Coldcard Users Warned of Potentially Exposed Wallets
A security advisory has been issued by Coinkite, warning users who generated seeds on Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3 to treat their wallets as potentially exposed and migrate their Bitcoin.
The issue was identified by Block's Bitcoin engineering and security teams while investigating remotely drained wallets, which found two weaknesses in seed-generation behavior affecting Coldcard generations at different severity levels.
Coinkite's analysis suggests that devices running firmware 4.0.1 through 5.0.3 are affected, but devices such as Mk4, Q, and Mk5 are not. Block researchers also stated that no Bitkey or other Block products are affected.
The weakness in the older firmware versions allows attackers to reproduce predictable seed generation on a freshly initialized device using only the number of keypad presses made during setup, according to Bitcoin Core developer Gregory Sanders.
Block engineers have traced potential drain scope to 1,083 BTC, with two identified sweeps moving a total of $69.6 million in Bitcoin.
Coinkite advises users to generate a fresh seed on an unaffected device and follow specific steps to mitigate the risk, including recording and verifying the backup, checking a receive address, sending a small test transaction, and only then moving the remaining balance.