits CFTC Reach in Kalshi Sports Contracts
Coldcard
2026-08-11 20:02:55

Coldcard Mk3 Vulnerability Could Generate Identical Mnemonics; ~4.5M Seed States Scannable in 3 Seconds

Bitcoin News shared on X a technical analysis by @KLoaec finding that some vulnerable Coldcard Mk3 wallets may derive from only ~4.5 million RNG starting states, searchable in about 3 seconds on a single RTX 4090. Even with extra per-wallet uncertainty, an attacker could finish the search on a high-end GPU in ~50 minutes. The flaw could cause different devices to generate identical mnemonics; assuming 30,000 Mk3 units, roughly 120 pairs may produce the same random stream.

540
Coldcard Mk3 Vulnerability Could Generate Identical Mnemonics; ~4.5M Seed States Scannable in 3 Seconds
Bitcoin
2026-08-08 13:02:42

Bitcoin New Wallet Count Hits 2026 High as Coldcard Bug Tied to $116M in Losses

Bitcoin's on-chain activity jumped this week, with new wallets reaching 2.27 million, the highest so far in 2026, and active wallets hitting 751,000, a multi-month high, according to Odaily. Active addresses peaked at nearly 978,000 on July 31, roughly 1.6 times the July daily average. The first week of August averaged about 751,000 active wallets, above July's average of around 610,000. Daily exchange inflows averaged $1.55 billion, down from $1.67 billion in July, suggesting the activity was not accompanied by obvious exchange buying. The surge is linked to a firmware vulnerability in Coinkite's Coldcard hardware wallets affecting some Mk3, Mk4, Mk5 and Q devices. The bug involves seed generation using a software random number generator, reducing effective entropy to roughly 40 or 72 bits on affected units. Since July 30, related bitcoin losses have exceeded $116 million. Holders of affected devices have moved funds to new addresses and switched to unaffected hardware. Coinkite has released a firmware fix and an entropy remediation disclosure. The flaw is a device-level random number generation issue, not a defect in the Bitcoin protocol layer.

580
Bitcoin New Wallet Count Hits 2026 High as Coldcard Bug Tied to $116M in Losses
Coldcard
2026-08-07 15:44:47

Galaxy Research: Coldcard Flaw Tied to 1,719 BTC Stolen, Losses May Top $130M

According to a new disclosure from Galaxy Research, approximately 1,719 bitcoin, worth roughly $111 million, were stolen through a vulnerability in Coldcard hardware wallets, based on victim reports the firm says it treats with high confidence. Additional suspicious funds are still being reviewed and verified, and total losses could surpass $130 million. More than 250 victims have filed reports with Galaxy so far. On-chain data shows no records of stolen coins being created before the affected Coldcard firmware was released on March 17, 2021, which the firm identifies as the release date of the vulnerable version. Galaxy added that there is currently no evidence linking the vulnerability to signing devices or wallets beyond the Coldcard Mk3, Mk4, Mk5, and Q models. The incident appears limited to those devices running firmware versions released after that date, leaving earlier firmware releases unaffected.

590
Galaxy Research: Coldcard Flaw Tied to 1,719 BTC Stolen, Losses May Top $130M