EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Coinkite warns Coldcard Mk3 users that all seeds from March 2021 may be predictable

2026-08-01 00:15:25
Bookmark

Coinkite warns Coldcard Mk3 users to transfer funds: 594.5 bitcoins were stolen and seed generation was flawed.

Coinkite issued a security warning reminding Coldcard Mk3 users to transfer funds immediately. Previously, 594.5 bitcoins (BTC) out of 500 addresses were transferred out in batches, and the investigation found that there were security flaws in the seed generation of these addresses.

Key Information

Since version 4.0.1, all Mk3 firmware versions may generate seeds that pose security risks. Users of Mk4, Mk5 and Q series who use older versions of firmware need to immediately update their devices, generate new seeds and transfer funds. Among the reported victims, no use of multi-signature or Taproot wallets was found.

Detailed explanation of Coldcard seed risks

Coinkite pointed out in the security bulletin that since version 4.0.1 released in March 2021, all Mk3 firmware versions have entropy problems, which affects the wallet seeds generated by the device. Seeds generated using Mk4 and Mk5 devices before 5.6.0, and Q-series devices before 1.5.0Q are also at serious risks.

The company said that the affected seeds actually contained only about 72 bits of entropy instead of the expected 128 bits, although the extent of impact varied among models. TAPSIGNER, OPENDIME, and SATSCARD are not affected by this issue because they use separate code libraries. Firmware updates cannot repair existing seeds.

Users should first install the repaired firmware, then generate a new seed, then backup it, verify the collection address on the device, and finally send a micro-test transaction. Mk3 users without other devices can temporarily use the strong and unique BIP-39 mnemonic, but Coinkite still recommends that users migrate to newly generated seeds.

Impact of Bitcoin theft incident

Atlas21 reported that on July 30, an automated operation cleared 500 single-signature addresses in blocks 960188 to 960191. These transactions consumed 1324 UTXOs, transferred 594.5 BTC, valued at approximately US$38 million, and a transaction fee of approximately 0.044 BTC. No multiple signatures or Taproot addresses were found.

The median victim loss was 0.41 BTC, of which 110 addresses were lost more than 1 BTC, and the largest single loss was 29.9 BTC. Atlas21 said transaction patterns indicate flaws in the way these wallets were created when they were created. The first public report came from a user whose 24-word seed was generated on Coldcard in 2021 and was never entered into a computer.

The importance of this incident is that offline storage cannot ensure the safety of funds when the underlying seeds lack enough randomness. Coinkite's warning covers wallets created over the past five years, and if users do not migrate, funds will always be at risk. After the incident, the Bitcoin market price remained around $64000.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP