Wanted to send out an email PSA that there was a massive security flaw found in a very popular hardware signing device this week, the Coldcard. I’ve used and recommended these for years, and they have been considered the gold standard of security amongst many bitcoiners.
Bottom line, if you used a Coldcard to generate your seed words when you first set it up, which is default behavior, the seed is insecure. Mark 3 models, which were first released in 2021, are the most affected. Mark 4, Mark 5, and Q models are also affected, though less severely than the Mark 3.
If you currently use a Coldcard, I recommend sending whatever sats you have in it to another wallet. As the saying goes, slow is smooth, and smooth is fast…don’t rush this process. Other signing devices aren’t affected by this (Passport, Jade, Trezor, Ledger).
More elaboration on bitcoin ten commandments, and more info on future meetups incoming…wanted to get this message out this weekend.
Upward and onward!
~Joe
Bitcoin in the Burg
- Provide value to others
- Spend less than you earn
- Save in a money that can’t be printed by someone else for free
Leave a comment