A Severe Bug in Coldcard MK3 Puts Over a Thousand Bitcoin at Risk
A cyberattack that began on July 30 exposed a critical vulnerability in Coldcard MK3 devices, one of the most widely used Bitcoin hardware wallets. According to initial estimates, over a thousand Bitcoin, worth approximately $70 million, have already been stolen. The flaw involves the generation of private keys, a process that, under certain specific conditions, would have been compromised by a bug in the device's firmware.
Technical Details of the Vulnerability
Coldcard MK3 devices with firmware version 4.0.1 (March 2021) up to 4.1.9 are the most affected. Seeds of 12 or 24 words generated by the device without the addition of dice rolls by the user or an extra BIP 39 passphrase are vulnerable. Users who fall into this category and hold Bitcoin in an unprotected Coldcard MK3 should consider themselves at risk and immediately transfer their funds.
The vulnerability lies in a specific line of code in the firmware, the low-level software that controls the device's hardware. Coinkite, the manufacturer of Coldcard, has published an urgent update with instructions for resolving the issue. Users are advised to update the firmware of their devices, but it is important to emphasize that the update does not repair seeds generated previously with the vulnerable firmware. To protect the funds, it is necessary to create a new wallet and transfer the funds to the newly generated addresses.
Risks for Multisignature Wallets
Peter Todd, a leading contributor to Bitcoin and a cybersecurity engineer, highlighted some particular cases involving multisignature wallets. In a thread on X, Todd explained that if a multisignature wallet uses multiple Coldcard devices, even just one of them could be sufficient to compromise the entire system. "For example, if you have a 2-of-3 with two Coldcards and a third uncompromised device, when you move your funds, the moment the script is revealed for the first time - previously hidden behind the address hash - the attacker now knows enough to use the compromised keys of the two Coldcards to steal your funds," Todd wrote.
To mitigate this risk, Todd suggested using the private mining service Slipstream by MARA, a mining pool that promises to keep the transaction secret until it is already in a block. This drastically reduces the possibility that the attacker could steal the funds.
Implications for the Cryptocurrency Industry
NVK, one of the co-founders of Coldcard, published an in-depth analysis of the attack, emphasizing how the use of artificial intelligence is changing the dynamics of cybersecurity. "We believe this is a sobering reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that surpasses even the most experienced experts in the industry," NVK wrote.
The attack has highlighted the need for companies to adopt advanced cybersecurity models to protect their systems. During a long public call on X Spaces, industry experts discussed the possible future implications, suggesting that other wallet providers might be subjected to similar tests. In particular, open-source projects that generate private key material will likely be the most affected.
Future Solutions for Self-Custody
Looking ahead, the self-custody industry could benefit from more secure and diversified solutions. Multisignature wallets, for example, can distribute vulnerability risks across different codebases, teams, and hardware. The use of non-software entropy sources, such as dice rolls, has been suggested as a solution to separate users from risks related to entropy generated by software or hardware.
Additionally, covenants, a potential Bitcoin consensus upgrade, could offer new smart contract capabilities, such as wallets that can only send funds to whitelisted addresses, a feature not available in the current Bitcoin script.
Immediate Actions for Users
Users of Coldcard MK3 with vulnerable firmware should immediately update the firmware of their devices. For Coldcard MK4 and MK5 users, updating to version 5.6.0 or later is necessary, while for Coldcard Q users, version 1.5.0Q or later is available. For Coldcard MK3 users, updating to version 4.2.0 or later is recommended.
After updating the firmware, it is crucial to create a new wallet and transfer the funds to the newly generated addresses. Users who have used the dice roll function for entropy or an extra BIP 39 passphrase are not considered at risk.
The attack on Coldcard MK3 represents an important lesson for the entire cryptocurrency industry. While users face the immediate consequences, the industry is already looking to the future, seeking ways to improve the security and resilience of self-custody systems. With the adoption of advanced technologies and improved security practices, the industry can work to prevent similar attacks in the future.
Useful Resources
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not engage in real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decisions.