New honeypot tests reveal that attackers prioritize the most easily exploited wallets within the Coldcard Mk3. Researcher @ColeTU injected funds into five affected Mk3 wallets, one of which used only a vulnerable mnemonic, while three were protected by BIP39 passphrases of one, two, and three words respectively, and the last used a random account number. After 14 hours, only the unprotected wallet, which relied solely on the mnemonic, had its funds transferred out. A real-time tripwire dashboard shows that out of 17 honeypot wallets, only two have been emptied, and it has been confirmed that the emptied wallets did not incorporate additional entropy; all wallets protected by dice rolls, passphrases, multisig, or other complexities remain untouched. The test results indicate that attackers focus on the wallets that are easiest to brute-force, and affected users should immediately migrate their funds instead of relying on temporary protections.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























