Casa publishes initial Coldcard vulnerability analysis and multisig guidance
casahodl-initial-vulnerability-analysis
- Author
- @CasaHODL
- Organisation
- Casa
- Evidence role
- social statement
- Posted
- 31 Jul 2026, 01:41 UTC
- Capture status
- capture held
Casa states that Coldcard disclosed a vulnerability affecting devices running firmware 4.0.1 (March 2021) or later, that the investigation is ongoing, and that multisig vaults with enough Coldcards remain safe because one compromised key cannot move funds. Held as a dated organizational incident-response statement with a specific firmware-version claim. The claims are the publisher's own and inclusion is not a recommendation.
This post is registered as evidence and has a locally held capture. The original remains the canonical publication. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.