IMPORTANT ColdCard SECURITY UPDATE

Important security update for anyone using a COLDCARD.

There has been a serious vulnerability disclosed involving the randomness used by some COLDCARD devices when generating Bitcoin seeds.

If you use a COLDCARD, I recommend moving your bitcoin to a completely new seed generated somewhere else. If you use another wallet today but you generated the seeds on a coldcard, you should also move your bitcoin.

First, an important reassurance: if you followed best practices and generated your own seed using at least 50 fair, independent, private dice rolls, you are not considered at risk from this specific randomness vulnerability. Similarly, if you used a strong passphrase, that provides additional protection. And there are several COLDCARD devices and seeds that fall outside the specific affected firmware ranges.

But my recommendation is simpler than trying to determine exactly which model you have, which firmware was installed years ago when you generated your seed, how many dice rolls you used, whether you remember every detail correctly, and whether further vulnerabilities may be discovered.

With something as important as your bitcoin, I would rather eliminate the uncertainty than take a risk we don't need to take. If you rolled your own dice more than 50 times and have a strong passphrase, you probably have more time. If you relied on the device to produce the randomness, you need to act immediately.

Either way, act decisively and with high focus. Take your time and use whichever migration option you are most comfortable and competent with. Rushing a Bitcoin transaction or improvising a security setup you don't understand can create its own risks.

If you decide to migrate to another hardware wallet or an airgapped computer you understand well, here's the process:

First, generate a completely new seed on an unaffected device you know is safe from bugs and is not connected to the internet.

Second, carefully record and verify the new seed backup.

Third, verify the wallet fingerprint and receiving address on the hardware wallet itself or the airgapped computer. Do not simply trust what your online computer or phone shows you.

Fourth, send a small test transaction.

Fifth, confirm that everything works and that you can access and spend from the new wallet before moving the remaining funds.

And keep your old seed backup until you have fully verified that the migration is complete.

If you're not comfortable setting up another self-custody wallet immediately, another option is to temporarily move the bitcoin to a reputable exchange or custodian that you already trust while you take the time to establish a new self-custody setup properly.

Again, the point is not to rush. Choose the option you understand best. But do move.

If you used a strong, unique BIP-39 passphrase, that provides an additional independent security barrier. If you used sufficient private dice entropy, that also protects you from this particular randomness problem. But personally, given what has been disclosed, I would still rather create a fresh seed somewhere else and remove the uncertainty entirely.

One final warning: scammers will absolutely try to exploit this situation.

Never give your seed words or passphrase to anyone. Never enter them into a website, chatbot, unsolicited recovery tool, or a link somebody sends you. Nobody helping you migrate needs your seed words.

Don't panic. Don't ignore it either. Take your time, verify every step, and move your funds in whatever safe way you are most comfortable with.

Be sure to hold on to all your devices and seeds, as they may be useful in demonstrating ownership of the coins if the hacker is caught.

Also be sure to follow the latest disclosures from Coinkite to understand if your device is affected, and to follow all the latest updates on the issue. I recommend Twitter for staying up to date.