Bitcoin Core developer says reported COLDCARD flaw was reproduced on freshly initialized MK3

Bitcoin Core developer says reported COLDCARD flaw was reproduced on freshly initialized MK3

N
News Editor
2026-07-30 23:02:52
Bitcoin News said in a post on X that Bitcoin Core developer instagibbs was able to reproduce a reported COLDCARD vulnerability on a newly initialized COLDCARD MK3 device using only the number of button presses during setup. He wrote, "sorry, now is the time to panic," and said he believes the issue affects MK2 and MK3 devices, while adding that he cannot yet confirm whether MK4 is vulnerable as well. Developer Antoine Poinsot said the key distinction is that the MK4 uses a hardware random number generator to provide entropy for the seed and actually relies on the microcontroller's true random number generator, or TRNG, while the MK3 does not. The proof of concept and mnemonic verification are still under review, according to the post cited by ChainCatcher.

ChainCatcher reported that Bitcoin News said in a post on X that Bitcoin Core developer instagibbs reproduced a reported COLDCARD vulnerability on a freshly initialized COLDCARD MK3 device using only the number of button presses during setup.

instagibbs wrote, "sorry, now is the time to panic." He said he believes the issue affects MK2 and MK3 devices, but added that he cannot yet confirm whether MK4 is also vulnerable.

Developer Antoine Poinsot said the key difference is that the MK4 uses a hardware random number generator to provide entropy for the seed and actually uses the microcontroller's true random number generator, or TRNG, while the MK3 does not.

The proof of concept and mnemonic verification are still under review.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.