Coldcard Seed Generation Flaw Exposes Millions in Vulnerable Bitcoin Funds
A vulnerability has been discovered in the seed generation process of Coldcard's hardware wallets. Specifically, owners of Mk3 devices that generated seeds on firmware 4.0.1 or later may be at risk, as well as those with Mk4 and Mk5 devices before firmware 5.6.0 and Q devices before 1.5.0Q.
This issue allows attackers to recreate private keys from the press of a button, which is a significant security concern for users who have not taken proper precautions.
CoinKite advises affected users to verify their backup, fingerprint, and receive address, send a small test payment, and then move the balance. This will limit the chance that urgency causes a second failure due to a mistyped address or incomplete backup.
The company also emphasizes the importance of using strong, unique passphrases and multisig wallets to add an extra layer of security. However, even with these precautions in place, affected users may still need to rotate their keys and perform an on-chain transfer to secure their funds.