Coldcard Seed Phrase Issue Sparks Investigation into $38M Bitcoin Wallet Drain
Coinkite has issued a warning to users of its Coldcard Mk3 signing device regarding potential risks to funds stored in affected wallets. The issue arises from seed phrases generated on firmware versions 4.0.1 and later, up to the final version 5.0.3. This does not affect newer devices such as the Mk4, Q, or Mk5.
The warning comes amidst an investigation into a coordinated sweep of 594.48 BTC from single-signature addresses. Although no definitive evidence links the Mk3 issue to these transfers, Coinkite advises users with affected seeds to generate a new seed on an unaffected device and verify its backup before transferring funds.
Bitcoin security specialists are examining the unexplained sweep, which saw 1,324 unspent transaction outputs drained across 500 transactions within a three-block window. According to AnchorWatch CEO Rob Hamilton, this was worth approximately $38.3 million at the time of writing, based on a Bitcoin price of $64,364.07.
Hamilton's preliminary analysis suggests that flawed entropy in wallet generation may have contributed to the sweep. Wizardsardine CEO Kevin Loaec hypothesizes that an attacker might have used AI-generated scripts to brute-force affected wallets, potentially targeting limited BIP-84 derivation paths.