How the bug works
" -> "Cách hoạt động của lỗi
" or "Cách lỗi hoạt động". We'll use "Cách thức hoạt động của lỗi". Paragraph: "The flaw disables secure random number generation on certain Coldcard models. Attackers don't need physical access to the device. If they can see a wallet address or an exported public key, they can test guesses against the predictable private key — derived from the serial number and clock — and steal the funds. The exploit is similar to the Ill Bloom attack that drained wallets via weak seed phrases earlier this year.
" Translation: "Lỗ hổng này vô hiệu hóa việc tạo số ngẫu nhiên an toàn trên một số mẫu Coldcard. Kẻ tấn công không cần truy cập vật lý vào thiết bị. Nếu chúng có thể nhìn thấy địa chỉ ví hoặc khóa công khai được xuất ra, chúng có thể thử nghiệm các phỏng đoán dựa trên khóa riêng tư có thể dự đoán được — được suy ra từ số sê-ri và đồng hồ — và đánh cắp tiền. Cách khai thác này tương tự như cuộc tấn công Ill Bloom đã rút sạch ví thông qua các cụm từ seed yếu hồi đầu năm nay.
" We kept "Ill Bloom" as is. "seed phrases" -> "cụm từ seed" (or "cụm từ khôi phục"? but we'll use "cụm từ seed"). Heading: "Who is affected
" -> "Ai bị ảnh hưởng
" Paragraph: "Only the Coldcard Mk3 is vulnerable, and only if it's running firmware version 4.0.1 or later. The Mk4, Q, and Mk5 models are not affected. Coinkite and Block are still assessing the full extent of the flaw across older firmware versions. The vulnerability also extends to paper wallets and seed backups that relied on the same broken random number generator.
" Translation: "Chỉ Coldcard Mk3 bị ảnh hưởng, và chỉ khi nó đang chạy phiên bản firmware 4.0.1 trở lên. Các mẫu Mk4, Q và Mk5 không bị ảnh hưởng. Coinkite và Block vẫn đang đánh giá mức độ đầy đủ của lỗ hổng trên các phiên bản firmware cũ hơn. Lỗ hổng này cũng mở rộng đến ví giấy và các bản sao lưu seed dựa trên cùng bộ tạo số ngẫu nhiên bị lỗi đó.
" Heading: "What users should do
" -> "Người dùng nên làm gì
" Paragraph: "Coinkite recommends generating a new seed on a device with the latest firmware and transferring all funds to the new wallet. A firmware update alone won't undo the damage — the old seed is already compromised. Users who added an extra passphrase to their seed face substantially lower risk, but Coinkite still advises moving funds as a precaution.
" Translation: "Coinkite khuyến cáo tạo một seed mới trên thiết bị có firmware mới nhất và chuyển toàn bộ tiền đến ví mới. Chỉ cập nhật firmware không thể khắc phục thiệt hại — seed cũ đã bị xâm phạm. Người dùng đã thêm cụm mật khẩu bổ sung vào seed của mình sẽ có rủi ro thấp hơn đáng kể, nhưng Coinkite vẫn khuyên nên chuyển tiền để phòng ngừa.
" Last paragraph: "The company is still working to determine how many devices and wallets were affected by the bug, which went undetected for years. For now, anyone with a Coldcard Mk3 that was updated after 2021 should treat their seed as exposed. The clock is ticking — and the attackers are still guessing.
" Translation: "Công ty vẫn đang làm việc để xác định có bao nhiêu thiết bị và ví bị ảnh hưởng bởi lỗi này, vốn không được phát hiện trong nhiều năm. Hiện tại, bất kỳ ai sở hữu Coldcard Mk3 được cập nhật sau năm 2021 nên coi seed của họ như đã bị lộ. Thời gian đang trôi qua — và kẻ tấn công vẫn đang




