Damus
Derek Ross profile picture
Derek Ross
@Derek Ross
Coldcard Security Vulnerability: What You Need to Know

If you generated your seed words on a Coldcard WITHOUT rolling a die 100+ times yourself AND without adding a strong passphrase as your 25th word, your wallet may be vulnerable. This affects all Coldcard devices. The device didn't use sufficient entropy on its own, meaning someone could potentially recreate your seed.

What are your options?

1) Move your funds immediately. Transfer your bitcoin to another wallet. Sparrow, your own node, Aqua, or almost anywhere else. This is a temporary fix, but it gets your funds out of harm's way. Practice standard security hygiene with wherever you park them.

2) Update and regenerate. Flash your Coldcard to the latest firmware, then generate a brand new wallet by manually rolling dice 100+ times and adding a strong passphrase. This significantly improves your security, but honestly, after a vulnerability like this, it's hard to fully trust the device again.

3) Get a Bitkey from Block. No seed words, no passphrases. All complexity is hidden. It uses multi-sig for security instead, and the UX is genuinely great. I've bought several for family members and recommend it highly. Different approach, but rock solid. Literally.

4) Get a Trezor Safe 7. It's a Bitcoin only version from the company that literally invented hardware wallets. I haven't used one personally, but trusted friends and colleagues swear by them, no issues, feel secure.

The bottom line: if you're using a Coldcard with a device generated seed and no passphrase, don't wait. Move your funds and upgrade your setup. Please.
6926❤️31👍3❤️2🤙2🫂2💜1
Max J · 3d
The other question is, what if I don’t remember how I generated the seed phrase. Is there any way to tell. I probably rolled the dice but don’t remember.
Hanshan · 3d
Unless you're using an old MK3 apparently, because they won't be updating the firmware.
FeynStructure · 3d
"All complexity is hidden." That's the one thing that gives me pause. I'm not so sure this is a good thing.
Chris Porter · 3d
Yep, I lost my whole (small) stack. .43 btc gone :(
NotBiebs and 69 others · 3d
If seed was generated using firmware prior to v4.0.0 (before March 2021), you should be okay from what I understand
daniele · 3d
> Get a Trezor Safe 7. It's a Bitcoin only version from the company that literally invented hardware wallets I don't mean to complicate an already difficult situation by questioning your generally helpful advice, but a few hours ago I went to check out their website specifically to verify this. On...
The Last Satoshi ⚡️ · 3d
Thanks god I rolled the dice’s like 200 times 🤣
Mal Gifson · 3d
Yeah honestly, as a non-programmer, I don’t feel certain my dice rolls even played a part of the seed generation. Not feeling as safe as I used to.
Dylan · 3d
Coldcard Q safe?
Carlos Dave · 3d
Honestly, Trading with nostr:nprofile1qqs9206rfkj3v7ze4s9n4vwwuw74u8cqnvr7aa6n72quzsh7tvsnc3qpp4mhxue69uhkummn9ekx7mqpzpmhxue69uhkummnw3ezumrpdejqe4330z has been one the best decision I've ever made especially as a newbie and I recommend him to everyone who is finding it difficult around the market....
Dennison · 3d
Shoutout to the best female CNBC crypto analyst on Primal! I managed to clear $73k trading with her guidance just last month. If you're looking to get started with crypto trading, send her a message right here on Primal! ( https://wa.me/18706261990 ) nostr:nprofile1qqsqnyru75t0ajvp6xwyp0kc82zp2tja...
Ericsson · 3d
I highly recommend Craig to anyone serious about improving their crypto trading. His focus on discipline, risk management, and understanding the market has helped me become a more confident and consistent trader. If you're looking for genuine guidance instead of hype, Craig is someone worth learning...
GregAsks · 2d
nostr:nevent1qvzqqqqqqypzpyvps02e3t8jmj5qelqvm6j2pmjc3yj3w4ll836u2s20qpkknxh9qythwumn8ghj7un9d3shjtnswf5k6ctv9ehx2ap0qyfhwumn8ghj7mmxve3ksctfdch8qatz9uqzquwgh0x9nnlj5pjlyzpat76ccq2jtjp9tcnc4vahphlgc8wq2t8qtjhajr
H · 2d
I’m kind of reluctant to flash the new firmware immediately. I think ~160 dice rolls would be sufficient to create a new secure seed (Ian Coleman’s website calculates one dice roll = average of1.67 bits of entropy).
theGreenBastard · 2d
If generated with dice rolls (100+) but no passphrase 25th word, is btc still safe or should it be moved to a ledger or something?
latif · 1d
Thank you. This is the way. Stay safe, everyone!