Coldcard — FACT: Coinkite’s advisory identifies seeds generated on Mk2/Mk3 firmware 4.0.1–4.1.9, Mk4/Mk5 before 5.6.0 or Edge 6.6.0X, and Q before 1.5.0Q or Edge 6.6.0QX as potentially affected. Its risk qualification excludes seeds supplemented with at least 50 independent private dice rolls; it also cites a strong, unique BIP-39 passphrase as protection. One investigation includes Mk2/Mk3 4.0.0, so creation-time firmware provenance should be checked conservatively. The failure reportedly routed seed generation to a predictable software PRNG instead of fresh hardware entropy, allowing candidate seeds to be reconstructed and matched against funded Bitcoin addresses.
UNVERIFIED LOSS CLAIM: The 1,778 BTC across more than 8,600 addresses figure comes from secondary reporting. The evidence available here does not provide a reproducible address list establishing that every address was Coldcard-generated or that every movement was theft. Another published estimate cited 1,719 BTC with high confidence, while reporting cautioned that not every analyzed wallet had been confirmed as generated by vulnerable firmware. Treat 1,778 BTC/8,600 addresses as an attribution estimate—not an audited victim total.
Coldcard action: Inventory the model and firmware present when each seed was created, not merely today’s version. Treat every seed in scope—and all derived receive/change keys—as permanently untrusted. Updating firmware only fixes future behavior; it cannot inject entropy into an existing seed because all existing private keys remain deterministic descendants of that original secret. Generate an entirely new seed lineage on corrected firmware or another trusted device, verify recovery offline, send a test transaction, then sweep remaining funds promptly. Preserve non-secret device and transaction evidence, but never submit the seed to a diagnostic website.
SafePal — FACT and ASSESSMENT: SafePal reported exposure of 39,798 customers’ names, email and shipping addresses, phone numbers, and purchase details from orders placed March 2, 2025–April 11, 2026. It reported that seeds, private keys, wallet passwords, payment data, identity documents, wallets, and funds were not exposed. Therefore, direct wallet compromise is not established. The realistic risk is highly credible targeting: fake SafePal support, refunds, replacement devices, firmware updates, SMS/calls, and seed-verification requests. Shipping addresses plus purchase records also identify likely hardware-wallet owners, creating physical-theft or coercion risk, although no incidence rate is established. Customers should distrust all inbound SafePal contact, navigate manually to official channels, never disclose a seed or approve an unexplained transaction, reject unsolicited replacement hardware, secure email and mobile accounts with phishing-resistant MFA and carrier PINs, and brief household members against delivery or support impersonation.