Crypto
Home›Crypto›Market Structure›Coinkite issues fixed firmware after Coldcard Bitcoin…
Coinkite issues fixed firmware after Coldcard Bitcoin key bug
The affected Coldcard MK3 firmware range is 4.0.1 through 4.1.9, and Coinkite says upgrading does not make previously generated keys secure, requiring users to create a new wallet and move funds on-chain.
Coinkite has released fixed firmware following a reported critical bug in how Coldcard Bitcoin hardware wallets generate secure private keys, in a hack that was believed to have resulted in more than 1,000 bitcoins stolen, according to Bitcoin Magazine. Bitcoin Magazine reports that industry experts believe the breach involved AI-assisted code review. The most affected devices are Coldcard MK3 units running firmware version 4.0.1 through 4.1.9, where certain seed setups are described as vulnerable. Coinkite’s guidance, as summarized by Bitcoin Magazine, indicates that 12- or 24-word seeds generated without user-generated dice rolls and without a BIP 39 extra passphrase are at higher risk, and affected users should move coins as soon as possible from the wallets. The advisory update noted by Bitcoin Magazine says users must upgrade all three chip generations, with MK4 and MK5 updating to version 5.6.0 or later, Q users updating to version 1.5.0Q or later, and MK3 users updating to version 4.2.0 or later. Coinkite also warns that firmware upgrades do not retroactively secure keys created under the vulnerable firmware, and that a new wallet must be created and funds sent on-chain to new addresses.
Latest closeBitcoin $62,955.18 ▼2.7%