Coldcard Mk3 Users Must Act Following Security Advisory

By Patricia Miller

2 min read

Coldcard Mk3 devices may have compromised seeds due to a firmware flaw. Users should take immediate action to secure their wallets.

#How Should You Respond to the Recent Coldcard Mk3 Security Advisory?

If you own a Coldcard Mk3, now is the time to take action. Coinkite has issued a security warning that seeds generated on Mk3 devices with firmware versions 4.0.1 through 5.0.3 may be compromised due to a potential issue with the device's random number generator. This warning is prominently displayed on Coinkite's firmware downloads page, indicating the seriousness of the matter.

#What Does This Flaw Mean for Your Wallet?

The flaw involves the generation of your wallet's seed, a critical component that acts as the master key to access your funds. Normally, this seed should be generated randomly to ensure security. However, if there is a flaw in the random number generator, the seeds may lack true randomness and could be replicable by someone familiar with the vulnerability.

The firmware versions in question span from 4.0.1, released in March 2021, to 5.0.3. Since any Mk3 device that generated a seed while on these firmware versions may be affected, it's crucial for users to evaluate their wallets promptly. Fortunately, models Mk4, Q, and Mk5 are confirmed to be unaffected by this issue.

#What Are Your Options?

In light of the advisory, Coinkite recommends two possible actions for users.

  • Option One: Implement a strong, unique BIP-39 passphrase for your existing seed. The BIP-39 standard allows the addition of a custom phrase or word, effectively creating a two-part authentication method that requires both the seed and the passphrase for access.
  • Option Two: Migrate to a safer device entirely. This involves generating a fresh seed on an unaffected model like Mk4, Q, or Mk5, which utilize a random number generator that is not compromised. Before moving substantial amounts of funds, it is advisable to conduct test transactions.

For those who prefer to continue using the Mk3 device, Coinkite has introduced an advanced dice-roll seed generation option to bypass the compromised RNG.

Regardless of your choice, verifying the eight-digit XFP fingerprint on your wallet every time you interact is strongly advised. The XFP serves as a short identifier derived from your master public key, enhancing your security procedure. Keep your old backups until you have fully confirmed the migration process to ensure all bases are covered.

#Why Is This Knowledge Important?

Coinkite's transparency in this matter deserves attention. The advisory is clearly outlined, providing actionable steps and specific information about the affected firmware versions. This approach not only informs users about the issue but also guides them towards resolving it effectively, rather than opting for a quiet fix without acknowledgment. By staying informed and proactive, you can better safeguard your digital assets and navigate the complexities of hardware security.

A sharper way to see the markets in just 5 minutes.

Same news, different lens. We cut through the noise and hand you the overlooked ideas and the deeper read the crowd misses. Join 38,000+ investors seeing the markets differently.

I agree to the privacy policy.

Important Notice And Disclaimer

This article does not provide any financial advice and is not a recommendation to deal in any securities or product. Investments may fall in value and an investor may lose some or all of their investment. Past performance is not an indicator of future performance.