pull down to refresh

Summary of Situation as of this Time

ACTION RECOMMENDATION: PLEASE CAREFULLY MOVE FUNDS STORED ON COLDCARD WALLETS CREATED FROM DEVICE-GENERATED ENTROPY TO UNAFFECTED WALLETS ASAP.

Any funds on a COLDCARD Mk3 using a firmware from version 4.0.1 (March 2021) to 4.1.9 (latest version as of yesterday), where the entropy was only generated by the device, should be considered compromised. COLDCARD Mk4, Mk5, and Q are affected by the same issue to a lesser degree. Wallets generated by those devices are at risk of theft. Wallets that pair the device entropy with a strong passphrase or wallets created with externally generated entropy with at least 50 dice throws should not be exposed. If you used a weak passphrase and did not input external entropy (at least fifty dice throws), your funds are at risk.

Coinkite has released firmware updates for COLDCARD Mk3, Mk4, Mk5, and Q. Wallets generated with the new firmware should be secure. Updating to the new firmware does not make affected wallets secure. Only new wallets generated with the new firmware are unaffected. Coinkite put out a security advisory. The security advisory has been updated to include more devices, more details about the issue, and migration advice.

Block security researchers reports that the COLDCARD Mk2 is affected the same way as the Mk3.

Anyone with access to a frontier AI model is capable of reproducing the attack. Especially if you have funds on a COLDCARD single-sig wallet created with wallet-generated entropy, please carefully move your funds to an unaffected wallet ASAP. Single-sig wallets with a weak passphrase, or multisig wallets that can be spent by a quorum of COLDCARD wallets or composed only of COLDCARD wallets created with device-generated entropy should be considered at risk and funds should also be moved.