The problem affects single-sig wallets generated by the ColdCard from March 2021 onwards.
Defenses include:
- Roll your own seed words offline
- Add entropy to seeds (dice)
- Use a passphrase (25th word)
- Use multi-vendor multisig
While it’s fine to change vendors, just changing vendors but sticking to single sig doesn’t protect you from future vulnerabilities like this being discovered.
The single, fastest, easiest mitigation is to roll a new seed with your own entropy and sweep your coins into it.

