Only the unprotected wallet was drained—Coldcard Mk3 honeypot test shows attackers still prioritize the easiest-to-crack wallets
2026-08-06 10:48
Odaily Planet Daily News: Bitcoin News posted on X platform stating that a new community honeypot test shows attackers are still prioritizing the most easily exploitable wallets affected by the Coldcard Mk3 RNG vulnerability. Researcher @ColeTU injected funds into 5 affected Mk3 wallets: 1 using only the vulnerable mnemonic seed, 3 protected respectively by 1-word, 2-word, and 3-word BIP39 passphrases, and 1 using a random account number. After 14 hours, only the unprotected wallet using just the mnemonic seed had its funds transferred out. Additionally, according to @jamesob's real-time tripwire dashboard, only 2 of the 17 honeypot wallets have been drained so far. Confirmed drained wallets all lacked added entropy, while all wallets protected by dice rolls, passphrases, multisig, or other complexity measures remain untouched. The test results show that attackers are currently focusing on wallets that are easiest to brute-force rather than investing resources in hardened targets—but affected users should still migrate funds immediately rather than relying on temporary protection.
