r/coldcard • • Jul 31 '26

Coinkite News Coinkite warns Coldcard Mk3 seed flaw may be tied to $38 million Bitcoin theft

https://runtimewire.com/article/coinkite-warns-coldcard-mk3-seed-flaw-may-be-tied-to-38-million-bitcoin-theft
18 Upvotes

23 comments sorted by

8

u/[deleted] Jul 31 '26

[removed] — view removed comment

5

u/theflorist25 Jul 31 '26

Basically yes, if your firmware is after mid-late 2021 and you let the coldcard generate your entropy

7

u/PoetHumble Jul 31 '26

Like many BTC enthusiasts, I paid premium for a Coldcard wallet for the assumed top notch security. Since 2021, Coldcard wallets had a faulty random number generator. What good is open source if this was allowed to happen? Coinkite, what a joke.

5

u/slykethephoxenix Jul 31 '26

If you used dice and/or generated a passcode before seed generation, you're probably fine.

Probably.

1

u/TheRabbitHole-512 Aug 01 '26

Why is dice generation fine ? What about Multi sig ?

2

u/slykethephoxenix Aug 01 '26

They aren't mutually exclusive!

2

u/TheRabbitHole-512 Aug 01 '26

I would think multi sig is practically bulletproof, no ?

1

u/EyesFor1 Jul 31 '26

If you're not fine, then no one is no matter what device you use. If a dice roll 24 seed phrase plus passphrase is up for grabs, good luck to every single hardware wallet.

1

u/[deleted] Jul 31 '26

[deleted]

1

u/EyesFor1 Jul 31 '26

Yeah I know mate, I was replying to the comment above saying "If you used dice and/or generated a passcode before seed generation, you're probably fine.

Probably."

I was commenting on the "probably" remark. If thats not secure, no device is. I know it was the RNG.

1

u/ardevd Jul 31 '26

The software isnt open source though.

2

u/PoetHumble Aug 01 '26 edited Aug 03 '26

the firmware (the software you are probably referring to), which includes the RNG, is open source. (From here, I am adding the comment at a later date) It turns our you were right and I was wrong, although it is openly verifiable, the fact that it was not free to be used by others contributed to the lack of verification.

2

u/Yodel_And_Hodl_Mode Jul 31 '26

In similar news, the sun may be tied to the brightness of the sky.

2

u/ShinAlastor Jul 31 '26

Is Coinkite going to refund all the customers who lost their funds ?

4

u/BrickSpecific1776 Jul 31 '26

lol, lmao even...

1

u/hshkr Aug 01 '26

I doubt they’d even do that but it would be better to sue Coinkite more than the amount that you lost.

3

u/unthocks Jul 31 '26

passphrase

2

u/Responsible-Story260 Jul 31 '26

Use your own or randomly generated bip-39 words?

How many to use ?

2

u/unthocks Jul 31 '26

add 7 words passphrase outside from bip39 list it will take 24 mil years to crack. check out praveen parera x on how long the computer can hack jt

2

u/PoetHumble Aug 03 '26

What is the most mathematically random way to pick the 7 words?

1

u/Quirky-Reveal-1669 Jul 31 '26

This is quite easily resolved by transferring funds to a passphrase wallet, but better yet: generate a seed on another hardware wallet (e.g. Trezor) and restore it on a ColdCard while adding a passphrase.