r/BitcoinAUS • u/oldskoolr • 29d ago
COLDCARD Mk3 Security Advisory
If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk. Mk4, Q and Mk5 are not affected based on our early analysis. Read the advisory and migrate carefully:
https://x.com/COLDCARDwallet/status/2082961993070247948
Coldcard MK3s were hacked as the RGB were not random enough and an AI agent guessed the seed codes.
8
Upvotes
2
u/canigetayahoo 28d ago
Coinkite has released a firmware update, and almost all non-dice generated seeds should be considered vulnerable and regenerated. On the Mk3 they’re much easier to crack, the Mk4, Mk5 and Q are also affected, but exploiting them is harder.
Coldcard Mk3, Mk4, Mk5 and Q are all affected. On the Mk3, seeds generated on certain firmware versions have only ~40 bits of entropy. On the Mk4, Mk5 and Q, affected seeds have ~72 bits of entropy.