Received an email from Passport regarding enhanced entropy protocol due to the Coldcard issues.
Is this real?
See below…
Enhanced Entropy Protocol
The recent security incident involving COLDCARD has highlighted a critical vulnerability in legacy hardware entropy generation. Foundation is responding by implementing a new security standard for all Passport Prime users.
PROTOCOL V2.4
Download and review the updated entropy standards and hardware audit documentation.
ACTION REQUIRED
All Passport Prime users must verify their device status by August 11, 2026.
This is the part we would most like you to take away.
Scammers are always circling, but when something high profile happens they go into overdrive, because they know a lot of people are suddenly worried, confused and in a hurry. Assume anyone who contacts you out of the blue about your wallet is a scammer until proven otherwise.
To be completely clear about how we operate:
Foundation will never ask for your seed words, recovery phrase, private keys, passphrase or PIN. Not by email, not on the forum, not in a support ticket, not on a call. There is no situation in which we need them.
We will never ask you to type your recovery phrase into a website, a form, an app or a support tool.
We will never contact you unexpectedly about your wallet, and we will never ask you to move your funds.
We will never ask you to share your screen or install remote access software.
If someone is pressuring you to act quickly, telling you your funds are at risk and they can help, offering a “recovery service”, or asking you to verify your seed somewhere, stop and do nothing. That is the scam.
Be especially wary of direct messages, of people claiming to be Foundation or Coinkite staff, and of search results and sponsored links for wallet software and only download software from the official source.