Coldcard Security Risk: Immediate Action Required
A major security vulnerability has been discovered in Coldcard hardware wallets, allowing attackers to find users' seed phrases without their action. Users who generated their word seed using the dice roll method are safe, but those who used the recommended 50+ dice rolls…
Intelligence analysis by Llama

A critical security issue has been found in Coldcard hardware wallets, affecting users who generated their word seed without sufficient randomness. Users are advised to move their funds immediately to a new word seed or a different device. A firmware patch has been released to secure word seeds generated after the update.
Imagine you have a special box that keeps your money safe. But someone found a way to open the box without you knowing. You need to move your money to a new, safer box right away. This is like a security issue with a special kind of box called a Coldcard. If you used this box to keep your money safe, you need to move it to a new box to keep it safe.
Analysis
A Critical Security Issue in Coldcard Hardware Wallets
A major security vulnerability has been discovered in Coldcard hardware wallets, allowing attackers to find users' seed phrases without their action. This issue affects users who generated their word seed without sufficient randomness, making them vulnerable to attacks. The vulnerability is being actively exploited, with around 1000 BTC seen moving on-chain connected to the issue.
What You Need to Do
If you used a Coldcard to generate a word seed and did NOT use the recommended 50+ dice rolls to provide your own entropy after the end of 2020, your word seed is not secure. You must move your funds to a new word seed, or a word seed generated by a different device, in order to secure your funds. This is a critical issue that requires immediate action.
How to Secure Your Funds
If you have another hardware wallet that is not a Coldcard, send your funds there. This is the quickest and simplest way to get them someplace secure. If you do not have another hardware wallet, and only have a Coldcard, generate a passphrase using at MINIMUM six seed words from the BIP 39 word list. Use this guide to select your words for the passphrase, do NOT pick them yourself. Check your wallet fingerprint (or an address), power down your device, restart it and re-enter the passphrase. Confirm that the fingerprint (or address) matches, and send your funds to the passphrase wallet. This is not a permanent solution. This is simply giving you enough security that an attacker will not be able to brute force your keys in a matter of days, and you can generate a new seed without being in a state of panic.
What You Can Do to Help Others
Once you have secured your own funds, take a minute and relax. Coldcards are still safe to use as long as the word seed is generated securely. A firmware patch has been released here. Any word seed generated after this firmware update should be secure (and you can use the dice roll option too). If you have transferred your funds to a hot wallet, or something less secure, your Coldcard is safe to use after applying the firmware update and generating a new seed. Once you have secured your own funds, stop and take stock. Reach out proactively to anyone you know who might be using a Coldcard that was vulnerable when they generated their seed. Inform them of the issue, and if needed (and you are capable) help walk them through migrating their funds.
Key points
- A critical security issue has been discovered in Coldcard hardware wallets.
- Users who generated their word seed without sufficient randomness are at risk of attacks.
- Immediate action is required to secure funds and prevent potential losses.
- A firmware patch has been released to secure word seeds generated after the update.
- Alternative software wallets such as Nunchuck, Blockstream Green, and Bluewallet are available to secure funds.
The release of a firmware patch to secure word seeds generated after the update is a positive step towards mitigating the issue. Additionally, the availability of alternative software wallets such as Nunchuck, Blockstream Green, and Bluewallet provides users with options to secure their funds.
The fact that the vulnerability is being actively exploited, with around 1000 BTC seen moving on-chain connected to the issue, highlights the severity of the situation. Users who failed to generate their word seed with sufficient randomness are at risk of losing their funds.



