Can steal mnemonic phrases and private keys, malicious COLDCARD seed recovery tool exposed as containing backdoor
2026-08-06 11:42
Odaily Planet Daily News: Bitcoin News posted on the X platform stating that a security analysis revealed a repository distributed on GitHub, disguised as a proof-of-concept tool for a COLDCARD random number generator, is malicious in nature. The software claims to be a research tool that reproduces a flawed wallet random number generator to help recover Bitcoin wallets created with vulnerable seeds. According to the report, the tool contains a remote code execution backdoor that downloads an information-stealing program capable of collecting wallet mnemonic phrases, private keys, browser passwords, SSH keys, and other credentials, exfiltrating the data via Telegram while installing persistent malware on Windows, macOS, and Linux. Researchers stated that any user who has executed the code should treat the affected device as fully compromised, rotate credentials, transfer crypto assets to a newly generated wallet, and report the repository. The analysis also warned against running proof-of-concept code for vulnerabilities on devices containing wallets or sensitive data without independent verification.
