Bitcoin Core开发者称已复现COLDCARD MK3漏洞,MK2/MK3设备或受影响
2026-07-30 23:02
Odaily Planet Daily News: Bitcoin News posted on X platform, stating that Bitcoin Core developer instagibbs claimed to have successfully reproduced the reported COLDCARD vulnerability on a newly initialized COLDCARD MK3 device, using only the number of button presses during the setup process, and said, "Sorry, it's time to panic."
He believes the issue affects MK2/MK3 devices, but stated that he cannot confirm whether there is a vulnerability in the MK4 yet.
Developer Antoine Poinsot said the key difference is that the MK4 uses a hardware random number generator to provide entropy for the seed, and actually utilizes the microcontroller's True Random Number Generator (TRNG), whereas the MK3 does not.
The proof of concept and the verification of the mnemonic are still under review.
He believes the issue affects MK2/MK3 devices, but stated that he cannot confirm whether there is a vulnerability in the MK4 yet.
Developer Antoine Poinsot said the key difference is that the MK4 uses a hardware random number generator to provide entropy for the seed, and actually utilizes the microcontroller's True Random Number Generator (TRNG), whereas the MK3 does not.
The proof of concept and the verification of the mnemonic are still under review.
