Coldcard Hardware Wallets Exposed to Weak Randomness Vulnerability
A recent security failure in some Bitcoin hardware wallets has left users vulnerable to theft. The issue arises from weak randomness in seed generation, allowing attackers to reproduce candidate seeds and identify matching Bitcoin addresses.
The affected wallets are Coldcard's Mk2 and Mk3 models running firmware versions 4.0.1 through 4.1.9, as well as Mk4, Mk5, and Q models with standard firmware before version 5.6.0 or Edge 6.6.0X.
According to estimates, the affected seeds have around 40-72 bits of effective search space, making it easier for attackers to find matching addresses.
To protect against this vulnerability, users should update their wallets to fixed firmware and create a new seed with trustworthy entropy.