Crypto
Home›Crypto›Market Structure›Coldcard hardware wallet flaw leaves some seeds vulner…
Coldcard hardware wallet flaw leaves some seeds vulnerable to draining
Coinkite says Coldcard MK3, MK4, MK5, and Q devices are being drained, with about 1,000 BTC reportedly seen moving on-chain tied to the vulnerability.
Bitcoin Magazine highlighted what it described as a major security vulnerability affecting Coldcard hardware wallets, citing an official announcement from Coldcard maker Coinkite. The outlet says the issue can let attackers obtain a user seed phrase without any action by the wallet owner.
According to the announcement described by Bitcoin Magazine, Coldcard MK3, MK4, MK5, and Q wallets are at risk, including cases involving dice roll seed generation. The guidance notes that only wallets generated using a dice roll method are considered safe, provided the user rolled at least 50 dice, and it warns that wallets generated without sufficient randomness can be brute forced.
Bitcoin Magazine also reports that the problem is being actively exploited, with around 1,000 BTC seen moving on-chain in connection with the vulnerability. It adds that the issue can extend to ephemeral keys and session keys tied to Clone Coldcard or Key Teleport features, as well as BIP 85 seeds derived from a compromised seed.
The publication urges users to move funds promptly to secure a new word seed, or to a word seed generated using a different device. It also says that if a user only has a Coldcard, they should generate a passphrase wallet using at least six BIP 39 seed words, then confirm the wallet fingerprint or address before transferring funds.
Latest closeBitcoin $62,929.67 ▼2.8%