XKEYCHAINX LABS
Coldcard / Public disclosure

Coldcard: multisig change validation

Insufficient multisig script validation could allow tampered PSBT files to redirect transaction change. Coinkite credited researcher Dmitry Petukhov.

Source date: 19 DEC 2019Reviewed: 11 October 2026

Affected scope

Multisig transactions · Historical

What the attack requires

A maliciously altered multisig transaction file presented for signing.

Response & remediation

What changed

Fixed in firmware 3.0.6

What this finding establishes

Coinkite released the fix in version 3.0.6 and published additional disclosure detail in March 2020. The vendor reported no evidence of malicious exploitation. This record concerns multisig validation, not the separate 2026 seed-generation incident.