Fascinated by the new prospects offered by Bitcoin in terms of freedom and individual sovereignty, I devote my time to exploring and testing innovations that enable everyone to appropriate this technology without any prior technical expertise. If I can do it, anyone can.
⚠️ URGENT SECURITY DISCLOSURE (July 2026) — Coldcard wallets are actively being drained. A firmware bug in the seed generation of Coldcard devices allows attackers to find your seed phrase without any action on your part. All Coldcard models are affected: Mk3, Mk4, Mk5, and Q. On July 30, 2026, roughly 594 BTC were stolen from about 500 wallets, and the attack is still ongoing. Only wallets generated with the dice roll method are considered safe, and only if you rolled at least 50 dice. If you don't know, don't remember, or aren't sure how your seed was generated, treat it as compromised and move your funds immediately to a wallet whose seed was not generated on a Coldcard. Follow Coinkite's official announcements. See our dedicated migration tutorial:
- Limits on magnitude**: cap the amount of bitcoins you can spend in a single transaction.
- Velocity limits:** decide how many transactions you can carry out per unit of time (per hour, day, week, etc.), requiring a minimum number of blocks between them.
- Pre-approved addresses:** Only allow bitcoins to be sent to pre-approved addresses.
- Two-factor authentication:** Requires confirmation from a third-party 2FA mobile application (TOTP RFC 6238) on an NFC-enabled smartphone/tablet with internet access.
- by signing with one of the backup keys and the seed hand, or 2 backup keys depending on the size of your Multisig.
- by entering the "Spending Policy Key" or "C Key" in the "Co-Sign" menu. The latter cannot be consulted directly on the device, otherwise anyone could cancel the spending conditions configured.
Configuring ColdCard Co-Sign
1- Activate functionality
- Mk4: v5.4.2
- Q: v1.3.2Q
-
Or press "ENTER " to generate a new seed sentence of 12 words.
-
Either click on "(1) " to import an existing 12-word seed, or choose "(2) " to import an existing 24-word seed.
-
Or press "(6) " to import a seed from your device's vault.
2- Choose the spending conditions or "spending policies"
3- Create Wallet Multisig 2-on-N
ccxp-0F056943.json.Co-Sign with Sparrow wallet
1- Export Wallet Multisig 2-sur-3 to Sparrow wallet
2- Testing predefined spending policies
Co-Sign with Nunchuk
1- Web 2FA & Whitelisted addresses
2- Export Wallet Multisig 2-on-3 to Nunchuk
3- Testing predefined spending policies
Author
This tutorial has been written by Louferlou
You can say thanks by tipping the professor.
Credits
This tutorial has not been proofread yet
The original content has been translated by AI, but human review is necessary to ensure its accuracy.
3 512 sats1 756 sats878 satsEvery content on the platform is the result of a collaborative effort: each lesson, translation, and revision is made possible by the work of contributors. For this reason, we are always looking for proofreaders who can review our content in many languages. If you want to participate in the proofreading process, please reach out in our Telegram group and read our tutorial. We remind you that this content is open-source - licensed under CC BY-SA - so it can be freely shared and used, as long as the original source is credited.







