Coinkite Warns Users of Coldcard Mk3 Firmware Issue Following $38M BTC Sweep
Coldcard's Mk3 signing device users have been warned by Coinkite to move funds from wallets whose seed phrases were generated on affected firmware. This warning comes after a coordinated sweep involving 594.48 BTC, worth approximately $38.3 million, was detected.
The issue affects seeds created on an Mk3 running firmware version 4.0.1 or any later version up to and including 5.0.3. However, the Mk4, Q, and Mk5 models are not affected according to Coinkite's early analysis.
Experts, including AnchorWatch CEO Rob Hamilton and Wizardsardine CEO Kevin Loaec, are examining the sweep and have proposed theories on how it occurred. Hamilton's preliminary analysis suggests that 1,324 unspent transaction outputs were swept across 500 transactions within a three-block window, moving 594.48 BTC.
Loaec hypothesizes that a low-entropy random-number generator produced wallet seeds with insufficient randomness, potentially allowing an attacker to brute-force affected wallets using an AI-generated script. However, Loaec stresses that this theory remains unconfirmed and warns that if it is correct, wallets that were only partially drained may remain at risk of further theft.