Learn how this stuff works. The bug has been fixed, the wallet will be fine again. Random number generation always has risk. It's possible these issues exist in other wallets, even exchange wallets. At least ColdCard lets you generate entropy above their code guided generation, a lot of wallets don't.
ColdCard suggests that users roll dice in the manual. @BTC Sessions encouraged it and explained why it's important.
Login to reply
Replies (3)
I believe that Coinkite is not going to patch the mk3, but only later models. So no, it's not been patched. And patches take a long time to propagate when they have to be installed manually with a nontrivial amount of effort.
There's no recovering from this when the majority of coldcard wallets in people's hands are pwned. Mk3 for sure and the rest severely degraded.
Ah, I take the first part back. There is a patch for the mk3 now. I saw a screenshot earlier that there wasn't.
Still, the problem remains an enormous problem, and people's trust in Coinkite products should be at zero, patched or no.


COLDCARD Documentation
Upgrade Firmware
How to check current COLDCARD security status, choose and verify firmware for your model, and upgrade using MicroSD.
Yeah the patch just makes sure it uses the proper RNG. So once that's fixed, it's technically good again.