BLOCK WARNS COLDCARD VULNERABILITY MAY HAVE ENABLED ONGOING WALLET DRAINS
Block says it began investigating reports of non-Bitkey wallets being remotely drained and identified two vulnerabilities affecting Coldcard Mk2, Mk3, Mk4, Q, and Mk5 devices at varying levels.
According to Block, vulnerable firmware generated wallet seeds with far less randomness than intended, potentially making some wallets predictable to attackers.
The company warns the attack is likely ongoing and says simply importing an affected seed into a different wallet does not eliminate the risk, as the seed itself remains compromised.
Block says no Bitkey or other Block products are affected and that it disclosed its findings to Coinkite before publishing its report.
1/ Earlier today, our Bitcoin engineering and security teams at Block began investigating reports of non-Bitkey wallets being drained. To proactively protect our customers, we began investigating immediately. Here’s what we found 🧵