Bitcoin Core developer claims to have reproduced the COLDCARD MK3 vulnerability; MK2/MK3 devices may be affected
2026-07-30 23:02
Odaily Planet Daily reported that Bitcoin News stated on the X platform that Bitcoin Core developer instagibbs claimed to have successfully reproduced the reported COLDCARD vulnerability on a newly initialized COLDCARD MK3 device, using only the number of button presses during the setup process, and said, “Sorry, it’s time to panic.”
He believes the issue affects MK2/MK3 devices but stated that it is currently unclear whether there is a vulnerability in the MK4.
Developer Antoine Poinsot stated that the key difference is that the MK4 uses a hardware random number generator to provide entropy for the seed and actually utilizes the microcontroller’s true random number generator (TRNG), while the MK3 does not.
The proof of concept and mnemonic phrase verification are still under review.
He believes the issue affects MK2/MK3 devices but stated that it is currently unclear whether there is a vulnerability in the MK4.
Developer Antoine Poinsot stated that the key difference is that the MK4 uses a hardware random number generator to provide entropy for the seed and actually utilizes the microcontroller’s true random number generator (TRNG), while the MK3 does not.
The proof of concept and mnemonic phrase verification are still under review.
