Reddit Posts
Can we get back to the good ol' days when nobody thought this was a fucking community?
Coldcard Users Reported Instant Drains Years Before July 2026. Here Are the Receipts.
Your keys, not your crypto. A 330K lesson for all.
Coldcard MK4 - are wallets generated with 100% dice at risk?
I barely avoided getting all my BTC robbed with Coldcard - I don't know if I should consider myself lucky or not
My 2 sats on the ColdCard failure, and a weakness it reveals about us, the BTC community
It seems people did not understand what happened to ColdCard
Coldcard lack of "truly randomness" wasn't the issue, it was almost no randomness.
Which HW wallets have native dice roll support for seed generation?
Coldcard multi-sig wallets that have never spent.
Generated Seed on MK3 in 2020 - How Worried Should I Be?
Coldcard MK3 vulnerability just got announced. In one of coldcards older firmware(4.0.1) updates the wallet was using weak entropy for seedphrase generation. Over $38 million in BTC stolen. Coldcard confirmed this on their X page. If you use a coldcard id play it safe and move your BTC asap.
XRP JUST EXPLODED +1.74% AND MY MK ANALYTICS NAILED THE MAX TP HIT… This Chart Is Insane 🚀💰
Coldcard MK5 First Look: My initial impressions and comparison to Mk4/Q models
$MK MemeLinked - social media meets crypto
They thought they could build me. He thinks he can control me.
The code shouldn’t be responding. But it is.
I didn’t mean to leave the code alive. But I did.
Mentions
Literally just purchased one last week lol. I was an MK4 user. Panicked and bought both Trezor and Jade.
This is FUD and speculation. I just bought a MK5 a few days ago and it has already shipped. Their online shop says the units will ship with updated firmware. I'll use dice for entropy and the CC will remain an air-gapped signing device.
The caption should read "The guy you convinced to store on a ColdCard MK4 and you, who are still on Trezor."
I might get one as second (backup) wallet in case MK4 dies or something.
The MK3 was reportedly the most compromised as far as the bug is concerned, so it is especially nice to read that it could be flashed without causing the device to 'brick'.
I was not affected by this at all. Not because I was doing anything special but most likely by pure luck. I was able to transfer my bag elsewhere and made a bonfire with my MK3. I will never support these arrogant clowns in this or any other venture associated with them. Nor do I want to ever hear from any of the asshat griftubers that peddled this shitbox for years. As far as the features I really don’t care about any of it. Will likely go to a dice rolled 24 word + pass phrase seed stamped on metal and a safety deposit box, with a seedsigner for home use.
Both things that were considered advanced schizo stuff at the time. Entering a passphrase on an MK3 would also be a royal pain in the ass.
So, in theory, I can have a wallet with a single seed phrase and derive three wallets from it using different passphrases, with a multisig setup required to transfer my crypto. Could this have prevented what happened with the Coldcard MK3?
Okay, you have a wallet with a seed phrase. This wallet does not hold any funds, and from this wallet you have three wallets with passphrases, whose funds can only be transferred through multisig. Could what happened with the Coldcard MK3 have been prevented with what I just proposed?
The public key is derived from the private key. They are tied together. Once you have the private key, you have the public key too. What they did was calculate all possible private keys the MK3 could generate. Then calculate the wallet address that belonged to each private key. Then scan the UTXO to see which wallets existed. The rest is history.
here i dice rolled (MK4). But somebody mentioned to me that MK4 and Q using the RNG, have a bit more entropy than MK3. But it seems it is still weak.
That's why I said it's a nightmare scenario. Would need KYC, or people sharing serial numbers and such. A sizeable portion probably couldn't prove it. The issue is, if you ask people to migrate, there is a fairly high chance that some attackers would look into the code, find the vulnerability, and sweep all the funds before they can migrate. In this case, more people would likely lose their funds. In the end though, it depends on how bad the fk up is. The MK3 keys can all be cracked on a laptop within hours. For this, I'd say white hat hacking is your best bet. For the MK4+, they are still vulnerable, but it would take years. In a case like this, blaring emergency alerts to move your BTC is a better bet.
Depends. For the Mk4+ yes, but all the MK3 seeds were easily crackable in a few hours on a laptop, I believe. And you're right, it would be a legal nightmare. Would likely need to get authorities involved before doing anything. The problem is, if you alert everyone, you can be sure the funds are just going to get swept by someone, so you need to do something else.
I bought a MK4 because it was supposed to be open source? I did dice rolls on it so I'm fine thankfully. I'm planning on doing a new seed that I generate manualy away from any machine. Am I right in understanding that I can do 23 words then I have a 1 in 8 chance of the 24th being compatible? And the way to test it is recover it till you get a good 24th word? Cheers to any insight. This is the time we help eachother out and learn.
I'm going to keep using the MK4 because I rolled 110 dices and also have a strong passphrase and I'm used to the device and guides. That being said, my firmware is from 2024 5.2.2 I do not require and update but maybe some day I update the firmware.
The only thing I would like to have in my MK4 is a big QWERTY keyboard to type the passphrase. LOL
Of course. All the possible addresses an MK3 could have made are known. It's a small list, maybe 10M addresses. The chances of someone else ever creating one of those addresses in extremely, extremely small
What do you mean it’s known? You can distinguish if an address was made by MK3?
Because the whole MK3 pool is known and it would be very suspicious that each and every owner of an MK3 decided to move their funds in a small window of time.
I wonder if two MK3s generated the same secret over the past 5 years. This could have had a less horrendous end if this happened and the person made it public knowledge that they generated a secret and it already was being used. People would have dove into the code then and could have saved a lot of people over the years.
Yeah and not just MK3. I don't know why the put MK3 in the title, instead of also putting MK4 and Q. It is a common bug in them. I agree that people did not understand that happened because they think everyone with CC is impacted and people who followed the paranoid guide are not impacted by this issue because they never used CC RNG.
I don't have KP3 I only used CC MK4. But I recently learned that the method to convert 100+ numbers into a seed phrase is share among different wallets and tools. And I think one of them is the one you mention. Coldcard has this in some python script rolls.py in their paranoid guide.
A post in 2022 - "Coincard MK4 UX Flaw" described this exact scenario. Posted by Economy_Cash6726
Just the fact the MK5 exits makes MK4 a leftover product.
wrong. it's those who created the seed using their flawed RSG fro m the MK3 onwards. entropy was severely narrowed making determine seeds easier to find. doesn't matter if it was online or not.
Well buy a used MK3 and then transfer your bitcoin to it.
it not hard to generate your keys using well known community projects and then use this wallet + a passphrase just to make sure on your MK3. The problem was that people blindly belive in the MK3 seed generation and then all this happened.
If you have a CC... Just be completely sure that you used the manual dice roll method. If you are paranoid and you still do not trust that the CC will correctly convert 100+ numbers into the right seed (and not a pre-made seed or something like that). Well in that case you can run the same numbers with that [rolls.py](http://rolls.py) which is supposed to be a simple script and used by the CC wallet. Of course, by doing this, you will expose your seed to a new device (the device running the live linux OS). But this should be extremely low risk if it is done by an experience person, with no internet, no bt, fully formatting the live linux usb, etc. At least you will sleep knowing MK4 converted 100 manual rolls to a seed using a std approach. I THINK if you put the same 100+ numbers into other methods (**SeedSigner**, **Sparrow Wallet's dice input**, and **Ian Coleman's BIP39 tool in Coldcard mode)** you will get the exact same seed phrase. I quickly asked the AI and they all seem to be using the same code to convert random numbers into a seed phrase.
This is the script i used to check on a linux live usb to check MK4 was giving me the same seed phrase of the 100+ manual dice rolls [https://coldcard.com/docs/rolls.py](https://coldcard.com/docs/rolls.py) Yes. Many are still using it. The tremendous bug found, so far, seems to be only impacting the seeds that were generated with a Random Number Generator from coldcard wallet. The paranoid guide from cold card suggest the user to manually roll the dices in case they do not trust the Random Number generator from the hardware wallet (and doing this was the right choice because, look, that RNG functionality was bugged).
Yes but the entropy wasn't generated by MK4. It was generated by me rolling the dice. MK4 only converted the 100+ numbers into a seed phrase. But I also used a python script to do the same to ensure the MK4 was converting to the same seed phrase as the script.
**One important thing to add:** the Proof of Concept is already public and anyone can study or use it: [https://github.com/domaup/coldcard-poc](https://github.com/domaup/coldcard-poc) I agree with most of your points, especially the distinction between **how the seed was generated** and the wallet itself. That’s the part many people are missing. However, I think it’s also important not to underestimate the impact of the public PoC. Before it was released, exploiting the issue required reverse engineering and significant research. Now the barrier to entry is much lower because the implementation is available for everyone to inspect, improve, and automate. That doesn’t mean every Coldcard user is suddenly at risk, but it does mean affected users should act sooner rather than later. As you explained, the key factor is the seed generation method: **Dice-only generated seeds:** no evidence that this vulnerability affects them. **Internal RNG-generated seeds (especially affected MK3 devices):** users should migrate their funds as soon as it is safe to do so. **If you’re unsure how your seed was generated:** it’s safer to assume you may be affected and move your funds carefully. I also agree that panic is dangerous. Rushing to move coins without verifying backup phrases, destination addresses, or recovery procedures can easily result in permanent loss. A careful migration is always better than a rushed one. The important message should be: **don’t panic, but don’t ignore it either.** The vulnerability is real, the PoC is public, and everyone should verify whether they are actually affected based on how their seed was created—not based solely on the Coldcard model they own.
Not even. The MK3 RNG was effectively a seed phrase that’s 1.25 words long.
If the guy in the screenshot tells the truth then it's definitely bad handling of the issue on CoinKite's part, and is even a bit suspicious. But it's a MK4 which to my understanding still has low entropy but not quite low enough for a reasonable bruteforce attack and to my knowledge wasn't yet affected in the current attack. If we assume all the reported cases of funds drained from CC wallets and CK not responding/blocking are them utilizing a backdoor, that means that likely they have another backdoor on the mk4 and also that their strategy was to only drain wallets sporadically and pray no one realizes, until they suddenly switched to a big drain strategy but now only on mk3. Or maybe someone else did find the mk3 backdoor now? So it was an "inside job" in the past but now it's an "outside job"? It could be, but I feel like all these theories assume a lot more dedication to plausible deniability than most criminals give, when simply covering their tracks is often simpler and more effective (why not place the backdoor in the proprietary "secure element"?). I saw too many cases of things like these happening out of negligence to not assume it's the case here too. If there will be more direct evidence of maliciousness it can change my mind but for now I still tend to assume negligence.
I actually did this. live Linux USB with no internet, I didn't used this to generate the wallet. But I used it to verify that that the scripts that converts the 100+ dice rolls into a seed phrase was giving me the same results as the coldcard MK4. After verifying that the MK4 was not doing something different than the small python script, I proceeded with that seed and slowly formatted the live Linux USB.
I would like to say "I like to roll the dice" but its too soon, even for myself. The honest answer is a combination of I though my seed was unbreakable and having 2 hardware wallets with the same seed, steel plates in different countries would be safe enough. But then again i was reading about someone else who lost more than 10BTC and had it in 3 different MK3 wallets. So the question becomes why colcards? because ledger and trezor both had their breaches and oopsie days and i guess at the time, coldcards seemed the safest option.
The probability space was like 2\^40 for Coldcard MK3? Brother, 2\^40......
I'm probably alone (and on CC but nothing lost, thanks to His Noodly Appendages) and i'm looking for them to lower their prices for an MK5...
I'm.coldcard MK4 and used dice rolls. I'm ok right?
You're sure that your MK4 is drained? Cause I have an mk4 that is also probably 800 km from me and I would rather you be wrong.
hey all are unfortunately. My uderstanding is that until the July 30 firmware update MK3 hacking used less compute than 4,5,Q so it was done first, but the rest are still vulnerable. It's probably safe to use any of them now so long as you update the firmware, but most people, probably wisely under the "fool me once" theory are going to do something else to secure their self-custody btc.
They all are unfortunately. My uderstanding is that until the July 30 firmware update MK3 hacking used less compute than 4,5,Q so it was done first, but the rest are still vulnerable. It's probably safe to use any of them now so long as you update the firmware, but most people, probably wisely under the "fool me once" theory are going to do something else to secure their self-custody btc.
They all are unfortunately. My uderstanding is that until the July 30 firmware update MK3 hacking used less compute than 4,5,Q so it was done first, but the rest are still vulnerable. It's probably safe to use any of them now so long as you update the firmware, but most people, probably wisely under the "fool me once" theory are going to do something else to secure their self-custody btc.
MCU does the signing. SE does the storing. SE is there specifically to store encrypted pins and seeds and keys. Yes you can wipe it each time and restore from backup when need to spend. But SE is there to securely store the secrets and resist physical attacks. No, can't expect 30 years out of a security device. MK3 was discontinued 3 years ago and people did not migrate. It would not help at all if they wiped their mk3's and emptied the secure element. Which are designed to, and do, store secret data.
None of this was mainstream back when i bought my MK3. Wasn't even mentioned in the setup documentation.
Also entering a strong passphrase on my MK3 would have been a royal pita
Post titled Cashcard MK4 UC flaw in 2022.
The post was titled Coldcard MK4 UX flaw in 2022.
It’s not FUD if you generated a seed on a Coldcard MK3 and on. It is if you didn’t, which is the vast majority of folks who may also be panicking because they don’t understand what’s going on.
Well they managed to update the code for MK4 and MK5... suggests someone 8noticed when updating the code from MK3
Yep had an MK4 and been in btc since 2017, never tempted to sell until this. I'm completely out of all cryptos now.
The seed keys are 128 or 256 bit and Coldcard decided to have 40 bit entropy on MK3 and something like 78 bit entropy on MK4 and MK5 and somebody is asking is Satoshi was idiot, no he wasn't, he generated his private keys with proper entropy almost 20 years ago. You can do fucking coinflip.
I don't know, but I think this isn't as simple as many claim, asserting that the MK3 generated 40 bits instead of 70. It's a very small space with a trillion possibilities, and I'll put it to the test. It's not certain; it's all speculation. Nobody has run tests to confirm it 100%. This smells to me like silicon from the STM32L475 chip, a vector in C that was set to 0, and many people believe that was the problem. To me, this is all physical; we would have to test the device. Hardware bus clues: Captures with a logic analyzer or oscilloscope of the RNGCLK, HCLK pins and the internal bus registers during data output. Among other tests, I wouldn't trust what they say on X; it's not entirely accurate. We would have to look for the offset in the firmware assembler. I already did, but this is really strange. And now that some affected wallets are public, I'll do my job. That 40-bit thing isn't entirely true it's a possibility, but not a certainty. I have the complete analysis of both firmware, but this is really strange.................
I had a brand new sealed MK3 Coldcard in my draw. I purchased it in 2022 directly from Coinkite. With all the news about them lately I decided to open it up and take a look. Was disappointed to find that the red "Caution" LED was on, and that the device booted into what I can only guess is the factory pre-shipment menu. The factory menu has functions for: Bag me now, DFU Upgrade, Show version, Ship W/O bag, Debug functions ... AI told me that the "Bag Me Now" menu item was intended for the final factory step performed before the device is paired with its tamper-evident bag. I literally had to run the "Ship W/O bag" in order to get any further with the device. Needless to say I won't be using it.
No - BTCSessions shared that an MK3 with a passphrase was leaked shortly ago.
Who knows what else is compromised on MK3 or 4
According to BTCSessions on Twitter, a MK3 with a passphrase has been drained. It was a two word passphrase, but it's an indicator that the attackers are moving on from low hanging fruit now (vulnerable seeds without passphrase).
How does that help the people who followed the official guide setting up their MK3s, which said nothing about dice rolls? If dice rolls were so important, it should have been a mandatory step.
Sorry, I meant my original seed has moved from hardware wallet to hardware wallet, never entered on hot wallet. Allot of people who had the MK3 generated a seed and moved that seed years later to other wallets.
Sorry, I meant my original seed has moved from hardware wallet to hardware wallet, never entered on hot wallet. Allot of people who had the MK3 generated a seed and moved that seed years later to other wallets.
With AI only going to get better, I am thinking about creating a Fidelity Crypto account. I have three cold storage wallets: Trezor, Ledger, and Coldcard Q. I was very lucky that after hearing about the Coldcard MK3 issue, I immediately transferred all my BTC to my Trezor and Ledger, along with a few exchanges to spread out my holdings. I have been playing around with BTC and crypto since 2020, and I feel like with the advancements of AI, self-custody is just getting a little dangerous, and places like Blackrock, Fidelity, and Morgan Stanley who are just getting into the space, who also have full time cybersecurity teams might be the only way to go for people like myself who do not have time to be up to date with all the security threats.
Bitcoin is not set it and forget it.. got to keep up with it. If you buy a new phone every few years it's not that crazy to buy a new piece of technology that protects your bitcoin every few years as well. No one is recommending Trezor T without secure element anymore. No one is recommending MK3 anymore, which was essentialy discountinued 3 years ago. Passphrases are a much easier lazy path vs rolling dice. You just.. add a passphrase, no 50 or 100 pieces of info to transform. Certianly the dice rolling should be recommended now, but passphrases are fast, cheap, and easy, and much more bearable to implement. No, the passphrase cannot be hunter2, it has to be stronger than that. Single-sig with passphrase is still the lowest friction setup that is accessible to vast numbers of people.
Bitcoin is not set it and forget it.. got to keep up with it. If you buy a new phone every few years it's not that crazy to buy a new piece of technology that protects your bitcoin every few years as well. No one is recommending Trezor T without secure element anymore. No one is recommending MK3 anymore, which was essentialy discountinued 3 years ago. Passphrases are a much easier lazy path vs rolling dice. You just.. add a passphrase, no 50 or 100 pieces of info to transform. Certianly the dice rolling should be recommended now, but passphrases are fast, cheap, and easy, and much more bearable to implement. No, the passphrase cannot be hunter2, it has to be stronger than that. Single-sig with passphrase is still the lowest friction setup that is accessible to vast numbers of people.
The known exploit right now effects only Coldcard MK3, and to a lesser extent MK4, MK5 and Q. But as this exploit shows, any wallet in the future could have a problem, so in the long term if you have significant funds , I'd look into other methods. Relying on a single wallet , is a single point of failure, which multi-sig addresses. You can even lose an entire wallet and/or it's seed backup and still recover your funds by using the 3rd key. At [Unchained.com](http://Unchained.com) you can even rollover Roth funds into real bitcoin you own in a Roth. Note that with multi-sig there are other things to worry about. You have two wallets, and two seed phrases ( stamped into two metal plates ) to store in 4 different locations, and the wallets should be different manufactures. Multi-sig has wallet config files that must be preserved safely forever as well. So most people will not figure this out safely alone without help, which is why [unchained.com](http://unchained.com), [thebitcoinadvisor.com](http://thebitcoinadvisor.com),casa,io and [numchuck.io](http://numchuck.io) among others exist.
You really should have rolled the dice properly. Professional casino dice and use a cup and shake it well, don’t just roll it in your hands. MK4 is less at risk because there is some entropy from an extra chip the MK3 doesn’t have, but it’s still not adequate apparently. It could be brute forced if you don’t add at least 50 independent random dice rolls I’d say with less than 50 independent dice rolls that wallet is lacking the necessary entropy. Is it going to be hacked imminently? Sounds like it won’t be. The numbers you inputted help, but if you don’t remember how many “rolls” you did and they weren’t done with properly rolled casino grade dice then you should calmly create a new wallet and stop using your current one. Yeah don’t do it at an airport with security cameras everywhere. You can go home first. I take no liability if I’m wrong here, but my guess is doing this at an airport is riskier than waiting a day or two until you get home. Or just send it to an exchange temporarily? I get that might be unpopular here.
Oh! Man, 😂 sorry not laughing at you is just the timing, I have a MK4 and moved everything to a different storage but I am researching for a new HW. The Trezor 5 / 7 Jade and passport are the ones Im looking at right now. Sorry you paid for the Q just few days before the shit hitting the fan.
You are 100% safe. Dont do anything rushed. Do you know what MK version was your coldcars?
Because an AI was able to discover the problem in 8 minutes, that should be a huge red flag and something that the CC software engineers should have double triple quadruple checked. The entire security of the wallet hinges on that RNG call functioning correctly and they fucked up big time and it's now cost people tens of millions of dollars. Even if their code was written before AI was as advanced as it is now, that's basically the entire point of the security of the wallet and they messed it up. Also that comment as you understand it isn't entirely correct but gets the main idea right. Basically, there should have been x number of possible combinations that would lead to the seed phrases being damn near impossible to crack with current technology. There's this idea called the birthday paradox where when you have a room of just 23 people there is approximately a 50% chance that 2 of those people share the same birthday. When CC improperly implemented entropy in their wallets, they called ONLY the software RNG and not the hardware RNG on the secure chip in the actual hardware wallet. In doing so, they minimized the pool of possible combinations for seed phrases from an astronomical number of combinations (approximately 340 undecillion combinations) to a much more manageable pool of combinations (roughly 1.1 trillion). After that all the attacker had to do was replicate the possible combinations of the 40 bits of entropy and then begin generating wallets. This is where the birthday paradox comes into play, once he could generate a wallet that had a crossover with an already existing wallet with the same seed phrase, he queried a large cryptocurrency exchange to determine if those wallets he matched up with had any UTXOs (evidence of transactions to and from the wallet) to decide if they were a good target to sweep the btc from. He likely did this all in the background for some time before actually implementing the attack so they could steal as much as possible before the attack became a known issue. Basically CC majorly fucked up and left their wallets unsecure for years and someone finally discovered this issues and then weaponized it to steal tens of millions in BTC. This post just shows that CC should have been auditing their own internal code because an AI agent discovered the issue in a matter of minutes. This issue is also still present on the newer generations of cold cards as well albeit not nearly as severe. Even on the MK 4 and MK 5 wallets, they are only implementing 72 bits of entropy (4.7 sextillion possible combinations) which makes them significantly more secure but still much more vulnerable than a wallet with the correct 128 or 256 bits of entropy. This is entirely on CC and the fact that this went unnoticed for so long or even if they did notice it and continued to just push a fundamentally broken product out to their customers, it's just unacceptable. They had a responsibility to their customers to create a product as they promised which was secure, and safe, and they did the opposite and now here we are. This post is just shining a light on how incredibly terrible their fuck up was.
\> Why did this issue not exist in MK4 and MK5? Most likely because CC learned of it and fixed it. No, the issue does exist in MK4 and MK5 as well, just not as severe.
The bug is using IFNDEF vs IF. This is the type of bug that human code reviews could easily fail to catch. In 2021 when this bug occurred there were no LLMs to test your code with. The output of the function was apparently random seeds, so their unit tests didn't pick up failure from the function. Now, let's imagine that by 2026 CC had used an LLM on their source code and it had revealed this vulnerability. What do they do about it? Vulnerable seeds exist in the wild. They can't announce the bug because they'd just be announcing to bad actors to go and break into these wallets. They could issue a firmware fix, but how do they tell people to apply it and regenerate new seeds? Why did this issue not exist in MK4 and MK5? Most likely because CC learned of it and fixed it. But, they were well and truly stuck when it came to addressing it in MK3 because it was out there and their best hope was it never being found. But then LLMs came along that aren't fooled by IFNDEF vs IF
Just a side note… I have decided to stay with my MK4 but to generate a seed with dice roll (NOT THE COLD CARD DICE ROLL)… THAT IS COMPRISED AND YOU SHOULDN’T USE ANYTHING GENERATED BY COLD CARD… I WOULD ARGUE THE SAME FOR OTHER HARDWARE WALLETS. Also add a Passphrase… something that is long enough and complicated. Write everything down on a piece of paper… never digitally. Make sure everything is correct before sending BTC. Everybody, be careful out there and if you are ever in doubt… reach out to butcoiners. Bitcoiners help each other. Good luck, Cheers.
Question, since I can't use dice method in Trezor, is it reasonable to update MK4, create a seed with dice then move to Trezor? Got my coins out of MK4 on a temp wallet, and I just got my new Trezor, and learning from what happened I am planning to create a new wallet with seeds generated using dice, however it seems Trezor doesn't have that option, and I don't have a device I can have offline to run any program to help, so I am thinking of updating the new firmware of MK4, create a new wallet with Dice, import the seeds into Trezor and add a passphrase, does this make sense? is there any possible issues?
Even MK4 and MK5 has weak keys, see the response in the other thread.
\> A key thing here is you had to understand why the keys were weak I think, it's not as if the software said 'here is your weak key'. \> But to me hacking is utilising a technical exploit on a computer to make an unauthorised use It is completely irrelevant why are the keys weak. Just that they are. I would add that this does not affect MK3, but also MK4 and MK5, those keys are weak as well, just not that weak. Users were accepting weak keys and they still accept them today. Not that weak, but weak nonetheless. The keys are 128 or 256 bit (depending on the number of words), but the entropy for MK3 was just roughly 40 bit and MK4 and MK5 seems to be 72 bit. Somebody determined will break MK4 and MK5 keys as well. Maybe not today. But if you remove enough entropy, security breaks. Sometimes even 1-2 bits of entropy removed can have catastrophic effects. Here, We have removed 88 bits. Who has the key controls the coins. There is no unauthorized used at all.
This is really besides the point. This is only valid if the attacker already has your seed (private key). If they don't then the posted chart is misleading. I explain in another post: Basically the attacker went through trillions of combinations to find vulnerable wallets. If they looked at an address, but they couldn't hack it, they have two choices. Spend another thousands of attempts on EVERY of the trillions of attempts for a very weak passphrase, or spend a bit more than thousands for a non weak passphrase, WITHOUT knowing if the address comes from vulnerable wallet. MK3 had entropy of 2\^40. Around 15M addresses on the blockchain have money (assumption). 1.1t iterations (or half for 50% chance) have to be done on eachaddress to find out if it's vuln. Multiply this with 4096 for a dictionaly passphrase (the weakest i guess, as coldcard offers it - upper/lowerase versions of the seed words). So... the Q is... if the attacker goes through lowest hanging frutis and highest payment (>0.15BTC) per address, and then they go through the lower amounts (<0.15BTC) and then they might go to assume that every address they could not hack, is vuln but with passphrase, and scan 15M addresses again with 1.1T \* 4K (minimum uppercase/lowercase single seed word assuming nobody puts a passphrase of 'a') = 4,400 trillions of attempts for 15millions addresses... doable, but ... has nothing to do with the posted image
Imagine you asked the same "what issues might there be with MK3?" a month ago? Nobody would point out to current issue too. This is what is meant by "unknown unknowns"
Are there fully airgapped alternatives to ColdCard with the same PSBT workflow to sign transactions ? 99% of recommendations are for Trezor and Ledger right now ... I have nothing against them but the idea of using an app and connect my wallet to a computer or phone really bugs me. I was one of the lucky ones , so far at least, with a seed generated on MK3 3.1.9 ... I want to move to something else but I would really like to keep the fully airgapped approach What I found so far * Seedsigner - probably the best but sourcing all components is not necessarily that easy * Block stream jade plus - people reporting bad quality builds but is not like CC was much better * Foundation passport - expensive !!! Anything else I should include in my research ? Thanks
The first two versions of the firmware didn't have the RNG disabled, so this might actually be a new sealed working MK3, which could make it be worth even more as a collectable.
what other issues might there be with MK3? The only other problem I see that is if for some reason it leaks the private key when signing a PST, and if it does, it leaks to whom? Because if I can use a MK3 to sign a PST generated in Electrum Bitcoin Wallet, how will the MK3 leak my private key to Electrum if it does not expect it?
I never trusted hardware wallets to buy one lol, I dont like them, just stating that the problem with the MK3 was the psudo random bullshit they used, but as a signer, it still usable.
Was it the MK3 or a different Coldcard?
i dobut there will be any other insane flaw with it, a signer is simple a signer, it does sign your PST so you can broadcast it, the only secure issue would be if the MK3 had access to the internet and leak your private key during that process, which it does not.
what? Have you read what was the actual problem with the MK3?
What are they going to do? Give everyone a free MK5? They don’t have $70M cash just lying around. They’re finished
the MK3 is still safe to sign transactions, just not to generate seeds
Did you have the MK3 or a different Coldcard? Sorry about this man, somebody should start a go fund me
Don't receive it. I received back in 2021 the MK3 with a broken screen and they were assholes and terrible customer service, so don't expect them to refund you willingly, This scam company is F, it's matter of time and I hope the CEO ends in prison and rot in hell
I'm sorry for your loss. I received my Coldcard MK3 in January 2021. I literally skirted this catastrophe by 2 months! For all those who fell victim, I am deeply sorry. You did everything you were supposed to but got screwed over. Coinkite should be ashamed and provide relief to those who lost money to their shoddy coding.
Am I a sadist for believing that Bitcoin is for people capable of a fairly simple set of steps? I use Cold Card, and I'm of the opinion that a person's keys are their responsibility no matter what happens. There is no circumstance in which a loss of coin is not the responsibility of the person who no longer owns the coin. Even if I trusted third-parties who presented themselves as trustworthy, it is still my fault if they do something to expose my seed, because I trusted them. In the case of CC MK3 or any subsequent Coinkite hardware the trivial step of using dice roll to introduce external entropy, which is advised strongly by Coinkite, would have preserved the Bitcoin in possession, and the equally trivial step of using a secure 12-16 digit passphrase would have guaranteed security. Is this controversial? I feel like our sense of solidarity and humanity is glossing over this really basic fact. I am a fucking idiot, and I knew how to secure my Bitcoin. I didn't have an MK3, but if I did I would not have lost my coin. Are we getting soft because we want to bring more people into Bitcoin, and we need to play with kid gloves now? Bitcoin is war. Good men die in war, sometimes the best of men. Its hard, its brutal, but its what we want.
So everything before March 2021 is safe? MK1, MK2 and MK3 before March 2021 firmware update was using Trezor code base and can be considered safe?
It appears so. Coinkite has acknowledged the hack goes beyond the MK3.
Honestly you probably would’ve been fine. The exploit (so far) only affects wallets generated on certain models of the MK3.
If it makes you feel any better OP (though I’m pretty sure it won’t), if your friend had enough coins stored on his MK3 to end your friendship because of his loss, then he should have at least used a passphrase if not dice rolls and/or multisig. If it was that large an amount he could have also spread it across a couple of different hardware wallets (different vendors) to distribute his risk. Yes, I fully understand hindsight is 20/20. I don’t mean to come across as a Monday morning QB. But he probably shouldn’t have had all of his eggs in one basket (and that basket being a Wallet without a passphrase.)
2/3 keys in my multi-sig with Unchained are MK4s. I have learned a lot about MARA Slipstream in the last 24hrs.
Unchained holder here. When setting up my 2 MK4s (FML) their documentation advised AGAINST dice rolls (once again, FML) They are providing support by allowing impacted holders like me to use their tool which will use MARA Slipstream, helping to avoid getting front-run on my TX to move my coins to a new vault. I’m currently traveling and won’t have access to my wallets for 7 more days. Currently my vault has never spent, but as soon as I move the coin I will be vulnerable to a front-run. I plan to use slipstream and am considering getting out of the BTC game all-together. Aside from the CC-clusterfuck Unchained has been pretty good to deal with.
Cannot replicate. I have MK4 Revision D.