A critical vulnerability in Coldcard’s Mk3 hardware wallet has enabled the theft of approximately $38 million worth of Bitcoin, prompting manufacturer Coinkite to urge immediate fund migration for all affected users. The flaw, residing specifically in the device’s seed generation process, allowed sophisticated attackers to mathematically recreate private keys tied to wallets initialized with firmware version 4.0.1 or later releases of the Mk3 model. This randomness bug effectively transformed supposedly “impossible to guess” cryptographic seeds into predictable sequences, systematically exposing users to private key compromise without requiring physical access to the devices CoinDesk.
The financial impact materialized with devastating speed, as attackers drained 594 BTC—valued at roughly $38 million—through a coordinated operation that lasted merely 25 minutes. The sweeping extraction targeted specific addresses known to be vulnerable due to the compromised entropy generation, demonstrating that the perpetrators possessed precise advance knowledge of which wallets were susceptible to the predictable seed algorithm CoinDesk.
Independent security researchers validated the exploit’s mechanics. Bitcoin Core contributor instagibbs successfully reproduced the compromised seed generation pattern on a freshly initialized Mk3 device, providing concrete evidence that the randomness flaw was reproducible and systemic rather than an isolated incident. His demonstration confirmed that the vulnerability allowed private keys to be recreated remotely by anyone understanding the specific weakness in the firmware’s entropy collection CryptoSlate.
Coinkite has clarified that the vulnerability is strictly limited to the Mk3 hardware generation, emphasizing that Mk4 and Mk5 devices remain unaffected by this particular seed generation flaw CryptoSlate. The company has issued urgent guidance advising all users who generated seeds on Mk3 devices running firmware 4.0.1 or subsequent versions to immediately migrate their Bitcoin holdings to secure wallets created on unaffected hardware or alternative trusted platforms.
Regarding the discovery of the vulnerability, Coinkite suggested that the perpetrators likely employed artificial intelligence to conduct comprehensive audits of previous versions of the company’s open-source firmware. This AI-assisted review may have enabled the systematic identification of the randomness vulnerability that escaped traditional human security audits, representing a significant evolution in how attackers analyze cryptographic hardware implementations Decrypt.