Coinkite just released a security advisory warning that private keys generated on a Coldcard device may be vulnerable to attack due to a lower than expected number of random bits. Mk3, Mk4, Mk5, and Q models are all affected, with Mk3 most severely vulnerable.
How This Affects Unchained Vaults
An Unchained vault is most commonly composed of three total keys, including two client-controlled keys and the Unchained key. Unchained’s private key is not affected by this vulnerability.
If you generated private keys on Coldcard devices, the funds in your Unchained vault may be at risk of loss!
Note: Even if you subsequently transferred your private keys to Trezor, Ledger, or other devices, if you originally generated them on a Coldcard, they are still vulnerable.
What You Should Do
The actions we are requesting you to take will differ based on your situation.
If you generated 2 of 3 private keys on a Coldcard:
If you generated 1 of 3 private keys on a Coldcard
If you generated 1 of 3 private keys on a Coldcard then your funds are safe absent an additional security breach, but you should still replace your vulnerable key. Step-by-step instructions may be found in our knowledge base.
Replacing Your Hardware
If you are affected and need new hardware devices, they can be purchased online or at local retailers such as Best Buy. Note that simply transferring your existing private keys from vulnerable Coldcards to new devices does not fix the underlying vulnerability. New keys must be generated on new devices.
If you choose not to purchase new devices, you may choose instead to update your vulnerable Coldcard firmware to a new version that Coldcard has represented as fixing the bug and regenerating keys after this update. Unchained has not reviewed the firmware upgrade for sufficiency, so please refer to Coldcard's security update for further information.
If You Need Unchained to Co-Sign
If you need Unchained to co-sign a sweep transaction with you: please be aware that using Unchained’s signature alongside your own does not provide more security than signing the transaction entirely yourself (since all vulnerable Coldcard-derived public keys in a redeem script are exposed regardless of who signs). During this time, we have increased the cadence of our reviews and are working to process each request for Unchained’s key signature as quickly as possible, while maintaining appropriate diligence and control standards.
Why Multisig Matters
Multisig lets you use devices from multiple vendors so a newly-discovered vulnerability affecting only one does not by itself compromise your bitcoin. If you’re already a client, this is a great opportunity to help friends and family who may be exposed to risks like these.
DISCLAIMER: This article is provided for educational purposes only and has not been tailored to your specific circumstances. Please do your own research before taking any action or inaction based on the contents of this article.
.png)

