COINKITE WARNS COLDCARD MK3 USERS OF POTENTIAL FUND RISK
Coinkite is urging anyone who generated a seed on a COLDCARD Mk3 running firmware version 4.0.1 (released March 2021) or later to treat their funds as potentially at risk.
The company says the vulnerability affects all Mk3 firmware through version 5.0.3, the final release for the device.
Based on its initial analysis, Coinkite says Mk4, Q, and Mk5 devices are not affected.
Users who protected their Mk3 wallet with a BIP-39 passphrase face minimal risk, according to the company.
Coinkite recommends migrating funds to a newly generated seed on an unaffected device, or, if necessary, using a strong BIP-39 passphrase or a dice-only seed as an interim measure.
The company says its investigation is ongoing and a full technical review will follow.
