Checkonchain PSA on the Coldcard exploit
checkonchain-coldcard-psa
https://newsletter.checkonchain.com/p/psa-addressing-the-coldcard-exploit
- Organisation
- Checkonchain
- Evidence role
- Independent primary analysis
- Published
- not established
- Source changes
- 0
- Detected differences
- 16
- Unreviewed
- 0
- Copies held
- 17
James Check's subscriber PSA with step-by-step owner guidance. Held as independent incident-response guidance from an analyst, not a custody provider; registered in this section because it circulated as the kind of client notice providers were sending.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
SubscribeSign in ⚠️ PSA: Addressing The Coldcard Exploit If you use a Coldcard in your Bitcoin security system, please read this post. James Check (Checkmatey) Aug 01, 2026 74 22 13 Share G’day Folks, The last two days have been uniquely challenging for many of us grizzled and tenured Bitcoiners. News that an exploit has been found in the Coldcard, which many (including myself) consider to be the ‘gold standard’ hardware wallet, has resulted in some cold storage wallets being drained. This strikes at the very heart of what makes Bitcoin so special: our ability to safely self-custody and secure our wealth without trusted third parties. I’m going to get right into it, keep things short and concise, and will cover the following topics: Overview of the exploit and risk profile. Summary of possible near-term and long-term solutions to consider. Disclaimer: This article is general in nature and is for informational and entertainment purposes only, and it shall not be relied upon for any investment or financial decisions. Additionally, since this article also deals with the technical details of self-custody, all opinions expressed must be viewed as the author’s opinions only (not advice of any kind). Please take all precautions necessary to thoroughly understand the nuances of any hardware or software wallet systems you consider using. TL;DR Please read this post in full if you are a Coldcard user. Coldcard Exploit Overview At the highest level, this exploit relates to the degree of entropy (randomness) that was used when generating seed words on a Coldcard device after the March 2021 firmware. It has been found that the random number generator was not random enough. This means an attacker can now brute-force ‘recreate’ a list of all potential seed phrases that Coldcards with this firmware would have generated. ⚠️ ACTION: Anyone who generated their seed phrase using a Coldcard from March 2021 onwards should assume that their seed phrase is compromised and cooly and calmly prepare to migrate to a new wallet. This exploit thus far appears limited to Coldcard products, and does not impact other hardware wallet vendors like Ledger, Trezor, Bitkey, etc. This exploit specifically affects Coldcard products. Categorising The Risk Profile The most important thing to think through first and foremost is that this exploit specifically affects the seed phrase at the time of generation. This exploit only affects seeds generated using a Coldcard that was running post March-2021 firmware. If a seed was generated on a vulnerable Coldcard but was then ported into another device (Ledger, Trezor etc), that seed remains vulnerable, and coins must be migrated off it. If I were to categorise the risk profile for Coldcard customers, it would be in three tiers. 🔴 High Risk: Critical to migrate your coins as soon as possible if ALL of the following are true. Generated seed on a Coldcard device after March 2021 (or you’re unsure of the date). Did not utilise the dice-roll feature with at least 50 rolls during seed generation (if you cannot remember doing this, assume you did not). Do not utilise an additional BIP-39 passphrase ontop to secure your coins. ⚠️ ACTION: If you fall into this category, your seed words should be considered vulnerable and at risk. You must migrate your coins to a new and safe wallet ASAP. Please skip ahead to the Potential Solutions section for some ideas on near-term and long-term options. 🟠 Medium Risk: Your coins are secure for now, but you should still plan to migrate them as soon as possible. Assuming you generated a seed on a Coldcard device after March 2021 but also: Added dice roll entropy at seed generation.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
16 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
- +4 -4 Only Substack engagement counters and comment counts changed; the post text was unchanged.
- +2 -2 Only relative date labels rolled from '8d' to 'Aug 1'; the PSA text was unchanged.
- +2 -2 Only relative-time labels rolled from 7d to 8d on two comments; the PSA text was unchanged.
- +1 -1 Only a relative-age label changed from 6d to 7d; the PSA text was unchanged.
- +1 -1 Relative-date rollover only: the age label on Ricardo Santiago's reply changed from 6d to 7d. No comment text changed.
- +2 -2 Relative comment ages ticked from 5d to 6d on two comments. No new comments, replies or edits.
- +2 -2 Only two relative-time labels advanced from 4d to 5d. No PSA content changed.
- +1 -1 Only the relative-time label advanced from 4d to 3d.
- +3 -3 Only the visible reaction count rose from 83 to 84 and a relative-time label advanced by a day. The PSA and replies are otherwise unchanged.
- +4 -4 Only the Substack engagement counters moved, likes from 81 to 83 and restacks from 13 to 14, in both renderings of each counter. The PSA text was unchanged.
- +2 -2 Only the Substack like counter moved, from 80 to 81 in both renderings of the counter. The PSA text was unchanged.
- +4 -4 Only engagement counters and relative-time labels moved: the post's reaction count rose from 78 to 80 and two comment timestamps rolled from 2d to 3d. No post or comment text changed.
- +4 -4 Only Substack live counters and comment age rounding moved: the like total under the post went from 79 to 78 in both renderings of the counter, and two comments flipped from 3d back to 2d. The PSA text was unchanged.
- +4 -4 Only Substack live counters and comment ages moved: the like total under the post rose from 78 to 79 in both renderings of the counter, and two comments aged from 2d to 3d. The PSA text was unchanged.
- +6 -6 Only live counters changed: like and restack totals rose (76 to 78, 22 to 24), one comment's reply count grew from 1 to 3, and the collapsed comment count went from 20 to 22. The PSA text was unchanged.
- +2 -2 Only the Substack engagement counters changed: the like total under the post rose from 74 to 76 in both renderings of the counter. The PSA text was unchanged.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.