COLDCARD MK3 ADVISORY — SEEDS AFTER FIRMWARE 4.0.1 AT RISK. MK4 / Q / MK5 CLEAR. COINKITE SELF-DISCLOSES.
The material fact: if you generated a seed on a Coldcard Mk3 running firmware 4.0.1 or later, Coinkite says your funds may be at risk. Mk4, Q, and Mk5 are unaffected on early analysis. Migration path published on the Coinkite blog. Move now.
Coinkite disclosed a Coldcard Mk3 seed-generation vulnerability at 10:50 PM ET. Not a panic story — a responsible-disclosure story. The advisory names the specific firmware line (post-4.0.1), specifies the unaffected devices (Mk4, Q, Mk5), and links a migration path so operators can move their stack tonight instead of after an exploit hits the wild. The Technologist read: this is what sovereignty-stack maturity looks like. The industry-standard hardware wallet vendor found a flaw in a legacy device line, published it on record with 42,800 views and climbing in the first four hours, and gave the operator class the tools to act. No soft-pedaling, no vendor-comms language, no "we take security seriously" boilerplate. Twenty-four hours ago the DOJ came for the defensive stack from the border side with the Tunick pre-admission prosecution. Tonight the hardware layer takes a hit from the disclosure side. Both surfaces prove the same operator point: sovereignty is a practice, not a purchase. You check firmware. You migrate seeds. You harden the border cadence. You don’t outsource the stack — you run it, and when the vendor does its job and tells you the stack broke, you move.
@COLDCARDwallet X · Mk3 Security Advisory · thu jul 30 · 10:50 PM ET · 42.8K views
MORE ON THE DEFENSIVE STACK
PRE-ADMISSION FELONY — DOJ CHARGES ATLANTA MAN 5 YEARS FOR WIPING HIS OWN GRAPHENEOS PIXEL AT CBP.
FOR YOUR SAFETY — POLICE UNION FLIPS ON CLARITY, STATE DEPT LAUNCHES "FREEDOM TECH" WITH PALANTIR AND ANDURIL.
YAZBECK CALLS SELF-CUSTODY A CIVIL LIBERTY — WRAPPERS "NOT BITCOIN".