Coldcard Security Flaw Steals Thousands of Bitcoins
A critical security issue has been discovered in the Coldcard hardware wallet, affecting users who generated their word seed before 2021. The vulnerability allows attackers to find the seed phrase without any action from the user.
The issue affects Coldcard MK3, MK4, MK5, and Q models that used a word seed generated with fewer than 50 dice rolls. This means that users who rolled fewer dice may have seeds that can be brute-forced by attackers.
The problem is being actively exploited, with around 1000 BTC seen moving on-chain connected to the vulnerability. To secure their funds, users must move them to a new word seed or a different device. Users without another hardware wallet can generate a passphrase using at least six seed words from the BIP 39 word list.