Coldcard Mk3 Vulnerability Used to Steal 594 BTC ($38M) From 500 Wallets
AI مارکیٹ کا خلاصہ
An exploit tied to a Coldcard Mk3 seed-generation entropy flaw reportedly enabled theft of ~594 BTC (~$38M) from ~500 wallets in minutes, undermining confidence in Bitcoin self-custody and hardware-wallet operational security. While passphrases and multisig mitigations appear effective, the urgency to migrate funds elevates risks of user error and phishing, likely increasing near-term caution around self-custody practices and custody-provider scrutiny.
اثر کی سطح
● ہائی
متاثرہ اثاثے
BTC/USDT-3.13%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
On July 30, Bitcoin self-custody suffered a sharp real-world shock: an attacker siphoned roughly 594 BTC—valued at more than $38 million—from about 500 Coldcard wallets in an estimated 15–25 minutes.
On-chain investigators say the theft hinged on a weakness in Coldcard Mk3 seed generation that made certain recovery phrases more predictable due to insufficient entropy. Hardware wallets are designed to produce seeds using high-quality randomness, creating a vast search space. In this case, the flaw reportedly reduced that search space dramatically—shifting from roughly 340 undecillion possible combinations to only a few billion. The seed phrases appeared normal and used the standard word list, but the reduced randomness made brute-force attempts far more feasible.
Coldcard maker Coinkite has drawn criticism following the incident, even though it had previously warned Mk3 users that their funds were not safe. Coinkite said users who protected their seeds with a BIP39 passphrase faced minimal risk.
The company also noted that seeds generated on Mk4, Q, and Mk5 devices prior to the fixed firmware release may be affected as well. Its advisory stated: If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk. Coinkite added that other hardware signers in its lineup—TAPSIGNER, OPENDIME, and SATSCARD—were not impacted.
Coinkite urged Mk3 users to move funds, recommending migration to a newly generated seed on an unaffected device. It also suggested using a strong BIP39 passphrase or a dice-only seed. Still, shifting funds under time pressure can introduce fresh risks, including user mistakes, phishing attempts, and rushed operational errors.
The incident has rattled parts of the Bitcoin community, but the broader ecosystem remains intact. Reports indicate the attack primarily affected single-signature hardware wallet setups, reinforcing the case for additional safeguards such as passphrases, multisig, and user-generated entropy via dice rolls.
Final summary: An attacker exploited a Coldcard Mk3 flaw to drain about 594 BTC worth roughly $38 million in under half an hour. While the episode exposed weaknesses in certain self-custody practices, wallets using extra security layers such as multisig were not similarly compromised.