Coldcard Mk3 Vulnerability May Have Led to $70M BTC Theft

iconBitcoinsistemi
Share
AI summary iconSummary
Coldcard Mk3 devices with firmware 4.0.1 to 5.0.3 may have exposed BTC as hedge against inflation due to a critical flaw. Coinkite confirmed the vulnerability could leak seed expressions. Galaxy Research tracked 1,196 wallets drained in 41 minutes on July 30, totaling 1,082.65 BTC or $70.2 million. The theft occurred 30 hours before the flaw was disclosed. Experts urge users to create new seeds in secure wallets. No movement has been seen from the stolen BTC addresses. Authorities are likely to apply CFT (Countering the Financing of Terrorism) measures to trace the funds.

Bitcoin hardware wallet manufacturer Coinkite has announced the discovery of a critical security vulnerability that could affect the security of seed expressions generated on some Coldcard Mk3 devices. The company advises users who may be at risk to immediately transfer their funds to a new and secure wallet.

According to Coinkite, the issue stems from the seed generation process on Coldcard Mk3 devices running firmware versions 4.0.1 to 5.0.3. Users who have previously generated seeds on these devices should consider all Bitcoin addresses associated with that same seed potentially at risk.

Related News: There's a 43-Day Staking Queue on Ethereum: But According to an Expert, That's Not the Real Bullish Signal

The warning comes amid ongoing investigations into an attack in which a large amount of BTC was stolen from hundreds of single-signature Bitcoin wallets. While initial reports indicated approximately 594 BTC were stolen, Galaxy Research’s broader analysis suggests that 1,196 wallets were completely emptied, with a total of 1,082.65 BTC compromised. This amount was estimated to be worth approximately $70.2 million at the time of the transaction.

According to Galaxy Research, the wallets were emptied in just 41 minutes on July 30th. The fact that the same 30 sat/vB fee was used in all transactions and that no change was printed out for any transaction suggested that the transfers may have been carried out not manually by users, but by an automated tool scanning compromised private keys.

The stolen Bitcoins were reportedly consolidated into four different addresses, and so far, no activity has been observed from these addresses. It is noteworthy that the attack occurred approximately 30 hours before Coinkite publicly disclosed the Coldcard Mk3 vulnerability.

Security experts recommend that users of Coldcard Mk3 who have created a seed on the device no longer consider the old seed expression secure. Users are advised to create a new seed in a reliable and up-to-date hardware wallet, and then transfer all funds to this new address. Simply changing devices is not considered sufficient; the old seed expression should not be transferred to the new wallet.

*This is not investment advice.

Continue Reading: Attention Bitcoin Users: Today’s Hack May Be Larger Than Expected—Here’s What to Do

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.