All about Coldcard’s $38M Mk3 exploit and what’s next for Bitcoin self-custody

Coinmama
BTCC


On the 30th of July, Bitcoin’s [BTC] self-custody faced a stress test. An attacker drained about 594 BTC worth over $38 million from 500 Coldcard wallets within about 15–25 minutes.

This action is a real-world examination of Bitcoin’s core ethos, as these users did everything right. They bought a reputable air-gapped device, never entered the seed on a networked computer, and left funds untouched for years, but still lost money.

Are other hardware wallets at risk?

Hacker drains 594 BTC from 500 Coldcard wallets

As per on-chain investigations, an attacker exploited a Coldcard Mk3 seed generation flaw to steal BTC in less than half an hour. The bug made some Mk3 recovery phrases predictable due to weak entropy.

okex

Normally, a hardware wallet generates the seed phrase using true randomness. However, the flaw reduced the number of guesses a hacker needed to make by altering how the system selected the words

Instead of choosing from 340 undecillion combinations, the wallet was picking from a few billion. Despite that being a huge number, it is astronomically smaller than what Bitcoin’s security is designed to provide.

BitcoinBTCBitcoinBTC
Source: Arkham

Even so, the seed phrase looked normal, but the words came from the same word list. Hence, the search space became extremely smaller for the hacker.

Coldcard security advisory

Coldcard has faced backlash due to this incident despite warning Mk3 users that their funds were not safe. However, those who protected with a BIP-39 passphrase faced minimal risk.

Additionally, seedphrases generated on Mk4, Q, and Mk5 before the fixed firmware release were affected too. Coldcard advisory report said,

If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk.

Other Coinkite hardware signers, such as TAPSIGNER, OPENDIME, and SATSCARD, remained unaffected. The company advised Mk3 users to move their funds.

They recommend migrating funds to a newly generated seed on an unaffected device. Moreover, they could use a strong BIP-39 passphrase or dice-only seed.

Despite the company’s detailed technical analysis, the very act of moving funds under time pressure creates new opportunities for user error, phishing, or rushed mistakes.

Self-custody’s stress test

The attack has spread panic across the Bitcoin community, but the core ecosystem remains intact.

This is because only single-sig hardware wallets were affected, prompting the addition of extra layers of security to better them. Thus, passphrases, multisig, and dice rolls were non-negotiable.


Final Summary

  • An attacker exploited a Coldcard Mk3 flaw, draining 594 BTC worth $38 million in less than half an hour.
  • Bitcoin’s self-custody faced a stress test, but the security remains intact for wallets with extra layers like multisig. 

 



Source link

BTCC

Be the first to comment

Leave a Reply

Your email address will not be published.


*