Mk3 Security Advisory | COINKITE Blog
×<br>Home<br>Blog<br>Careers<br>Contact<br>RSS<br>Email Newsletter
Store
Out of an abundance of caution, Coinkite is warning all users who<br>generated a seed using a Mk3 on version 4.0.1 (March 2021) or any<br>subsequent version that their funds may be at risk.
Mk4, Q and Mk5 are not affected based on our early analysis of the issue.
The issue is present through firmware version 5.0.3,<br>the final release that supported Mk3.
Investigation Ongoing
This advisory reflects our early analysis. Our investigation is ongoing,<br>and a formal technical review will be released as soon as possible.
If You Used a Passphrase
If the affected Mk3 seed was used with a BIP-39 passphrase, our early<br>analysis indicates that your funds are at minimal risk from this issue.<br>This means a BIP-39 passphrase, not the COLDCARD PIN. Continue to protect<br>that passphrase and do not enter it into a website or an untrusted device.
If the Mk3 Is Your Only Option
If you cannot immediately move to an unaffected device, create a strong,<br>unique BIP-39 passphrase on the Mk3 and move the funds from the original<br>wallet to the new passphrase-protected wallet. Treat this as an interim<br>measure until you can migrate to a new seed generated on an unaffected<br>device.
Proceed calmly and carefully:
Read the COLDCARD BIP-39 passphrase<br>instructions before starting.
On the Mk3, select Passphrase and enter a long, random, unique<br>passphrase. Do not use a quotation, familiar phrase, name, or reused<br>password. Do not enter the passphrase on a computer, phone, or website.
Back up the passphrase exactly and separately from the seed words. Losing<br>it means losing access to the funds.
Select APPLY and record the new wallet’s eight-digit fingerprint<br>(XFP).
Power the Mk3 off, turn it back on, re-enter the passphrase, and confirm<br>that the same XFP appears before using the new wallet.
Export the new passphrase wallet to your coordinator and verify its<br>receive address on the Mk3 screen.
Power-cycle the Mk3 and sign in without applying the passphrase to return<br>to the original wallet. Send a small test transaction to the verified<br>address. Re-enter the passphrase and confirm the test funds arrived<br>before moving the remainder.
Every passphrase, including one with a typo, creates a different valid<br>wallet. Verify the XFP every time before sending funds.
Advanced Alternative: Dice-Only Seed
If you are confident in your ability to perform and verify a dice-only<br>migration, you can also create a replacement seed on the Mk3 without using<br>its random-number generator. On an empty Mk3 running 4.1.9, select Import<br>Existing > Dice Rolls and enter at least 99 independent rolls of a fair<br>six-sided die. This dedicated dice-only path hashes the roll sequence<br>directly; it does not use the device’s generator. Do not use the normal<br>New Wallet flow if your goal is to exclude the device generator.
This is an advanced procedure. A one-device migration requires safely<br>alternating between the old and new seeds. Before erasing either seed from<br>the Mk3, verify its written backup and XFP. Verify a receive address for the<br>dice-generated wallet, restore and verify the original wallet, and send a<br>small test transaction before moving the remainder. Keep the original<br>backup until the entire migration is confirmed.
The dice-roll sequence is secret key material. Never photograph it, save it<br>digitally, or enter it into a networked computer. Read the COLDCARD<br>dice-roll method<br>before attempting this option.
Migrate Carefully
When migrating to a new key, calm and care should be applied. Rushing a<br>wallet migration can create a more immediate risk than the issue you are<br>trying to address.
Mk4, Mk5, and later COLDCARD models are not affected based on our early<br>analysis and can be used to generate the new seed:
Generate a new seed on the unaffected COLDCARD.
Record and verify its backup before depositing funds.
Verify a new receive address on the COLDCARD screen.
Send a small test transaction and confirm that the new wallet works.
Only then move the remaining funds.
Keep the old backup until the migration is complete and confirmed.
We are continuing to investigate. More details will follow.