Ladies and gentlemen,
At Bitcoin News Weekly, we respect our readers and never want to flood your inbox.
However, the events of the last 72 hours make it very clear that it is imperative we get this message out to as many people as possible.
TL;DR: A major weakness was discovered in the random number generation of COLDCARD products, which has been exploited by hackers.
Over 1,359 BTC have already been stolen from COLDCARD wallets.
If you use any COLDCARD product (Mk2, Mk3, Mk4, Mk5, and the Q) to store your Bitcoin, please be advised that the smartest thing to do is move your funds to a secure address as soon as possible. Those using the Mk3 are at the highest risk and need to act with the most urgency.
Immediate Action
• Do not panic.
• Generate a brand new wallet on unaffected hardware.
• Move your bitcoin to the new wallet or an exchange you trust.
• Never reuse your existing recovery phrase from a COLDCARD.
• Verify your new backup before transferring large amounts.
Do not simply import your existing COLDCARD recovery phrase into another wallet. Generate a brand new seed on trusted hardware and transfer your bitcoin to new addresses.
If you protected your wallet with a strong BIP-39 passphrase, your risk may be significantly lower, but many security researchers are still recommending migration out of caution.
If you are looking for a video to advise you on how to safely get your BTC off of a COLDCARD for immediate next steps, BullBitcoin has provided a helpful tutorial here.
Security researchers have spent the last several days auditing other major hardware wallets and have not identified this same RNG vulnerability in Ledger, Trezor, Jade, Passport, Bitkey, or other widely used devices.
In addition, AnchorWatch is offering 60 free days of Multi-institution Custody. There is no commitment; they are just offering a place to safely store your Bitcoin while you figure out another cold storage solution.
For a technical deep dive into what went wrong with the COLDCARD, these articles by Kevin Loaec and Dusty Daemon will provide much of the necessary background information.
Authorities have already been informed, and there have been leads as to tracking down the perpetrator. If you yourself have been affected by this exploit, and you feel comfortable doing so, please send any relevant information to the team at Galaxy Research. They are piecing together evidence and assisting in law enforcement efforts.
We also published a live discussion Friday featuring FOUNDATION CEO Zach Herbert, OnRamp CEO Michael Tanguma, and NovaSapiens Founder Josh Groth.
To the victims of these attacks, our hearts go out to you. Many spent years stacking Bitcoin and following best practices, only to be let down by the random number generator on a device that was touted as the best in the industry.
This has been a very trying week for the Bitcoin community, but our ability to band together and find solutions, even in the hardest of times, never ceases to amaze me.
Our normal edition of Bitcoin News Weekly will be in your inbox tomorrow morning at the regular time.
If you have any questions or would like to reach out personally, feel free to respond to this email.
No one from Coinkite, Bitcoin News, or anyone else will ever ask for your seed words.
Stay safe out there,
Rob




