Coldcard2026-08-11 20:02:55Coldcard Mk3 Vulnerability Could Generate Identical Mnemonics; ~4.5M Seed States Scannable in 3 SecondsBitcoin News shared on X a technical analysis by @KLoaec finding that some vulnerable Coldcard Mk3 wallets may derive from only ~4.5 million RNG starting states, searchable in about 3 seconds on a single RTX 4090. Even with extra per-wallet uncertainty, an attacker could finish the search on a high-end GPU in ~50 minutes. The flaw could cause different devices to generate identical mnemonics; assuming 30,000 Mk3 units, roughly 120 pairs may produce the same random stream.1870
QuailSeed2026-08-08 17:06:52QuailSeed Turns Quail Eggshell Textures Into Bitcoin BIP-39 MnemonicsQuailSeed, a new experimental open-source tool described by Bitcoin News on X, uses the natural pigment patterns on quail eggshells as physical input to generate 24-word BIP-39 Bitcoin mnemonics. The tool photographs 12 quail eggs from four angles, measures the shell textures, converts the resulting data into a deterministic record, and applies cryptographic processing to produce 256 bits of entropy. The developer stresses that QuailSeed is experimental research software that has not been independently audited or formally verified, and is not approved for use as a secure random number generator or a production-grade custody system.1800
policy2026-08-08 16:48:23Foundation Releases KeyOS 1.3.1 for Passport Prime With Mnemonic GenerationFoundation has released KeyOS 1.3.1 for Passport Prime, adding a feature that lets users generate a valid final mnemonic word from a BIP39 seed phrase. The update also enables on-device mnemonic generation without external tools. An AI security review by Claude Fable Max and ChatGPT 5.6 Sol Extra High found no serious issues.1920
Bitcoin Core2026-07-30 23:02:52Bitcoin Core developer says reported COLDCARD flaw was reproduced on freshly initialized MK3Bitcoin News said in a post on X that Bitcoin Core developer instagibbs was able to reproduce a reported COLDCARD vulnerability on a newly initialized COLDCARD MK3 device using only the number of button presses during setup. He wrote, "sorry, now is the time to panic," and said he believes the issue affects MK2 and MK3 devices, while adding that he cannot yet confirm whether MK4 is vulnerable as well. Developer Antoine Poinsot said the key distinction is that the MK4 uses a hardware random number generator to provide entropy for the seed and actually relies on the microcontroller's true random number generator, or TRNG, while the MK3 does not. The proof of concept and mnemonic verification are still under review, according to the post cited by ChainCatcher.2190
South Korea2026-07-08 23:10:14South Korea Tax Agency Accelerates Crypto Custody Outsourcing After Mnemonic Leak Sparks TheftFollowing a Feb. 26 mnemonic leak that enabled two thefts, South Korea's NTS plans to select a private custodian by H1 2026, and has launched a task force to overhaul seized crypto management.430