Coinkite Issues Security Advisory for Coldcard Mk3 Following Potential Seed Phrase Vulnerability

AI Market Summary
Coinkite warned Coldcard Mk3 users on firmware 4.0.1–5.0.3 to migrate funds due to a potential seed-generation weakness, with suspicion around low-entropy randomness; Mk4/Q/Mk5 are unaffected. Researchers also flagged an unusual 594.48 BTC movement, though no direct link is proven. The advisory increases perceived self-custody operational risk, potentially raising near-term on-chain churn and security-driven selling pressure.
Impact level
● Medium
Affected assets
BTC/USDT+0.33%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
On July 31, Canadian hardware wallet manufacturer Coinkite issued a critical security advisory for Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3, urging users to migrate funds immediately due to potential seed phrase exposure. According to BlockBeats, Coinkite noted that wallets utilizing BIP39 passphrases may face lower risk, while newer models like the Mk4, Q, and Mk5 remain unaffected. Simultaneously, security researchers are investigating the suspicious movement of 594.48 BTC, valued at approximately $38.3 million. AnchorWatch CEO Rob Hamilton observed the attacker consolidating 1,324 UTXOs across 500 transactions, suggesting a possible vulnerability in randomness entropy during wallet generation. Wizardsardine CEO Kevin Loaec indicated the weakness might stem from a low-entropy random number generator in specific firmware or hardware batches. While researchers suspect attackers are using AI-driven scripts for brute-force attempts, no definitive link between the BTC movement and the Coldcard Mk3 advisory has been established.