- Organisation
- Orange Surf
- Evidence role
- Independent primary analysis
- Published
- 2026-08-09
- Source changes
- 0
- Detected differences
- 0
- Unreviewed
- 0
- Copies held
- 1
Orange Surf publishes a technical analysis of the COLDCARD key exposure, documenting the author's understanding of the vulnerability and its implications. Held as a dated independent technical account. The analysis is the author's own and is not verified here.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
Home Analysis Websites Guides Designs Reviews About Workshop This report was produced for mempool research by @orangesurfbtc on 2026-08-04 Coldcard Key Exposure There is an ongoing exploit of an error in the firmware of Coldcard devices that resulted in highly insecure wallets being generated by default. If you have used a Coldcard, you must carefully evaluate whether your bitcoin is at risk and act accordingly. If you are at risk, or are unsure, you should migrate your funds immediately following the guidance below. Which wallets are insecure / have exposed keys? Wallets derived from a seed generated on a Coldcard running firmware version 4.0.1 or later (excluding the emergency patch released on 2026/07/30) which were setup using the default initialisation steps are insecure wallets. An exposed key is defined as one which is associated with these insecure wallets. Whether the device was updated following the insecure wallet generation is irrelevant. Updating does not repair an existing seed. Furthermore, users are reporting that their devices have been bricked by applying the latest 2026/07/30 firmware updates. If at all possible do not update the firmware on the device and simply sweep the funds and put the device into storage. Protection via a passphrase A secure BIP39 passphrase is unique and generated using genuine randomness rather than chosen by a person. For example, 12 independently and randomly selected words would be extremely difficult to guess. Common phrases, quotations, personal information, reused passwords, predictable word combinations are not secure passphrases. You should not enter your passphrase anywhere online to evaluate it's security, because such sites could harvest your passphrase in order to steal your funds. If your passphrase is not truly randomly selected, you should treat your wallet as insecure and migrate your finds. Protection via dice rolls If you entered 50+ dice rolls when creating the wallet then you did not follow the default setup, and you have a more secure wallet than the insecure wallets which used the default setup procedure - your key is not exposed by this bug. If you can't remember how many dice rolls you performed you should treat your wallet as insecure and migrate your funds. Migration If you have an insecure wallet / exposed keys you should migrate to a new wallet urgently. Affected keys Policy visibility Funds at risk Submission route Action Below signing threshold Irrelevant No immediate theft using only the identified affected keys. Public broadcast OK Migrate to restore the intended security margin. Signing threshold reached, but at least one cosigner is unaffected The witness script, descriptor and equivalent wallet metadata have not been disclosed.1 No practical theft using this flaw until sufficient policy and public-key information is disclosed. Private preferred Migrate urgently using a direct-to-miner or private-relay service. Signing threshold reached, but at least one cosigner is unaffected The witness script, descriptor or equivalent wallet metadata is already known.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.