So much for the orange man making the US the world leader. He’s too busy obsessing about the reflecting pool paint job and who he’s gonna sue (or bomb) next.
Yeah I’ve been thinking about that. For me the immediate Step 1 was to mitigate the Coldcard seed phrase entropy problem (and not do something to create a bigger problem). Step 2 will be to figure out best practice going forward. Who knows what may be coming next and what signing devices may be affected. But I agree it seems diversification of signing device manufacturers/vendors may be a good call.
I upgraded to latest Coldcard Q firmware, wiped 2 spare Coldcard Q’s and created new seeds using 500+ dice rolls, then moved funds to a new multisig wallet that was created using the new seed phrases (and a seed phrase created using a different hardware signing device). I think that should mitigate the risk?