Coldcard Security Vulnerability: What You Need to Know
If you generated your seed words on a Coldcard WITHOUT rolling a die 100+ times yourself AND without adding a strong passphrase as your 25th word, your wallet may be vulnerable. This affects all Coldcard devices. The device didn't use sufficient entropy on its own, meaning someone could potentially recreate your seed.
What are your options?
1) Move your funds immediately. Transfer your bitcoin to another wallet. Sparrow, your own node, Aqua, or almost anywhere else. This is a temporary fix, but it gets your funds out of harm's way. Practice standard security hygiene with wherever you park them.
2) Update and regenerate. Flash your Coldcard to the latest firmware, then generate a brand new wallet by manually rolling dice 100+ times and adding a strong passphrase. This significantly improves your security, but honestly, after a vulnerability like this, it's hard to fully trust the device again.
3) Get a Bitkey from Block. No seed words, no passphrases. All complexity is hidden. It uses multi-sig for security instead, and the UX is genuinely great. I've bought several for family members and recommend it highly. Different approach, but rock solid. Literally.
4) Get a Trezor Safe 7. It's a Bitcoin only version from the company that literally invented hardware wallets. I haven't used one personally, but trusted friends and colleagues swear by them, no issues, feel secure.
The bottom line: if you're using a Coldcard with a device generated seed and no passphrase, don't wait. Move your funds and upgrade your setup. Please.
If you generated your seed words on a Coldcard WITHOUT rolling a die 100+ times yourself AND without adding a strong passphrase as your 25th word, your wallet may be vulnerable. This affects all Coldcard devices. The device didn't use sufficient entropy on its own, meaning someone could potentially recreate your seed.
What are your options?
1) Move your funds immediately. Transfer your bitcoin to another wallet. Sparrow, your own node, Aqua, or almost anywhere else. This is a temporary fix, but it gets your funds out of harm's way. Practice standard security hygiene with wherever you park them.
2) Update and regenerate. Flash your Coldcard to the latest firmware, then generate a brand new wallet by manually rolling dice 100+ times and adding a strong passphrase. This significantly improves your security, but honestly, after a vulnerability like this, it's hard to fully trust the device again.
3) Get a Bitkey from Block. No seed words, no passphrases. All complexity is hidden. It uses multi-sig for security instead, and the UX is genuinely great. I've bought several for family members and recommend it highly. Different approach, but rock solid. Literally.
4) Get a Trezor Safe 7. It's a Bitcoin only version from the company that literally invented hardware wallets. I haven't used one personally, but trusted friends and colleagues swear by them, no issues, feel secure.
The bottom line: if you're using a Coldcard with a device generated seed and no passphrase, don't wait. Move your funds and upgrade your setup. Please.
6926❤️31👍3❤️2🤙2🫂2💜1