How the bug works
" -> "बग कैसे काम करता है
" Paragraph: "The flaw disables secure random number generation on certain Coldcard models. Attackers don't need physical access to the device. If they can see a wallet address or an exported public key, they can test guesses against the predictable private key — derived from the serial number and clock — and steal the funds. The exploit is similar to the Ill Bloom attack that drained wallets via weak seed phrases earlier this year.
" Translation: "यह दोष कुछ Coldcard मॉडलों पर सुरक्षित रैंडम नंबर जनरेशन को अक्षम कर देता है। हमलावरों को डिवाइस तक भौतिक पहुंच की आवश्यकता नहीं होती है। यदि वे एक वॉलेट पता या निर्यात की गई सार्वजनिक कुंजी देख सकते हैं, तो वे अनुमानित निजी कुंजी — जो सीरियल नंबर और घड़ी से प्राप्त होती है — के खिलाफ अनुमानों का परीक्षण कर सकते हैं और फंड चुरा सकते हैं। यह शोषण इस साल की शुरुआत में कमजोर सीड वाक्यांशों के माध्यम से वॉलेट को खाली करने वाले Ill Bloom हमले के समान है।
" Note: "Ill Bloom" is a proper noun, keep as is. Next heading: "Who is affected
" -> "कौन प्रभावित है
" Paragraph: "Only the Coldcard Mk3 is vulnerable, and only if it's running firmware version 4.0.1 or later. The Mk4, Q, and Mk5 models are not affected. Coinkite and Block are still assessing the full extent of the flaw across older firmware versions. The vulnerability also extends to paper wallets and seed backups that relied on the same broken random number generator.
" Translation: "केवल Coldcard Mk3 कमजोर है, और केवल तभी जब यह फर्मवेयर संस्करण 4.0.1 या उसके बाद चला रहा हो। Mk4, Q, और Mk5 मॉडल प्रभावित नहीं हैं। Coinkite और Block अभी भी पुराने फर्मवेयर संस्करणों में दोष की पूरी सीमा का आकलन कर रहे हैं। यह कमजोरी उन पेपर वॉलेट और सीड बैकअप तक भी फैली हुई है जो उसी टूटे हुए रैंडम नंबर जनरेटर पर निर्भर थे।
" Note: "paper wallets" -> "पेपर वॉलेट", "seed backups" -> "सीड बैकअप". Next heading: "What users should do
" -> "उपयोगकर्ताओं को क्या करना चाहिए
" Paragraph: "Coinkite recommends generating a new seed on a device with the latest firmware and transferring all funds to the new wallet. A firmware update alone won't undo the damage — the old seed is already compromised. Users who added an extra passphrase to their seed face substantially lower risk, but Coinkite still advises moving funds as a precaution.
" Translation: "Coinkite नवीनतम फर्मवेयर वाले डिवाइस पर नया सीड जनरेट करने और सभी फंड नए वॉलेट में स्थानांतरित करने की सिफारिश करता है। अकेले फर्मवेयर अपडेट से नुकसान नहीं उलटेगा — पुराना सीड पहले ही समझौता हो चुका है। जिन उपयोगकर्ताओं ने अपने सीड में एक अतिरिक्त पासफ्रेज़ जोड़ा है, उन्हें काफी कम जोखिम का सामना करना पड़ता है, लेकिन Coinkite फिर भी सावधानी के रूप में फंड स्थानांतरित करने की सलाह देता है।
" Next paragraph: "The company is still working to determine how many devices and wallets were affected by the bug, which went undetected for years. For now, anyone with a Coldcard Mk3 that was updated after 2021 should




