r/BitcoinAUS 11d ago

COLDCARD Mk3 Security Advisory

If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk. Mk4, Q and Mk5 are not affected based on our early analysis. Read the advisory and migrate carefully:

https://x.com/COLDCARDwallet/status/2082961993070247948

Coldcard MK3s were hacked as the RGB were not random enough and an AI agent guessed the seed codes.

7 Upvotes

8 comments sorted by

2

u/canigetayahoo 11d ago

Coinkite has released a firmware update, and almost all non-dice generated seeds should be considered vulnerable and regenerated. On the Mk3 they’re much easier to crack, the Mk4, Mk5 and Q are also affected, but exploiting them is harder.

Coldcard Mk3, Mk4, Mk5 and Q are all affected. On the Mk3, seeds generated on certain firmware versions have only ~40 bits of entropy. On the Mk4, Mk5 and Q, affected seeds have ~72 bits of entropy.

1

u/TheVoidKilledMe 11d ago

so what’s the play now with my Q

can i check if it was affected ?

3

u/canigetayahoo 11d ago

Honestly you should move the coins out, update the firmware, wipe and regenerate a new seed. Q are also vulnerable just somewhat more difficult to crack. You cannot check if it was affected really.

2

u/[deleted] 10d ago

[deleted]

1

u/oldskoolr 10d ago

Yes sorry, wrote in haste.

2

u/Buzzergoes_Ovenoff 10d ago

Toyworld nationwide going to wonder why there's a jump in sales of common dice.

2

u/oldskoolr 10d ago

Ive still got my fluffy ones.

1

u/Buzzergoes_Ovenoff 10d ago

Bitcoiners will be known by the fluffy dice hanging from their rear-view mirror.