Coldcard issues Mk3 warning as $38M Bitcoin wallet drain draws expert scrutiny
Hardware wallet security is under examination across the Bitcoin custody sector. Coinkite, the maker of the Coldcard signing device, has urged all Mk3 model users to migrate their funds after identifying a potential risk in seed…
Key takeaways
- Coinkite, maker of the Coldcard signing device, has urged all Coldcard Mk3 users to migrate their funds after identifying a potential flaw in how the device generates seed phrases.
- Because seed generation happens once at setup, a flaw would expose every address derived from it regardless of how carefully the device was handled afterward.
- Bitcoin security experts are separately investigating an unexplained $38 million wallet drain that currently has no publicly attributed cause or named attack vector.
- There is no confirmed link between the $38 million drain and Coinkite's Mk3 disclosure.
- Coinkite's recommended migration requires generating a fresh wallet on a different device or model and moving BTC on-chain, which costs transaction fees and takes time.
Hardware wallet security is under examination across the Bitcoin custody sector. Coinkite, the maker of the Coldcard signing device, has urged all Mk3 model users to migrate their funds after identifying a potential risk in seed generation. Bitcoin security experts are separately investigating an unexplained $38 million wallet drain that has no publicly attributed cause.
What Coinkite identified on the Mk3
The affected product is the Coldcard Mk3. Coinkite's concern is a potential flaw in how the device generates seed phrases. A seed phrase is the master credential for a Bitcoin wallet: whoever can reproduce it controls the funds, completely and irreversibly. Coinkite's instruction to Mk3 holders is to move the funds to a different wallet.
Seed generation happens once, at setup. If that process carries a flaw, every address derived from it carries the same exposure, regardless of how securely the device has been handled since.
The $38 million drain, a separate thread
Security experts are examining a distinct event: an unexplained $38 million Bitcoin wallet drain. The source provides no confirmed link between that incident and Coinkite's disclosure. No attack vector has been publicly named.
These two developments arriving in the same news cycle will invite comparisons. Whether the drain is connected to any hardware wallet vulnerability is a question the current record does not answer.
The read-through for self-custody
Against the backdrop of continuing questions about centralized custody risk, hardware wallets carry a specific promise: the user controls the seed, so the user controls the funds. A disclosed seed-generation flaw from a named product cuts at that premise.
For Mk3 users, the migration Coinkite recommends means generating a fresh wallet on a different device or model, then broadcasting transactions to move $BTC on-chain. That process costs transaction fees and takes time. It also requires users to trust that the destination wallet does not carry the same kind of flaw.
The question of whether similar risks exist sector-wide, across hardware wallet models, is now in the air. Coinkite's advisory names the Mk3 specifically. The $38 million drain remains under expert examination with no confirmed cause.
Related reading
Source · 來源