Coldcard Mk3 hardware wallets with firmware 4.0.1–5.0.3 have a seed generation flaw; Coinkite warns users to migrate funds immediately amid investigation into 594 BTC theft from single-signature wallets.
Security & Exploits ·
Coinkite has alerted users of Coldcard Mk3 hardware wallets to a potential vulnerability in seed generation affecting firmware versions 4.0.1 through 5.0.3, recommending immediate fund migration. The warning emerged alongside an ongoing investigation into the theft of 594 BTC from numerous single-signature wallets, though authorities have not yet established whether the two events are connected.
The nature of the seed generation flaw and its precise exploitation mechanics remain under examination. Researchers are working to determine whether the firmware vulnerability played a role in the broader theft or represents a separate issue requiring remediation.
What remains unclear is the full scope of affected wallets, the timeline of the vulnerability's discovery, and whether any connection between the Coldcard flaw and the 594 BTC loss will be confirmed as the investigation progresses. Users of the affected firmware versions face uncertainty about past exposure until further technical details emerge.