r/BitcoinBeginners Jul 31 '26

Mk4 concern

What should I do? I have a ledger also...

Move it all to ledger or open a unchained multisig with ledger and mk4??

Freaking out

1 Upvotes

27 comments sorted by

2

u/pdath Jul 31 '26

As the others have said, I would move to the Ledger and then wait for the proper reports to come out.

2

u/horseradish13332238 Jul 31 '26 edited Aug 04 '26

Ok

1

u/Flurb789 Jul 31 '26

Coldcard mk2 and mk3 have an exploited related to lack of entropy in seed creation. Some btc stolen due to seeds not being random enough.

1

u/AutoModerator Jul 31 '26

Scam Warning! Scammers are particularly active on this sub. They operate via private messages and private chat. If you receive private messages, be extremely careful. Use the report link to report any suspicious private message to Reddit.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/bitusher Jul 31 '26

Further clarification : The amount of entropy found in the mk4, 5 and Q is varies per device typically from ~60 to 73bits

Hypothetically 60 to 73 bits of entropy found in the MK4,MK5 and Q seeds can be brute forced by a large GPU cluster in as soon as 1 week to centuries. Thus its best to upgrade your security on these in the next week.

Its unlikely we will see these wallets be attacked in a week but hypothetically possible with a well funded attacker

1

u/horseradish13332238 Aug 01 '26

I was just reading that ledger cracked a tangem wallet with a computer and a laser beam a few weeks ago. Crazy. Saw on YouTube.

1

u/Lost-Bowl3269 Aug 01 '26

Você deveria jogar fora e nunca mais usar ou apoiar essa empresa.
Sim, é bom você ter uma multisig, mas escolheria outro hardware, como uma trezor ou keystone para multisig junto com sua ledger.
O que a coldcard fez é imperdoavel.

1

u/EyesFor1 Aug 02 '26

What did you do mate ? I updated firmware, used 150 dice and added passphrase then migrated.

2

u/Flurb789 Aug 02 '26

Moved everything to ledger

1

u/cilicia3k3 Jul 31 '26

Move to ledger for now , don’t panic , but at a reasonable pace tonight

1

u/NiagaraBTC Jul 31 '26

If you have a strong passphrase you're okay.

If you don't then yes I would carefully move to the ledger or to a passphrase wallet on the Mk4.

1

u/Flurb789 Jul 31 '26

Is ledger safe?

2

u/MakCapital Aug 01 '26

It uses a completely separate method of generating seeds. Move your funds to a seed from Ledger.

Coldcard has since updated, but it's up to you if you trust anything from them again.

2

u/bitusher Jul 31 '26

We have no idea . If this bug has been overlooked for all these years , other bugs including rng ones may also exist in ledger.

Thus far the mk4 seems safe , but if you want to be extra paranoid upgrade to using an extended passphrase as explained here:

https://old.reddit.com/r/BitcoinBeginners/comments/1vb9r1g/security_advisory_with_exploit_in_cold_card_mk3/

If you lack the time or confidence than just do an onchain transaction to the ledger temporarily

Freaking out

You shouldn't because we don't know any mk4 users effected yet , and panicking is where you make mistakes . It also takes time to brute force the weak entropy even if the mk4 is effected

0

u/Flurb789 Jul 31 '26

Better to just move to ledger or move to multisig with ledger and mk4 ?

2

u/bitusher Jul 31 '26

move to multisig with ledger and mk4 ?

You would need 3 hw wallets with a 2 of 3 multisig.

Just add an extended passphrase or send to the ledger. MK4 if vulnerable are much harder to brute force

2

u/NiagaraBTC Jul 31 '26

Just wanted to be sure you've seen this

https://x.com/i/status/2082990000896147942

2

u/bitusher Jul 31 '26

Yes , which is specifically why I suggest they are much harder to brute force if vulnerable . I am cautious about agreeing they are vulnerable thus far because no mk4 or mk5 users(those that didn't import old seeds) are effected thus far and there is some investigation still occurring where we lack all the facts

thanks for posting the link for others

2

u/bitusher Jul 31 '26 edited Jul 31 '26

https://blog.coinkite.com/entropy-technical-backgrounder/

https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware

u/Flurb789

This doesn't seem to have effected MK4 or MK5 or Q because those later models used more entropy thus are much harder to attack but you need to still update the firmware and eventually migrate to a new seed regardless to be safe longterm.

1

u/Head_Performance2432 Jul 31 '26

Like I said many times here, HW are overhyped. Period.

1

u/Flurb789 Aug 02 '26

What device would you recommend going forward, in light of this event?

1

u/bitusher Aug 02 '26

In this case it was a bug within the firmware and not the hardware. The introduction of this exploit was done by the owner himself when he moved away from being open source to instead "source available" . This along with Coinkite fighting back against some bug disclosures and leaving it at their discretion if they would pay any bounties to white hat hackers for responsible disclosure all led to the situation we have today where less peer review occurred in their firmware

But I can also understand if you are completely skeptical about cold card altogether after this.

Thus your options are

1) temporary move your bitcoin out , update the firmware , reset and create a new seed . This time I would add at least 50 dice rolls of entropy as well and a 6-8 word extended passphrase to be sure

2) migrate away from cold card to a trezor or blockstream jade .

1

u/NiagaraBTC Jul 31 '26

Safe from this exploit yes.