🚨@Coldcard MK3 PIN Replacement Attack🚨
— LazyNinja (@FreedomIsntSafe) March 31, 2021
I bypassed an MK3 security feature which prevented needing 100% trust in the SE, not serious by itself..
However, when paired with a second attack on the SE it allowed for seed extraction if an attacker steals your wallet
Video below👇 pic.twitter.com/ScofMMm3nW