Skip to content
Back to Guavy Wire
Crypto

COLDCARD Device Vulnerability Reproduced by Bitcoin Core Developer

Instruments
BTC COL
Share

A vulnerability in COLDCARD devices has been successfully reproduced by Bitcoin Core developer instagibbs. The issue, which affects MK2/MK3 devices, was initially reported but not confirmed. Instagibbs stated that he was able to reproduce the problem on a newly initialized COLDCARD MK3 device using only button presses during setup.

The developer believes the vulnerability is present in devices up to the MK4 model, although he cannot confirm its presence in the latest MK4 iteration. However, Antoine Poinsot pointed out that the key difference between the MK4 and previous models lies in their use of a hardware random number generator for seed entropy.

The proof-of-concept and mnemonic verification are still under review, and users are advised to exercise caution. Instagibbs' statement 'Sorry, now is the time to panic' suggests that the issue may have significant implications for COLDCARD device owners.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Real-time market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc