pull down to refresh

Summary of Situation as of this Time

Any funds on a Coldcard Mk3 using a firmware version 4.0.1 (March 2021) or later, up to the current version, where the entropy was generated by the Coldcard and it was not paired with a strong password, are at risk.

Coinkite has put out a security advisory.

It looks like anyone with access to a regular LLM subscription is capable of reproducing the attack now. If this describes your wallet setup, please move your funds to an unaffected wallet ASAP. Please move deliberately enough to move your funds safely, people make mistakes when they rush.

Mk2 may also be at risk, unclear.

Issues with Mk4 and Mk5 are now also being reported.

If you hold funds in any Coldcard single-sig wallet without password, you should consider moving those funds.

reply

fortunately, if you generated the seeds with dice, you may still be able to maintain some confidence that it can be used as part of your new multi-sig setup:

it looks like the dice roll code is not total shit.

reply

important to note it needs SUFFICIENT DICE ROLLS

reply

Anthropic making bank tonight.

reply
reply

what's the context, another hack or someone shoring up funds?

reply

Rob didn't add any context, but I scanned through some of the inputs and all the ones I looked at are from a similar era to the others.

it does kind of have the hallmarks...

reply