Update, Sunday.
The last three days have been some of the hardest in this company’s history, and for a lot of the people reading this, they’ve been something much worse. Money that took years to save, gone. Trust that took years to build, broken. That impact is real, and for some, the damage is permanent. Some are asking hard questions about our company. We are, too.
Our work won’t stop in the weeks ahead. It is just beginning.
Since Friday, our team has been reaching out and working directly with customers, helping move funds that were still safe to move, walking through recovery options together, and staying reachable for anyone who wrote in not knowing where they stood. We acknowledge that others in the community did the same, selflessly, and without compensation. We thank them sincerely.
We’ve also been in direct contact with the wider hardware wallet and self-custody community, including other builders, researchers, and people who’ve thought hard about this kind of failure. All have graciously offered whatever resources they could spare. We are still engaged in this outreach and are committing to work with the broader industry going forward.
If you have an affected device, please do not dispose of it. It may become essential if funds are recovered. Our legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible.
We destroyed our remaining COLDCARD inventory manufactured with the vulnerable firmware, and shipment was halted when the vulnerability was confirmed. SATSCARD, OPENDIME, and TAPSIGNER are not affected by this issue.
Our patched firmware prevents this issue from affecting any new seed generated going forward. It does not repair or restore security to a seed that was already generated on vulnerable firmware. A new seed must be created, and funds moved to it to be secure.
If you need a device sooner than we can provide one, or want an alternative while you decide next steps, Bitkey, Ledger, Trezor, Jade, and BitBox are reputable options. For collaborative custody, AnchorWatch, Casa, Unchained, Nunchuk, and Liana are worthy of consideration.
We continue to read everything—the replies, the texts, the emails. Some of it we owe direct answers to. We’ll follow up on that specifically and soon.
There are real lessons here for us as a company. We owe the community better, and we’re beginning to understand the many ways in which our best efforts and designs could have allowed for this to happen. We’ll show that in our technical postmortem, as soon as it is possible to do so.
For now, please continue to refer to the COLDCARD Security Advisory for the best available information. Please continue to reach out to friends, family, and loved ones who may be affected. Time is of the essence. The threat remains real and ongoing.