
A critical firmware vulnerability in Coldcard hardware wallets (MK3, MK4, MK5, and Q) has exposed users to immediate theft, necessitating urgent action to secure funds. Introduced in 2021, the bug compromises seed phrase generation, leaving wallets without a strong 25th-word passphrase or custom entropy susceptible to brute-force attacks. With over 1,100 Bitcoin already stolen, multiple malicious actors are actively scanning the network to drain vulnerable addresses. Users must treat this as a "code red" emergency, prioritizing the immediate migration of assets to secure, non-impacted custody solutions. While multi-signature setups involving only Coldcards remain at risk, those who utilized external entropy or robust passphrases are relatively safer. This incident highlights the catastrophic nature of foundational cryptographic failures and underscores the necessity for heightened vigilance in self-custody practices as automated, AI-driven exploitation becomes increasingly prevalent.
Sign in to continue reading, translating and more.
Open full episode in Podwise