Your signal. Your price.
A Coldcard hardware wallet entropy flaw affected seed phrase generation for specific versions issued approximately between 2021 and 2023, leading to compromised wallets.
For Coldcard users potentially affected by the entropy flaw, Simon Dixon recommends updating firmware, generating a new seed in a calm environment, and moving funds with test transactions.
Block's security research identified vulnerabilities in COLDCARD firmware that could enable Bitcoin theft, stemming from an RNG integration error causing `ngu.random` to default to MicroPython's deterministic Yasmarang fallback.
COLDCARD Mk2/Mk3 v4.0.0-v4.1.9 firmware versions have no cryptographic entropy added to `ngu.random`, making wallet generation deterministic if the device UID, timer state, and RNG-call history are known.
COLDCARD Mk4/Q/Mk5 devices, using production firmware v5.0.0 onward, incorporate a limited secure-element reseed that hashes 32 bytes to retain only four, replacing just one 32-bit Yasmarang state word.