594 BTC stolen as Coldcard Mk3 security flaw comes to light
Hardware wallet manufacturer Coinkite has issued an urgent warning to Coldcard Mk3 users: anyone who created a seed on this device between March 2021 and the latest firmware version 5.0.3 may be at risk. The warning comes at an unfortunate time, as researchers are simultaneously investigating the theft of 594 Bitcoin in which hundreds of single-signature wallets were completely drained.
Bitcoin is available at OKX and Bybit.
In brief:
- Coinkite warns that Coldcard Mk3 devices with firmware 4.0.1 up to and including 5.0.3 contain a flaw in seed generation, which could put funds at risk.
- 1,196 wallets are drained within 41 minutes for a total of 1,082.65 BTC, worth approximately $70.2 million.
- An official link between the theft and the security vulnerability has not yet been confirmed; the investigation is still ongoing.
Seed generation flaw affects Mk3 users
According to Coinkite, the problem lies specifically in the way the Mk3 generates seeds on firmware versions 4.0.1 up to and including 5.0.3. That is the last version supported by the Mk3. According to the company’s preliminary analysis, newer models such as the Mk4, Q and Mk5 are not affected. Users who still have funds in a potentially compromised wallet are advised to transfer them to a secure address as soon as possible.
There is some reassurance for those using a BIP-39 passphrase: Coinkite states that the risk is minimal in that case. This specifically concerns the passphrase, not the device’s PIN. The company advises keeping that phrase secret and never entering it on a website or an untrusted device. A formal technical analysis will follow as soon as possible, according to Coinkite on its blog.
Massive theft of 1,082 BTC in 41 minutes
While Coinkite is still investigating, Galaxy Research has published an analysis of a notable series of transactions on 30 July. Within a 41-minute timeframe, 1,196 wallets were completely drained. In total, 1,082.65 BTC disappeared, amounting to approximately $70.2 million at the time. That is considerably more than the previously mentioned 594 BTC, as the full scale of the leak turns out to be larger than initially reported.
What is striking about the transactions is that they all apply exactly the same fee rate: 30 sat/vB. In addition, they produce no change, which strongly indicates that an automated system is systematically draining the private keys rather than carrying out manual transfers. The stolen Bitcoin was ultimately consolidated into four addresses and has remained dormant since. A direct link to the Coldcard vulnerability has not yet been established; the theft took place roughly thirty hours before Coinkite made the security problem public.
What can you do as an Mk3 user?
If you have ever owned a Coldcard Mk3 and created a wallet on it after March 2021, it is wise to take action now. Transfer your funds as soon as possible to a wallet created on an unaffected device or via other software. Read more about the background to this security vulnerability for further context.
At the time of writing, Bitcoin is trading at $63K, down 2.7% over the past 24 hours. Whether the uncertainty surrounding this vulnerability is playing a role in that price movement is unclear, but the combination of a major security incident and an ongoing investigation is certainly causing unease among Bitcoin users.
Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.
Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.