Damus
Derek Ross profile picture
Derek Ross
@Derek Ross
Coldcard Security Vulnerability: What You Need to Know

If you generated your seed words on a Coldcard WITHOUT rolling a die 100+ times yourself AND without adding a strong passphrase as your 25th word, your wallet may be vulnerable. This affects all Coldcard devices. The device didn't use sufficient entropy on its own, meaning someone could potentially recreate your seed.

What are your options?

1) Move your funds immediately. Transfer your bitcoin to another wallet. Sparrow, your own node, Aqua, or almost anywhere else. This is a temporary fix, but it gets your funds out of harm's way. Practice standard security hygiene with wherever you park them.

2) Update and regenerate. Flash your Coldcard to the latest firmware, then generate a brand new wallet by manually rolling dice 100+ times and adding a strong passphrase. This significantly improves your security, but honestly, after a vulnerability like this, it's hard to fully trust the device again.

3) Get a Bitkey from Block. No seed words, no passphrases. All complexity is hidden. It uses multi-sig for security instead, and the UX is genuinely great. I've bought several for family members and recommend it highly. Different approach, but rock solid. Literally.

4) Get a Trezor Safe 7. It's a Bitcoin only version from the company that literally invented hardware wallets. I haven't used one personally, but trusted friends and colleagues swear by them, no issues, feel secure.

The bottom line: if you're using a Coldcard with a device generated seed and no passphrase, don't wait. Move your funds and upgrade your setup. Please.
5923❤️26👍3❤️2🤙2🫂2💜1
Brunswick · 6w
No mention of nostr:nprofile1qqs09jtvjlmyrxjn37zv70a89csegcz7rpyqjmnw29cveedhv7vagqqpzemhxue69uhk2er9dchxummnw3ezumrpdejz7qg4waehxw309aex2mrp0yhxgctdw4eju6t09uq3zamnwvaz7tmwdaehgu3wwa5kuef0x9u2rf 🤔
Vince · 6w
Would you be happy to store your whole stack on a Bitkey?
MrNice · 6w
Serious question: shouldn’t you update your Coldcard first to the latest firmware and THEN move your funds? Or does it not matter at this point (if you haven’t rolled dice and/ or have a 25th word)?
LiveJazz · 6w
Not affected by the Cold Card situation, but have been pondering a move to BitKey for awhile. I don’t trust myself to set up multisig myself, and the shared access for family / beneficiary options are appealing. This situation might push me all the way to move.
RobOK 🔸 · 6w
Your numbering may cause confusion. Do 1 NOW for mk3. Don’t wait on steps 3 or 4. Also investigate and consider collaborative custody (Unchained, Casa, OnRamp, etc)
Max J · 6w
The other question is, what if I don’t remember how I generated the seed phrase. Is there any way to tell. I probably rolled the dice but don’t remember.
Hanshan · 6w
Unless you're using an old MK3 apparently, because they won't be updating the firmware.
FeynStructure · 6w
"All complexity is hidden." That's the one thing that gives me pause. I'm not so sure this is a good thing.
Chris Porter · 6w
Yep, I lost my whole (small) stack. .43 btc gone :(
NotBiebs and 69 others · 6w
If seed was generated using firmware prior to v4.0.0 (before March 2021), you should be okay from what I understand
daniele · 6w
> Get a Trezor Safe 7. It's a Bitcoin only version from the company that literally invented hardware wallets I don't mean to complicate an already difficult situation by questioning your generally helpful advice, but a few hours ago I went to check out their website specifically to verify this. On...
The Last Satoshi ⚡️ · 6w
Thanks god I rolled the dice’s like 200 times 🤣
Mal Gifson · 6w
Yeah honestly, as a non-programmer, I don’t feel certain my dice rolls even played a part of the seed generation. Not feeling as safe as I used to.
Dylan · 6w
Coldcard Q safe?
Dennison · 6w
Shoutout to the best female CNBC crypto analyst on Primal! I managed to clear $73k trading with her guidance just last month. If you're looking to get started with crypto trading, send her a message right here on Primal! ( https://wa.me/18706261990 ) nostr:nprofile1qqsqnyru75t0ajvp6xwyp0kc82zp2tja...
GregAsks · 6w
nostr:nevent1qvzqqqqqqypzpyvps02e3t8jmj5qelqvm6j2pmjc3yj3w4ll836u2s20qpkknxh9qythwumn8ghj7un9d3shjtnswf5k6ctv9ehx2ap0qyfhwumn8ghj7mmxve3ksctfdch8qatz9uqzquwgh0x9nnlj5pjlyzpat76ccq2jtjp9tcnc4vahphlgc8wq2t8qtjhajr
H · 6w
I’m kind of reluctant to flash the new firmware immediately. I think ~160 dice rolls would be sufficient to create a new secure seed (Ian Coleman’s website calculates one dice roll = average of1.67 bits of entropy).
theGreenBastard · 6w
If generated with dice rolls (100+) but no passphrase 25th word, is btc still safe or should it be moved to a ledger or something?