A serious vulnerability in Cold Card hardware wallets has exposed Bitcoin funds across all current product lines — MK3, MK4, MK5, and the Q. Over 38 million dollars worth of Bitcoin had already been swept at the time of recording, with the number climbing, and the hosts make clear this is not a drill: if you generated a seed on a Cold Card, treat those keys as compromised and move your funds now.
In this episode:
• The bug stems from a flawed random number generator in Cold Card firmware — one line of code, undetected for five years, that reduced the entropy used when generating seeds, making wallets brute-forcible with roughly $10,000 worth of compute
• MK3 wallets are the highest priority, with only 40 bits of entropy; MK4, MK5 and Q wallets have around 72 bits — still brute-forcible and actively being targeted
• Recommended migration paths include: updating firmware and generating a fresh wallet, adding a strong six-word passphrase, moving to a hot wallet in Sparrow temporarily, or using another hardware wallet such as Trezor Safe 3/5/7, Blockstream Jade, Passport, Seed Signer, or Bitkey
• If you used 99 or more dice rolls during setup and added a passphrase, you are likely not at risk — but the hosts suggest migrating anyway out of caution
• NVK's public statement is read and discussed, including his warning that AI-assisted code review can now find latent bugs faster than seasoned human reviewers
• The attacker appears to have used bots to sweep high-value wallets first, skipping addresses below a threshold — and may have been identified through a paid service account they used during the attack
• The hosts reflect personally on years of recommending Cold Card to clients, friends and family, and discuss what this means for the future of self-custody, multi-vendor multisig, and user-generated entropy as a baseline requirement
Watch the video version: https://youtu.be/rrIQpRNhXiA