Coinkite Urges Coldcard Mk3 Users to Migrate Funds After 594 BTC Sweep

iconChainGPT
Share
AI summary iconSummary
Coinkite has issued an urgent BTC update for Coldcard Mk3 users who created seed phrases on firmware versions 4.0.1 through 5.0.3. A reported sweep of 594.48 BTC has raised concerns. The firm urges users to migrate funds to unaffected devices like Coldcard Mk4, Q, or Mk5, with migration steps provided. Security researchers noted a fast consolidation of BTC across 500 transactions in three blocks. No confirmed technical report has linked the sweep to the firmware flaw. Coinkite and researchers are looking at potential causes, including weak entropy during seed generation. No root cause has been confirmed. Users are told to keep old backups and double-check receiving addresses. This BTC news today highlights the risks of older firmware.

Coinkite has issued an urgent warning after security researchers observed a coordinated sweep of roughly 594.48 BTC — about $38.2 million at the time — and told Coldcard Mk3 users to migrate funds if their seed phrase was generated on affected firmware. What Coinkite said - On July 30 Coinkite advised anyone who created seeds on Coldcard Mk3 firmware 4.0.1 or any later Mk3 release up through 5.0.3 to move their Bitcoin off those wallets as soon as possible. - The company’s initial analysis indicates Coldcard Mk4, Q and Mk5 are not affected. - Coinkite described BIP-39 passphrases as presenting “minimal risk,” but stressed a passphrase is not the same as the device PIN. - It published recommended migration steps (generate a new seed on an unaffected device, verify backups and receiving addresses, send a small test transaction, then transfer the remaining balance) and warned users to preserve old backups until transfers are confirmed. Coinkite also promised a formal technical review, which had not been published at the time of writing. The on-chain sweep Security researchers watching the blockchain flagged a rapid consolidation that moved 594.48 BTC in a three-block window. AnchorWatch CEO Rob Hamilton reported 1,324 UTXOs moved across about 500 transactions; after the sweep 562 BTC were moved into a single consolidating address. The timing of those transfers prompted Coinkite’s advisory, but neither Coinkite nor independent researchers have confirmed the firmware issue caused the sweep. Early hypotheses — but no proof yet Researchers and industry figures have floated explanations consistent with weak or flawed entropy during seed generation: - Rob Hamilton called the activity “at a glance” consistent with flawed entropy when wallets were created. - Kevin Loaec, CEO of Wizardsardine, suggested a low-randomness wallet generator as a current hypothesis and proposed possible sources including a software library, the secure element, a device batch or particular firmware. He also suggested an attacker could have searched a narrow set of BIP-84 paths, possibly explaining the concentration on native SegWit addresses and partial sweeps. Importantly, these are preliminary theories. No public technical report has identified a faulty component, quantified available entropy, or demonstrated how private keys could be derived. The 594 BTC sweep and Coinkite’s seed-generation warning should be treated as linked in timing but not proven to share the same cause until a confirmed root cause is published. Context and precedent This incident resembles earlier weak-randomness failures in the space. Related cases include the Ill Bloom issue (weak recovery-phrase generation across multiple blockchains) and the older Randstorm vulnerability, which affected BitcoinJS wallets created between 2011 and 2016 that didn’t generate sufficiently random private keys. Those cases are separate but underscore how catastrophic low-entropy failures can be. Practical guidance for users - If you have an unaffected Coldcard (Mk4, Q, Mk5 per Coinkite’s early analysis), generate a fresh seed there and migrate carefully. - Preserve your old backup until your transfers are fully confirmed. - Verify every receiving address on the hardware screen. Don’t enter seed words or passphrases into websites or untrusted devices. - If your Mk3 is your only option, Coinkite recommends using a strong, unique BIP-39 passphrase as a temporary mitigation. Advanced users can create a dice-only seed on an empty Mk3 running firmware 4.1.9 by entering at least 99 independent six-sided die rolls, but Coinkite warns this method requires rigorous backup and verification. What’s next Investigators continue on-chain analysis and Coinkite’s technical review is pending. Until a public, forensic report identifies a root cause, users should take Coinkite’s migration advice seriously while understanding that the causal link between the Mk3 seed issue and the 594.48 BTC sweep has not been proven. We’ll update this story as Coinkite and independent researchers publish technical findings.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.