A HARDWARE WALLET IMPLEMENTATION FAILED. SELF-CUSTODY DID NOT.
Block’s investigation has identified a serious random-number-generation flaw affecting older COLDCARD devices and has raised unresolved questions about the RNG design used in newer models, including the Mk4, Mk5 and Q.
The confirmed vulnerable path currently concerns older Mk2 and Mk3 firmware. Practical exploitation of the newer models has not been established, so we are monitoring the technical evidence closely and will update our guidance as the facts develop.
This incident reinforces an important principle: proper self-custody must never depend on a single device alone.
The Bitcoin Way’s methodology uses strong, independently generated passphrases, disciplined verification and layered security to reduce the impact of hidden implementation failures.
Anyone using a seed generated by affected firmware should treat it as compromised and migrate to a newly generated wallet immediately.
Anyone concerned about their setup or unsure whether they are practicing self-custody safely can contact The Bitcoin Way (nprofile…wmw0) for guidance, whether or not they are a client.
Never trust. Verify.
Proper self-custody remains the standard.
