Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

coindesktech.yahoo+1tech.yahooA flaw in the key generation process of Coldcard Mk3 hardware wallets allowed an attacker to drain roughly 594 bitcoin — worth about $38 million — from around 500 wallets in under 30 minutes early Friday, in one of the largest hardware wallet exploits on record.
The funds were swept between 01:31 and 01:56 UTC on Friday, July 31, moving 1,324 chunks of bitcoin across 500 transactions inside a three-block window, according to CoinDesk. About 562 BTC was subsequently consolidated into a single address that has not moved. Every drained wallet used single-signature security and held more than 0.15 BTC, with many having been dormant for years.coindesk
Canadian hardware wallet maker Coinkite issued a security advisory on Thursday, July 30, warning that seeds generated on Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3 may be compromised. The company said Mk4, Mk5, and Coldcard Q devices are not affected based on its early analysis.kucoin+3
The vulnerability stems from a firmware bug that caused Coldcard devices to silently use a software-based pseudo-random number generator inherited from MicroPython, rather than the intended hardware random number generator, during seed creation. A preprocessor guard checked only whether a setting was defined without testing its value, so the build compiled against the software fallback without complaint. The flaw has been present since a March 2021 firmware migration.tech.yahoo+1
Coinkite estimates the effective entropy for an Mk3 seed at roughly 40 bits — against the 128 bits a seed is supposed to have — making affected seeds solvable puzzles rather than unbreakable secrets. Coinkite said it believes the attacker may have used AI to review its firmware and uncover the bug, noting that the company had run an AI model over its own code weeks earlier and "did not find this bug or anything serious".kucoin+1
Coinkite has stressed that a firmware update alone does not fix a seed already generated with weak entropy. Affected users must generate an entirely new seed on patched hardware — firmware 5.6.0 for Mk4 and Mk5, or 1.5.0Q for the Q model — and migrate all funds. The company recommends adding a strong BIP-39 passphrase, at least 99 dice rolls during seed generation, or both. Seeds created with a BIP-39 passphrase face minimal risk from the flaw.tradingview+2
Block , which published an independent analysis Friday, confirmed none of its products are affected. Its hardware lead Max Guise urged anyone with an exposed Coldcard seed to move funds "as soon as they safely can". Coinkite warned users against rushing: "Hastening a wallet migration could pose a more immediate risk than the issue you are attempting to resolve".tech.yahoo+1