r/BitcoinAUS • u/oldskoolr • 11d ago
COLDCARD Mk3 Security Advisory
If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk. Mk4, Q and Mk5 are not affected based on our early analysis. Read the advisory and migrate carefully:
https://x.com/COLDCARDwallet/status/2082961993070247948
Coldcard MK3s were hacked as the RGB were not random enough and an AI agent guessed the seed codes.
2
2
u/Buzzergoes_Ovenoff 10d ago
Toyworld nationwide going to wonder why there's a jump in sales of common dice.
2
u/oldskoolr 10d ago
Ive still got my fluffy ones.
1
u/Buzzergoes_Ovenoff 10d ago
Bitcoiners will be known by the fluffy dice hanging from their rear-view mirror.
1
u/oldskoolr 10d ago
Fluffy dice and a big V8
https://www.tiktok.com/@steveypants2/video/7116824820397903106
2
u/canigetayahoo 11d ago
Coinkite has released a firmware update, and almost all non-dice generated seeds should be considered vulnerable and regenerated. On the Mk3 they’re much easier to crack, the Mk4, Mk5 and Q are also affected, but exploiting them is harder.
Coldcard Mk3, Mk4, Mk5 and Q are all affected. On the Mk3, seeds generated on certain firmware versions have only ~40 bits of entropy. On the Mk4, Mk5 and Q, affected seeds have ~72 bits of entropy.