News

Public · Published

Coldcard now requires 65 key presses after seed exploit, while exposed funds still must move

Coldcard released new firmware versions that now require 65 key presses when creating a new wallet, aiming to stop a seed exploit. However, this update cannot fix wallets made on affected releases, so exposed funds must still be moved.

Published:

Updated:

What happened

Coldcard released new firmware versions that now require 65 key presses when creating a new wallet, aiming to stop a seed exploit. However, this update cannot fix wallets made on affected releases, so exposed funds must still be moved.

Confirmed

Global impact / market context

This matters for Bitcoin owners using Coldcard hardware wallets, which are physical devices that store digital money offline. If a wallet was created on an older vulnerable version, the private key could be at risk, meaning the cryptocurrency might be stolen. Moving funds to a new wallet protects them.

Analyst inference

Coldcard is owned by Block, a public company. A security flaw could damage user trust, which might reduce future sales of its hardware wallets. If investors worry about brand reputation and demand, the company's stock price could weaken in the short term.

Analyst inference

What to watch

  1. Users who made wallets on affected Coldcard versions must transfer all funds to a new wallet created after installing the updated firmware to keep their Bitcoin safe. Confirmed
  2. Investors should watch for announcements from Coldcard or Block about a recovery tool or compensation program for affected users, which would show how they handle this responsibility. Proposed
  3. Watch Bitcoin transaction activity for a sudden jump in volume, which could indicate many users moving funds at once, and note any public statements from Block addressing the situation. Analyst inference

Affected assets

  • BLOCK — Block
  • BTC — Bitcoin

Evidence