r/coldcard: Crypto-Guide relaying the Mk3 security advisory
reddit-mk3-advisory-relay
https://www.reddit.com/r/coldcard/comments/1vb9doi/mk3_security_advisory/
Latest reviewed change
source content difference between and
Two new comments: nyr00nyg saying they are doing fine with a Ledger Nano, and a reply from Crypto-Guide endorsing Ledger.
edited: false
body:
Thanks for surfacing the official advisory. The bit people keep skipping over: updating firmware doesn’t repair a seed that was generated on an affected version. That one needs replacing outright.
+
+comment: p220cy7
+parent: t3_1vb9doi
+author: nyr00nyg
+created_utc: 1786022432
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 2
- Detected differences
- 2
- Unreviewed
- 0
- Copies held
- 3
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Two new comments: nyr00nyg saying they are doing fine with a Ledger Nano, and a reply from Crypto-Guide endorsing Ledger.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 16 lines
edited: false body: Thanks for surfacing the official advisory. The bit people keep skipping over: updating firmware doesn’t repair a seed that was generated on an affected version. That one needs replacing outright. + +comment: p220cy7 +parent: t3_1vb9doi +author: nyr00nyg +created_utc: 1786022432 +edited: false +body: +Doing just fine with my ledger nano + +comment: p22hlmc +parent: t1_p220cy7 +author: Crypto-Guide +created_utc: 1786027109 +edited: false +body: +Ledger and chill ;)Extracted text as captured
post: 1vb9doi author: Crypto-Guide created_utc: 1785452914 title: Mk3 Security Advisory comment: p0rs8pl parent: t3_1vb9doi author: bitusher created_utc: 1785454184 edited: 1785605935 body: Thanks for getting the word out. Some more context - https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/ An exploit , likely a flaw in rng generation with lower entropy in firmware but waiting on more details from investigation, has allowed an attacker to drain what appears over ~~594 BTC~~ 1,128.49 BTC from over 500 wallets with the highest risk being Cold Card MK2 through MK3 wallets thus far . MK1 wallets are safe. https://coldcard-hack-tracker.vercel.app/ This doesn't seem to have effected MK4 or MK5 or Q initially because those later models used more entropy thus are much harder to attack but you need to still update the firmware and eventually migrate to a new seed regardless to be safe longterm. Hypothetically 60 to 73 bits of entropy found in the MK4,MK5 and Q seeds can be brute forced by a large GPU cluster in as soon as 1 week to centuries. Thus its best to upgrade your security on these in the next week **at the latest**. https://blog.coinkite.com/entropy-technical-backgrounder/ https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware Users using multisig created with a majority of other wallets or if you used an extended passphrase like our FAQ has always recommended should be safe although you should consider migrating in time to a new seed. Thus if you setup a single sig wallet with Cold Card MK3, first **do not panic** as that is when mistakes will happen. Ideally setup a new seed on a second hardware wallet that is not an MK3 and move your bitcoin over with an onchain transaction. Do not send your bitcoin to a hot wallet or an exchange that lacks secure U2F/FIDO 2fa If you lack a second hardware wallet than create a extended passphrase and move your btc to a new address within that account as a temporary measure. https://coldcard.com/docs/passphrase/ Please be aware that extended passphrases should beExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Reddit no longer served one earlier question about Tails and Electrum, and a separate comment's author and body now appear deleted.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 12 lines
[https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware](https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware) -comment: p0t0wt2 -parent: t1_p0sivl4 -author: ASilverSpartan -created_utc: 1785469295 -edited: false -body: -Was tails electrum ever unsafe? That’s how I protect mine and it’s lasted for almost a decade now. Do I need to change my security posture? - comment: p0t53se parent: t1_p0soaak author: cilicia3k3 comment: p0u14mh parent: t3_1vb9doi -author: smaakversterker +author: [deleted] created_utc: 1785485305 edited: false body: -what about the MK1? +[deleted] comment: p0u2otq parent: t1_p0tqbhnExtracted text as captured
post: 1vb9doi author: Crypto-Guide created_utc: 1785452914 title: Mk3 Security Advisory comment: p0rs8pl parent: t3_1vb9doi author: bitusher created_utc: 1785454184 edited: 1785605935 body: Thanks for getting the word out. Some more context - https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/ An exploit , likely a flaw in rng generation with lower entropy in firmware but waiting on more details from investigation, has allowed an attacker to drain what appears over ~~594 BTC~~ 1,128.49 BTC from over 500 wallets with the highest risk being Cold Card MK2 through MK3 wallets thus far . MK1 wallets are safe. https://coldcard-hack-tracker.vercel.app/ This doesn't seem to have effected MK4 or MK5 or Q initially because those later models used more entropy thus are much harder to attack but you need to still update the firmware and eventually migrate to a new seed regardless to be safe longterm. Hypothetically 60 to 73 bits of entropy found in the MK4,MK5 and Q seeds can be brute forced by a large GPU cluster in as soon as 1 week to centuries. Thus its best to upgrade your security on these in the next week **at the latest**. https://blog.coinkite.com/entropy-technical-backgrounder/ https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware Users using multisig created with a majority of other wallets or if you used an extended passphrase like our FAQ has always recommended should be safe although you should consider migrating in time to a new seed. Thus if you setup a single sig wallet with Cold Card MK3, first **do not panic** as that is when mistakes will happen. Ideally setup a new seed on a second hardware wallet that is not an MK3 and move your bitcoin over with an onchain transaction. Do not send your bitcoin to a hot wallet or an exchange that lacks secure U2F/FIDO 2fa If you lack a second hardware wallet than create a extended passphrase and move your btc to a new address within that account as a temporary measure. https://coldcard.com/docs/passphrase/ Please be aware that extended passphrases should beExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vb9doi author: Crypto-Guide created_utc: 1785452914 title: Mk3 Security Advisory comment: p0rs8pl parent: t3_1vb9doi author: bitusher created_utc: 1785454184 edited: 1785605935 body: Thanks for getting the word out. Some more context - https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/ An exploit , likely a flaw in rng generation with lower entropy in firmware but waiting on more details from investigation, has allowed an attacker to drain what appears over ~~594 BTC~~ 1,128.49 BTC from over 500 wallets with the highest risk being Cold Card MK2 through MK3 wallets thus far . MK1 wallets are safe. https://coldcard-hack-tracker.vercel.app/ This doesn't seem to have effected MK4 or MK5 or Q initially because those later models used more entropy thus are much harder to attack but you need to still update the firmware and eventually migrate to a new seed regardless to be safe longterm. Hypothetically 60 to 73 bits of entropy found in the MK4,MK5 and Q seeds can be brute forced by a large GPU cluster in as soon as 1 week to centuries. Thus its best to upgrade your security on these in the next week **at the latest**. https://blog.coinkite.com/entropy-technical-backgrounder/ https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware Users using multisig created with a majority of other wallets or if you used an extended passphrase like our FAQ has always recommended should be safe although you should consider migrating in time to a new seed. Thus if you setup a single sig wallet with Cold Card MK3, first **do not panic** as that is when mistakes will happen. Ideally setup a new seed on a second hardware wallet that is not an MK3 and move your bitcoin over with an onchain transaction. Do not send your bitcoin to a hot wallet or an exchange that lacks secure U2F/FIDO 2fa If you lack a second hardware wallet than create a extended passphrase and move your btc to a new address within that account as a temporary measure. https://coldcard.com/docs/passphrase/ Please be aware that extended passphrases should beExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.