Coldcard's seed generator fell back on weak software randomness instead of hardware entropy. This flaw persisted for five years. Attackers predicted the weak random numbers and derived private keys to drain wallets.
Only if you generated your wallet seed on a Coldcard between March 2021 and the firmware patch. Check your device's firmware version on Coinkite's website. Seeds created before March 2021 or after the patch are safe.
If vulnerable, transfer all bitcoin from the affected wallet to a new seed on a patched device or a different hardware wallet. Do this today. Use one transaction to minimize fees. Do not delay or test with small amounts first.
Upgrade your Coldcard firmware to the latest patched version. Generate a completely new seed on the updated device. Move all funds to this new wallet. Never reuse a seed generated during the vulnerable period.
This hack cannot be reversed. The only defense is moving funds before attackers find them. Check your firmware version right now. If you fall in the vulnerable window, migrate immediately. Do not wait for more information.
Read More →