COLDCARD vulnerability what happened, and what to do
Informational only, and this site never asks for your recovery words. details

Informational only. This is independent analysis and an evidence-backed explainer, not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite, Block, or any other party named here. Published estimates are attributed, and differing scenarios are kept separate with their assumptions. Act on your own judgement. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it. Deliberate recovery on independently verified offline equipment is a separate operation. Seed-word safety.

Galaxy Research Firmware Block Boundary

glxyresearch-firmware-block-boundary

https://x.com/glxyresearch/status/2083623541921001756

Author
@glxyresearch
Organisation
independent
Evidence role
on-chain-analysis
Posted
1 Aug 2026, 18:38 UTC
Capture status
capture held
Artefacts held
2

Galaxy Research states that the vulnerable COLDCARD firmware shipped on 17 March 2021 around block 674,951, and that no coin identified in waves 1 to 3 was created before that block. This bears independently on the affected-range lower bound: 17 March 2021 is the v4.0.0 release date recorded here, not the 29 March 2021 v4.0.1 date that the vendor advisory uses as its stated boundary.

This post is registered as evidence and has locally held capture artefacts. The original remains the canonical publication; hashes below identify the files held by this project.

How to check this yourself

The SHA-256 prefixes above identify each held copy without turning this page into a mirror of somebody else's post. Compare a quotation against the original. If the post has since been edited or deleted, ask and the held copy can be produced.