Join Nostr
2026-08-06 17:03:32 UTC

flash on Nostr: ⚡️👀 NEW - Coldcard honeypot tests suggest attackers are still targeting only ...

⚡️👀 NEW - Coldcard honeypot tests suggest attackers are still targeting only the easiest wallets!

New community honeypot tests indicate attackers are continuing to prioritize the lowest-hanging fruit from the Coldcard Mk3 RNG vulnerability.

Researcher Cole funded five compromised Mk3 wallets: one with only the vulnerable seed, three protected by 1-, 2-, and 3-word BIP39 passphrases, and one using a random account number. Fourteen hours later, only the unprotected seed-only wallet had been drained.

Separately, James O'beirne's live tripwire dashboard shows just 2 of 17 honeypot wallets swept so far. The only confirmed sweeps have been wallets with no added entropy, while all wallets protected with dice rolls, passphrases, multisig, or other added complexity remain untouched.

The results suggest attackers are currently focusing on the easiest-to-brute-force wallets rather than expending resources on hardened targets, though affected users should still migrate funds immediately rather than relying on temporary protection.