Coldcard Warns Mk3 Users on Firmware 4.0.1 of Bitcoin Seed Compromise After Theft Reports
Coinkite warns users of the Coldcard Mk3 hardware wallet that private keys generated on devices running firmware version 4.0.1 or later may be compromised. The security advisory follows unverified reports of partial bitcoin wallet thefts tied to on-chain movements. Users who created seeds on the firmware released in March 2021 are advised to check their balances and migrate their funds.
Early analysis indicates the vulnerability does not affect the Mk4, Mk5 or Q models. The root cause remains unconfirmed, though industry researchers suspect a low-entropy random number generator flaw in the secure element that could allow targeted fund sweeps. Coinkite stated a full technical report will be released shortly.
From the sources (8 posts)
@robustusRT @jamesob: This is confirmed, and may also affect mk2/mk4. I'm updating my advice: if you have coins living under a single key generated…
@loppRT @COLDCARDwallet: COLDCARD Mk3 Security Advisory If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk. Mk4…
@aaronwiseThe Coldcard blog post is out. “Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk.”
@coldcardwalletCOLDCARD Mk3 Security Advisory If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk. Mk4, Q and Mk5 are not affected based on our early analysis. Read the advisory and migrate carefully:
@loppColdcard users should take notice: your private keys may be compromised if you generated them under these conditions. We should be getting a full report of the vulnerability soon.
@tftc21Reports are coming in that some Coldcard hardware wallet users are having their bitcoin drained. Multiple known Bitcoiners are confirmed affected. @KLoaec’s working hypothesis is a low-entropy RNG issue, possibly in the secure element, wit
@lopp@KevKevPal I was contacted overnight by someone who said they had a partial loss from a fully airgapped device and the seed was generated on-device without user-supplied entropy. 🤷
@loppHearing unverified reports of partial bitcoin wallet thefts that correspond to odd on-chain fund movements. Root cause is unclear at this time. Please check your wallet balance and report back if you notice any loss of funds - more informat