Urgent Security Advisory Issued for Certain Coldcard Wallet Setups
Alex Thorn, Head of Research at Galaxy Digital, has escalated warnings regarding potential vulnerabilities associated with specific configurations of Coldcard hardware wallets. The advisory calls for prompt user action to safeguard digital assets.
Identifying Potentially Vulnerable Wallets
Thorn's analysis indicates that wallets may be at significant risk if they meet all the following criteria:
- Were set up using the device firmware after March 17, 2021.
- Operate in a single-signature mode without an enabled passphrase.
- Were initialized without enhancing entropy through physical means like dice rolls during seed generation.
Wallets matching this profile might contain keys derived from a potentially compromised random number generation process.
Recommended Immediate Action
The core recommendation is unequivocal: users with wallets fitting the high-risk description should proactively migrate their funds to a new, securely generated wallet without delay.
Thorn notes that there is evidence of active attacks, with bad actors systematically draining addresses that exhibit these characteristics. Procrastination could lead to irreversible loss.
Lower-Risk Exemptions
The warning comes with specific exemptions. Users whose setup process adhered to one of these high-security practices face a markedly lower risk:
- Imported a seed from a known high-entropy external source.
- Performed extensive dice-rolling (e.g., 100+ rolls) to generate the seed phrase.
Regardless, Thorn advises all users to routinely audit their security setup, as proactive measures remain the strongest defense against evolving threats.