URGENT: I’ve seen some people saying that they are on vacation and won’t be able to check their coldcard for days until they get back.
If you have one of the affected coldcards and can’t get back in time please call a trusted person, have them go to where your device is stored and walk them through the procedure to transfer funds over FaceTime.
Normally this would be horrible advice but under these circumstances I think it has the potential to save someone’s coins.
Attacks are increasing not decreasing and attackers are starting to crack through the affected mk3’s with pass phrases. There are even credible reports of mk4’s with pass phrases being hit.
If you are in this specific situation, throw the regular rules out the window and do what you must in order to save your coins. DONT WAIT.
Login to reply
Replies (24)
THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS
No. The only risk is if you have too many coldcards in your quorum.
Just have them read out their seed phrase over the phone, the person will never remember it, and then you maintain the privacy of your stack and how much you have.
If this is you, jump on a computer. Call a friend and have them find your seed phrase and read it out loud to you over the phone.
Enter it on your end into Sparrow and you can easily send your bitcoin to a different address and your friend never knows how much bitcoin you had or any other details.
View quoted note →
The devices themselves are not compromised.
It's the seed phrases generated on these devices not being random, making them easier to brute force.
Moving to a new device makes absolutely no difference.
You need to generate a new seedphrase (with updated firmware/ on a different device / using real world entropy)
Agreed - I guess the simple message catches 95% of the attack surface.
Prioritize security like you prioritize animal fat in your diet, non-negotiable.

Literally did this 2 days ago
Solid advice from @Samson Mow
The COLDCARD RNG vulnerability may be worse than an exchange hack. It hit at the core of sovereign Bitcoin holders - it struck those who did all the research, understood why self-custody is important, and didn’t keep coins on exchanges.
My heart goes out to everyone affected. It’s a horrible situation and the damage is irreparable. While I have many thoughts and criticisms about how we got here, I’ll hold back because I know nvk is devastated too.
Self-custody is hard. If you advocate for self-custody, you should also be telling people to use a multi-vendor multisig setup. I’ve been saying this for years. Self-custody only works if you do it in a way that minimizes a single point of failure. Don’t trust any single vendor for hardware. Assume everyone is your adversary.
As self-custody is hard, we should be less critical of people who chose to use custodians or hold BTC in ETFs or Bitcoin Treasury Companies. There isn’t a single right or wrong way to use Bitcoin and there are tradeoffs everywhere.
Some people have contacted me about what to do. Here’s what I recommend:
1️⃣ Document everything. Write down all the facts and details you know (dates, addresses, firmware, etc.).
2️⃣ File a police report, as it creates an official record which is useful for a number of reasons. Even better if you can contact a cybercrime unit, national reporting portals (e.g., FBI IC3 in the US), or specialized crypto-crime task forces if they exist.
3️⃣ Watch for coordinated efforts to track movements of funds.
4️⃣ Do not destroy your COLDCARD and seed phrase. Hold onto them as there could be a chance that stolen funds reach an exchange, are frozen, and you need to prove ownership. Write down your PIN too, or note it in your documentation. When you stop using it for a long time, you may forget it.
5️⃣ This next point is very important: DO NOT share your personal details, seed phrase, or send any money to anyone claiming they can “help recover” the funds. Scammers will be targeting people who are desperate.
Just know that almost everyone has lost coins for some reason at some point. Don’t do anything rash. Talk to someone if you need to. You can always rebuild, but only if you’re still here.
For all of us developing wallets, software or hardware, security is the most important thing we provide. People are counting on us and we have to do better.
Depending on how much is on those keys and how long the flight would take, just go the the airport and get on the next plane!
Wdym "2 password wallet".
Or just get on the phone with someone close - Apple are not going to steal your seed phrase over FaceTime (today)
2 password wallet should probably say “a single sig wallet with a two word passphrase” was drained. That is the report I read.
It essentially means the attach has evolved from single sig non-passphrase wallets to empty single sig wallets which are now having the passphrase’s cracked.
I expect it will progress further to the attacker combining the known seeds to try generating signatures for multisig wallets.
You receive the order of Entropy Master 2026 🏆 🎉🎉🎉🎉
Nightmare to put that into your HW every time lol. Better not screw it up
Yet another PSA from @Rob Hamilton
I have spent over $10,000 scanning 100+ bitcoin ecosystem related libraries looking for vulnerabilities with Kimi K3 running as quarterback.
Myself and a small "Red Team" have found multiple serious vulnerabilities impacting the ecosystem. They vary in scope severity, but this is a call to action.
For any critical tier vulnerability that was identified if I was able to immediately demonstrate a POC (proof of concept), I have already responsibly disclosed to the maintainers.
HERE IS HOW YOU CAN HELP ME
IF YOU ARE NOT TECHNICAL:
- please share with me any repository that is on github that I can scan, we want to cast a wide net. It takes a few moments for you to link github accounts, we'll take it from there
- if that project does not have a SECURITY.md make an issue asking the dev to list one
IF YOU ARE TECHNICAL:
- If you are a maintainer or contributor to a project, I may have already scanned your repo, hit me up I'll share the results, if not I'll add your project to the list.
- If I can trust you to do larger review to start looking through this stuff to give me more eyes let me know.
AI Has forever changed software development. Tomorrow marks 1 week of Kimi k3 being live in open weights.
We are going to accelerate.
🚨@MARA Slipstream is now available as a permissionless public good with no client code requirement.
Please be careful and conservative with fees to avoid transactions getting stuck in the Slipstream mempool in the event that competitive rates spike.
For the foreseeable future, we are not charging additional fees for this service, but users are responsible for paying appropriate Bitcoin transaction fees.
Slipstream.mara.com
nice try schizo


URGENT WIPE UR OWN DUMB ASS SODL
Great to see.
Sorry, a two word password
Now we have to decide whether constant access is a requirement vs wrench attack risk?? 🤷♂️
