Coldcard Issues Security Advisory Over Possible Seed Phrase Exposure on Mk3 Devices
BlockBeats reported that on July 31, Canadian hardware wallet maker Coinkite released a security advisory urging users who created mnemonic seed phrases on Coldcard Mk3 units running firmware 4.0.1 through 5.0.3 to move their funds as soon as possible.
Coinkite said an initial review suggests wallets protected with BIP39 passphrases face lower risk. The company added that Coldcard Mk4, Q, and Mk5 devices are not affected, and that its investigation remains ongoing.
Separately, security researchers are examining an unusual movement of 594.48 BTC (about $38.3 million). AnchorWatch CEO Rob Hamilton said the attacker shifted 1,324 UTXOs through 500 transactions over three blocks, suggesting the incident could be tied to insufficient randomness entropy during wallet creation.
Wizardsardine CEO Kevin Loaec said the weakness could involve a software library, a security chip, a specific device batch, or a firmware build with a low-entropy random number generator. He added that attackers may be using AI-generated scripts to brute-force wallets that are vulnerable.
There is currently no definitive evidence linking the BTC transfer directly to any Coldcard Mk3 seed phrase issue.