XKEYCHAINX LABS
Coldcard / Public disclosure

Multisig wallet substitution

Failure to verify the device’s own xpub could substitute attacker-controlled keys.

Source date: 2021-02-09Reviewed: 11 October 2026

Affected scope

Firmware through 3.1.9

What the attack requires

Malicious wallet coordinator supplies a manipulated multisig registration.

Response & remediation

What changed

Firmware 3.2.1.

What this finding establishes

This wallet-registration finding is separate from the 2019 multisig change-validation bug.