Login
Sign Up
Woofun AI reports that a seed-generation vulnerability in Coinkite’s Coldcard hardware wallets extends beyond the previously identified Mk3 model, as revealed by Max Guise, lead developer of Block’s Bitcoin wallet Bitkey.
The compromised device list now includes the Mk2, Mk4, Q, and Mk5 models, Guise emphasized that the severity of the flaw varies significantly across these different hardware iterations, creating a fragmented risk profile for users depending on their specific device generation.
Woofun AI notes that the likelihood of an ongoing theft attack is high, posing a risk of additional wallets being compromised even if recovery phrases are migrated elsewhere. The attack surface encompasses multi-signature setups where two or more key generation processes are affected, as well as wallets relying on easily guessable passphrases. While Block’s Bitkey is confirmed not affected, these findings have been shared with Coinkite for immediate review.
Hardware wallet users must prioritize cold storage security by monitoring firmware updates and official security advisories from Coinkite. This incident underscores the critical need for rigorous security audits across all models to protect digital assets from hidden architectural flaws.