Coldcard Mk3 Hack Exposes Weakness in Single-Sig Hardware Wallets
On July 30th, Bitcoin's self-custody was put to the test when an attacker exploited a Coldcard Mk3 flaw, draining 594 BTC worth $38 million from 500 wallets in under 25 minutes. Despite users following best practices by buying reputable air-gapped devices and never entering their seed on a networked computer, they still lost funds.
The attack took advantage of a seed generation flaw that reduced the number of possible combinations to an astronomically smaller number, making it easier for hackers to guess the correct phrase. Normally, hardware wallets generate seeds using true randomness, but in this case, the system selected words from the same word list, significantly reducing the search space.
Coldcard issued a security advisory warning users that their funds were not safe and advised those who generated seeds on Mk3 after firmware 4.0.1 to move their funds immediately. However, users who protected with a BIP-39 passphrase faced minimal risk.