security
02

What Was the Bug?

Coldcard's seed generator fell back on weak software randomness instead of hardware entropy. This flaw persisted for five years. Attackers predicted the weak random numbers and derived private keys to drain wallets.

security
03

Am I Affected?

Only if you generated your wallet seed on a Coldcard between March 2021 and the firmware patch. Check your device's firmware version on Coinkite's website. Seeds created before March 2021 or after the patch are safe.

security
04

Action Plan: Move Your Funds

If vulnerable, transfer all bitcoin from the affected wallet to a new seed on a patched device or a different hardware wallet. Do this today. Use one transaction to minimize fees. Do not delay or test with small amounts first.

security
05

Update Your Device

Upgrade your Coldcard firmware to the latest patched version. Generate a completely new seed on the updated device. Move all funds to this new wallet. Never reuse a seed generated during the vulnerable period.

security
06

No Shortcuts

This hack cannot be reversed. The only defense is moving funds before attackers find them. Check your firmware version right now. If you fall in the vulnerable window, migrate immediately. Do not wait for more information.

Read More →