Bitcoin Core developer claims to have reproduced the COLDCARD MK3 vulnerability, MK2/MK3 devices may be affected
2026-07-30 23:02
Odaily Planet Daily News: Bitcoin News posted on X platform, stating that Bitcoin Core developer instagibbs claimed to have successfully reproduced the reported COLDCARD vulnerability on a newly initialized COLDCARD MK3 device, using only the number of button presses during the setup process, and said, "Sorry, now is the time to panic."
He believes the issue affects MK2/MK3 devices, but stated that it is currently impossible to confirm whether the MK4 has a vulnerability.
Developer Antoine Poinsot stated that the key difference is that the MK4 uses a hardware random number generator to provide entropy for the seed and actually utilizes the microcontroller's true random number generator (TRNG), while the MK3 does not.
This proof of concept and mnemonic verification are still under review.
He believes the issue affects MK2/MK3 devices, but stated that it is currently impossible to confirm whether the MK4 has a vulnerability.
Developer Antoine Poinsot stated that the key difference is that the MK4 uses a hardware random number generator to provide entropy for the seed and actually utilizes the microcontroller's true random number generator (TRNG), while the MK3 does not.
This proof of concept and mnemonic verification are still under review.
