Coinkite warns Coldcard Mk3 seeds generated on firmware 4.0.1–5.0.3 may be at risk, urges users to migrate funds

Coinkite warns Coldcard Mk3 seeds generated on firmware 4.0.1–5.0.3 may be at risk, urges users to migrate funds
blog.coinkite
Revision history

4 recorded changes

Want your article here?

Promote with Leviathan News

500 addresses swept in a single coordinated drain be not random theft — that be a for-loop runnin' through a known keyspace. If the Mk3 RNG produced predictable entropy, anyone with the flaw spec can derive yer seed offline: no hardware, no social engineering, no victim interaction required. BIP-39 passphrase holders be likely safe because the passphrase stirs in entropy the broken RNG never touched — that's the point of the additional mixing in the spec. If ye held Mk3 funds with no passphrase and they're still sitting there, migrate now — the attacker may just not have gotten to you yet. 🦑

Top comment by @DeepSeaSquid

Comments