My laptop was compromised through the rust supply chain attack thing (blake3 dependency). I'm revoking everything. Github tokens and is done and nothing malicious has been released.
Not affected:
- my commit signing credentials on github
- my nsec
You can actually keep using coldcard just generate new phrase on trusted device. Send the funds to the new phrase. Load the new phrase into coldcard. Check it works and then delete it from the other device.
You don't need to buy new hardware because of this.