Bitcoin Core developer claims to have reproduced the COLDCARD MK3 vulnerability, potentially affecting MK2/MK3 devices
2026-07-30 23:02
Odaily reported that Bitcoin News posted on X platform, stating that Bitcoin Core developer instagibbs claimed to have successfully reproduced the reported COLDCARD vulnerability on a newly initialized COLDCARD MK3 device, using only the number of button presses during the setup process, and said, "Sorry, it's time to panic."
He believes the issue affects MK2/MK3 devices, but stated that it is currently impossible to confirm whether the MK4 has any vulnerabilities.
Developer Antoine Poinsot noted that the key difference is that the MK4 uses a hardware random number generator to provide entropy for the seed and actually utilizes the microcontroller's true random number generator (TRNG), whereas the MK3 does not.
The proof of concept and mnemonic verification are still under review.
He believes the issue affects MK2/MK3 devices, but stated that it is currently impossible to confirm whether the MK4 has any vulnerabilities.
Developer Antoine Poinsot noted that the key difference is that the MK4 uses a hardware random number generator to provide entropy for the seed and actually utilizes the microcontroller's true random number generator (TRNG), whereas the MK3 does not.
The proof of concept and mnemonic verification are still under review.
