Loading market data...

Coldcard Mk3 Seed Generation Flaw Lets Attackers Recreate Keys, Coinkite Warns

Coldcard Mk3 Seed Generation Flaw Lets Attackers Recreate Keys, Coinkite Warns

How the flaw works

->

漏洞原理

The Mk3 generates entropy by measuring the timing of user button presses during initialization. That randomness turned out to be far too predictable. The issue affects Mk3 devices running firmware 4.0.1 or later, as well as Mk4 and Mk5 units before firmware 5.6.0, and Q devices before version 1.5.0Q. Coinkite, the company behind Coldcard, published an advisory this week detailing the problem and urging users to migrate.

Translation:

Mk3 通过测量初始化期间用户按键的时间来生成熵。事实证明,这种随机性过于可预测。该问题影响运行固件 4.0.1 或更高版本的 Mk3 设备,以及固件 5.6.0 之前的 Mk4 和 Mk5 设备,以及 1.5.0Q 之前的 Q 设备。Coldcard 背后的公司 Coinkite 本周发布了一份公告,详细说明了该问题并敦促用户迁移。

Next:

Who is affected

->

受影响人群

The highest-risk profile is a Mk3-generated seed used in a single-signature setup with no BIP-39 passphrase, no dice entropy, and no multisig. A strong passphrase adds an independent barrier, but Coinkite still recommends migration. Multisig setups confine the risk to one signer — if the other keys are independent, the overall wallet remains safe. User-supplied dice entropy can mitigate the flaw, but only if at least 50 fair rolls were used; fewer rolls or any uncertainty still requires a full migration.

Translation:

风险最高的情况是使用 Mk3 生成的种子,且采用单签名设置,没有 BIP-39 密码短语、没有骰子熵、也没有多重签名。强密码短语会增加一道独立屏障,但 Coinkite 仍建议迁移。多重签名设置将风险限制在一个签名者身上——如果其他密钥是独立的,整个钱包仍然是安全的。用户提供的骰子熵可以缓解该漏洞,但前提是至少使用了 50 次公平掷骰;如果掷骰次数较少或存在任何不确定性,仍需完全迁移。

Note: "dice entropy" - 骰子熵, common term. "fair rolls" - 公平掷骰. Next:

What users need to do

->

用户需要做什么

There is no firmware fix that can change existing keys. The only remedy is to generate a new seed on an unaffected device and transfer all funds. Coinkite recommends verifying the backup, fingerprint, and receive address, then sending a test payment before moving the full balance. The advisory covers Mk3 devices manufactured from March 2021 onward, with the final Mk3 firmware released in June 2023 — meaning there is a roughly three-year window during which dormant holders may still be using vulnerable seeds.

Translation:

没有固件修复可以改变现有密钥。唯一的补救措施是在未受影响的设备上生成新种子并转移所有资金。Coinkite 建议验证备份、指纹和接收地址,然后在转移全部余额之前发送测试付款。该公告涵盖 2021 年 3 月之后制造的 Mk3 设备,最终 Mk3 固件于 2023 年 6 月发布——这意味着大约有三年的时间窗口,在此期间,休眠持有者可能仍在使用易受攻击的种子。

Next:

The three-year gap

->

三年窗口期

That gap is the real worry. Anyone who bought a Mk3 in 2021 or 2022, set it up, and then put it in a drawer may not have updated firmware or thought about seed generation. Coinkite's warning is clear: if you have a Mk3 seed generated during that period, assume it is compromised. The company advises moving funds to a new wallet generated on a Mk4, Mk5, or Q device with the latest firmware, or using a different hardware wallet entirely.

Translation:

这个窗口期才是真正的担忧。任何在 2021 年或 2022 年购买 Mk3、完成设置然后将其放入抽屉的人,可能没有更新固件或考虑过种子生成。Coinkite 的警告很明确:如果你在该时期生成了 Mk3 种子,请假定它已被泄露。该公司建议将资金转移到使用最新固件的 Mk4、Mk5 或 Q 设备生成的新钱包,或者完全使用其他硬件钱包。

Now meta description: "A seed generation flaw in Coldcard Mk3 hardware wallets uses weak button-press randomness, allowing attackers to recreate keys. Coinkite urges users to migrate funds immediately." Translate: "Coldcard Mk3 硬件钱包的种子生成漏洞使用弱按钮按压随机性,允许攻击者重建密钥。Coinkite 敦促用户立即迁移资金。" Now we need to output JSON with title, content (full HTML), and meta description. We must ensure the content is exactly the translated HTML, preserving tags. Let's assemble the content string:

Coldcard Mk3 硬件钱包的种子生成过程存在漏洞,由于按钮按压产生的随机性较弱,攻击者可以重建私钥。Bitcoin Core 贡献者 instagibbs 在新初始化的 Mk3 上重现了易受攻击的种子,证实了这一风险。该漏洞破坏了硬件钱包本应保证的“气隙”安全——如果攻击者能够预测种子,他们就可以派生地址并监控存款,而无需接触设备。

漏洞原理

Mk3 通过测量初始化期间用户按键的时间来生成熵。事实证明,这种随机性过于可预测。该问题影响运行固件 4.0.1 或更高版本的 Mk3 设备,以及固件 5.6.0 之前的 Mk4 和 Mk5 设备,以及 1.5.0Q 之前的 Q 设备。Coldcard 背后的公司 Coinkite 本周发布了一份公告,详细说明了该问题并敦促用户迁移。

受影响人群

风险最高的情况是使用 Mk3 生成的种子,且采用单签名设置,没有 BIP-39 密码短语、没有骰子熵、也没有多重签名。强密码短语会增加一道独立屏障,但 Coinkite 仍建议迁移。多重签名设置将风险限制在一个签名者身上——如果其他密钥是独立的,整个钱包仍然是安全的。用户提供的骰子熵可以缓解该漏洞,但前提是至少使用了 50 次公平掷骰;如果掷骰次数较少或存在任何不确定性,仍需完全迁移。

用户需要做什么

没有固件修复可以改变现有密钥。唯一的补救措施是在未受影响的设备上生成新种子并转移所有资金。Coinkite 建议验证备份、指纹和接收地址,然后在转移全部余额之前发送测试付款。该公告涵盖 2021 年 3 月之后制造的 Mk3 设备,最终 Mk3 固件于 2023 年 6 月发布——这意味着大约有三年的时间窗口,在此期间,休眠持有者可能仍在使用易受攻击的种子。

三年窗口期