Coldcard's key generation produced weak random numbers. This narrowed the private key search space from impossible to computable, allowing direct key recovery.
Unlike supply-chain breaches (Trezor), this flaw was embedded in firmware. Affected devices generated mathematically weaker keys.
Devices made before mid-2024 or running older firmware are most vulnerable. Update to the latest firmware and check Coldcard's official advisory for your device.
Ledger, Trezor, and Foundation use different entropy generation. All hardware wallet users should update to the latest firmware and monitor addresses for unauthorized activity.
Monitor your public addresses for unauthorized transactions. If keys were compromised, plan a key rotation: generate new seeds and move Bitcoin to new addresses.
This incident is fixable and affected a specific device. Software wallets face continuous malware, phishing, and exchange theft exposure.
Read More →