Crypto Prices

Coinkite Alerts Coldcard Mk3 Users Amidst $38 Million Bitcoin Theft Investigation

24 minutes ago
2 mins read
1 views

Urgent Alert from Coinkite

On July 30, Coinkite issued an urgent alert to users of its Coldcard Mk3 hardware wallets, advising them to transfer their Bitcoin from any wallets that had seed phrases generated using potentially compromised firmware versions. Specifically, users should be cautious if their seeds were created using firmware 4.0.1 or any subsequent Mk3 release up to version 5.0.3, as these may jeopardize the safety of their funds.

This advisory comes amid ongoing investigations into a significant theft involving 594.48 BTC—valued at approximately $38.2 million based on Bitcoin’s price of around $64,324. Although the timing of the alerts and the theft coincides, neither Coinkite nor independent analysts have confirmed a direct link between the firmware issue and the recent fraudulent transactions.

Investigation and Impact

Coinkite emphasized that its investigation is ongoing and clarified that other models, including Coldcard Mk4, Q, and Mk5, do not appear to be impacted by this firmware vulnerability, based on initial assessments. Notably, the company mentioned that users with an affected seed phrase employing a BIP-39 passphrase face only ‘minimal risk.’ It is critical to distinguish that a BIP-39 passphrase is not the same as the device’s PIN.

Guidance for Users

To assist users in safely transitioning their assets, Coinkite has provided comprehensive guidance on how to migrate funds effectively. They advise:

  • Creating a new seed with an unaffected device.
  • Ensuring the security of the backup and receiving address.
  • Executing a small test transaction.
  • Only transferring the full balance once users are confident in the setup.

Expert Insights

Rob Hamilton, CEO of AnchorWatch, noted that 1,324 unspent transaction outputs had been relocated within a three-block timeframe across 500 transactions, which entailed the movement of the aforementioned BTC from single-signature addresses. Following this, a significant portion—specifically 562 BTC—was pooled into a different address.

Hamilton suggested that there may have been issues with randomness during wallet creation, although this is merely an initial observation rather than a definitive conclusion.

Further speculation came from Kevin Loaec, CEO of Wizardsardine, who hypothesized that the wallet generator may have exhibited low entropy, with possible sources of this flaw including a specific software library, batch of devices, or the firmware itself.

He suggested that an attacker might have exploited a limited range of BIP-84 paths, which might explain the narrow focus on native SegWit addresses and the partial withdrawals observed. However, this theory lacks empirical support at present.

Historical Context

The current situation echoes previous vulnerabilities in cryptocurrency software linked to inadequate randomness in key generation. One such reported vulnerability, known as Ill Bloom, affected recovery phrases across various blockchains. Similarly, the Randstorm vulnerability impacted BitcoinJS wallets created between 2011 and 2016 due to insufficient key randomness, although this case is distinct from the Coldcard Mk3 issue.

Recommendations for Affected Users

For users with unaffected Coldcard devices, Coinkite recommends generating a new seed and completing the migration with caution. It is advisable to keep the original backup until all transfers are verified. Users must check every displayed address on the hardware and refrain from inputting seed phrases or passphrases on potentially compromised platforms.

For those with no choice but to utilize an Mk3 device, Coinkite suggests incorporating a robust and unique BIP-39 passphrase as a temporary safeguard. Advanced users may consider creating a dice-based seed on an empty Mk3 that runs firmware 4.1.9, although this method involves entering at least 99 independent rolls of a fair die, necessitating meticulous backup and validation processes.

Conclusion

The final outcome of this situation hinges on ongoing technical evaluations by Coinkite and further analysis of blockchain activities. Until a formal root cause is established, the events surrounding the 594 BTC transfer and the firmware-related warnings should be regarded as coincidental but not conclusively linked.

Popular