PSA: Advice Regarding the Coldcard Bug - Exploit - Hack - Theft
stackernews-psa-advice
- Organisation
- Stacker News
- Evidence role
- Community discussion
- Published
- 2026-08-01
- Source changes
- 0
- Detected differences
- 0
- Unreviewed
- 0
- Copies held
- 1
BITC0IN's PSA with owner advice, including the Mk3-without-passphrase case. Community guidance from the response window; specific claims are the author's and partly contested in replies. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
{ "data": { "item": { "comments": { "comments": [ { "createdAt": "2026-08-02T00:21:59.662Z", "text": "If you trusted Cold Card to properly use their secure element, how can you be sure they properly used your dice roll entropy? I know you can check the outputs with a CLI script but who actually does that?\n\nI'd go even farther and say just ditch Cold Card altogether. You have nothing to gain by staying and everything to lose.", "user": { "name": "UncleJim21" } }, { "createdAt": "2026-08-02T04:29:35.696Z", "text": "Interesting post... I just disagree with putting your funds on an exchange since it's like Russian roulette (don't get involved with any of them) as it's not recommended.\nBlockstream wallets are quite secure and are not under attack, as their creators have already announced!", "user": { "name": "mkmloom" } } ] }, "createdAt": "2026-08-01T22:24:20.088Z", "text": "\n\nI’m just going to write, this won’t be polished.\n\n**If you have/use a coldcard MK3 without a passphrase, that wasn’t setup with 100+ dice rolls, you need to move your funds out of that coldcard as soon as possible to safe harbor.**\n\n*If you have/use a coldcard MK4/5/Q without a passphrase, that wasn’t setup with 100+ dice rolls, you need to move your funds out of that coldcard sooner then latter to safe harbor.*\n\nIf you have/use a coldcard MK3/MK4/5/Q with a passphrase and/or that was setup with 100+ dice rolls, you have more time. It could very well be safe for the long term too, but you’d be wise to migrate to safer harbor eventually.\n\n**If you use any of these devices and forget what your setup is, you need to move to safe harbor as soon as possible.**\n\n----------------------------------------------------------------------------------------------------------------------\n\n**What is safe harbor at this point in time? For MK3’s with no passphrase/no dice – literally anything else. Hot wallets are better in this moment in time (blue wallet, sparrow wallet). Exchanges are also an option. Adding a 16 character passphrase on top of your Mk3 wallet is also an option and helps. Another hardware wallet from a different vendor is better too. Anything else is better at this moment. Your funds are at severe risk in a mk3 here. But none of these safe harbours are long term solutions, they’re short term safety nets for an extreme situation. Consider your safe harbour options carefully and pick the strongest one for your situation.**\n\n*Safe harbor for the MK4/5/Q’s with no dice/no passphrase is the same situation to be honest. Get it off somewhere else, anywhere else.*\n\n**Before moving to hot wallets/exchanges please consider if you have other more secure options available. A spare hardware wallet from another vendor, trezor, ledger etc might be better in this moment too.**\n\nIdeally for everyone else not in the extreme conditions, migrating away from coldcard eventually is probably wise here for several reasons I won’t get into yet, but are probably obvious. A 2/3 Multisig setup from multiple different hardware wallet brands is ideal long term, and guards against this attack/bug. Seedsigner, Krux, Trezor Model 5 Bitcoin only version, are good options to consider for such a multsig arrangement at this point in time. I don’t believe it wise to reuse coldcards for long term storage even if updated at this point in time. This article (link below) is a good follow up on entropy generation offline with analog methods. This guards against this coldcard attack/bug.\n\n[https://btcmaxis.com/article.html?id=7554e7cb-d8aa-45d5-95c8-adea8d87ea23](https://btcmaxis.com/article.html?id=7554e7cb-d8aa-45d5-95c8-adea8d87ea23)", "title": "PSA: Advice Regarding the Coldcard Bug - Exploit - Hack - Theft", "user": { "name": "BITC0IN" } } } }Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.