Coldcard Mk3 Vulnerability Compromises Bitcoin Seed Expressions
A critical security vulnerability has been discovered in certain Coldcard Mk3 devices, potentially affecting users' Bitcoin seed expressions. Coinkite, the manufacturer of the hardware wallet, advises affected users to transfer their funds to a new and secure wallet immediately.
The issue stems from the seed generation process on Coldcard Mk3 devices running firmware versions 4.0.1 to 5.0.3. According to Coinkite, users who have previously generated seeds on these devices should consider all Bitcoin addresses associated with that same seed potentially at risk.
This warning comes amid an ongoing investigation into a recent attack in which a large amount of BTC was stolen from hundreds of single-signature Bitcoin wallets. Galaxy Research's analysis suggests that 1,196 wallets were completely emptied, with a total of 1,082.65 $BTC compromised, worth approximately $70.2 million at the time of the transaction.