Coldcard Users Warned of Brute-Force Seed Phrase Vulnerability
A critical security issue has been discovered in Coldcard hardware wallets, potentially putting user funds at risk. The issue affects users who generated their word seed using a method that was deemed insecure after December 2020.
According to an official announcement from Coinkite, the vulnerability allows attackers to brute-force users' seed phrases without any action on their part. This can result in wallets being drained of their funds.
The affected devices include Coldcard MK3, MK4, MK5, and Q models, as well as ephemeral keys and session keys for Clone Coldcard or Key Teleport features. Users who used a Coldcard to generate a word seed using the dice roll method are safe, provided they rolled at least 50 dice.
The issue has already been exploited, with around 1000 BTC moving on-chain connected to the vulnerability. Users are advised to move their funds to a new word seed or a different device as soon as possible.