A researcher-funded wallet protected only by the vulnerable mnemonic was emptied within 14 hours, while passphrase-protected and more complex setups remained untouched.
Attackers exploiting the Coldcard Mk3 RNG vulnerability appear to be targeting the easiest wallets to brute-force first, based on community honeypot tests highlighted by Bitcoin News on X. Researcher @ColeTU funded five affected Mk3 wallets: one secured only by the vulnerable mnemonic, three protected with BIP39 passphrases of 1, 2, and 3 words, and one using a random account number. After 14 hours, only the wallet using just the mnemonic had its funds moved. Data from @jamesob's real-time tripwire dashboard showed that only 2 of 17 honeypot wallets had been emptied so far. Those drained wallets were confirmed not to have added extra entropy, while wallets protected by dice rolls, passphrases, multisig, or other added complexity remained untouched. The results suggest attackers are focusing on the lowest-effort targets rather than spending resources on harder wallets, but affected users are still urged to move funds immediately instead of relying on temporary defenses.