COLDCARD Device Vulnerability Reproduced by Bitcoin Core Developer
A vulnerability in COLDCARD devices has been successfully reproduced by Bitcoin Core developer instagibbs. The issue, which affects MK2/MK3 devices, was initially reported but not confirmed. Instagibbs stated that he was able to reproduce the problem on a newly initialized COLDCARD MK3 device using only button presses during setup.
The developer believes the vulnerability is present in devices up to the MK4 model, although he cannot confirm its presence in the latest MK4 iteration. However, Antoine Poinsot pointed out that the key difference between the MK4 and previous models lies in their use of a hardware random number generator for seed entropy.
The proof-of-concept and mnemonic verification are still under review, and users are advised to exercise caution. Instagibbs' statement 'Sorry, now is the time to panic' suggests that the issue may have significant implications for COLDCARD device owners.