Firmware releases
Which firmware, on which model, generated an affected seed. Exposure is fixed by the build that was running when the seed was created, not by what is installed today.
Exposure is bounded by the firmware that was running when the seed was generated, not by the device in front of you today. A COLDCARD updated to a hotfix release can still hold a seed created on an affected build, and a device left on an affected build matters only if a seed was generated on it. The first table gives the affected ranges by model; the second identifies the individual releases and commits that mark each boundary. R1 U2 The device and update record below preserves what the held sources say about version display, downloads and what a firmware update does and does not change.
Whether a seed is exposed depends on the firmware the device was running when that seed was generated, not on what is installed today. Block's published analysis places the affected path in every Mk2 and Mk3 release from v4.0.0 in March 2021 to v4.1.9 in June 2023, and in every published Mk4, Mk5 and Q release before the 31 July 2026 hotfixes. R3 Coinkite's advisory starts the Mk2 and Mk3 range one release later, at v4.0.1, on the stated ground that v4.0.0 was built and signed but never released publicly as a binary. Block, whose range begins at v4.0.0, calls the same build released firmware. Both positions are recorded here rather than resolved: they differ over whether that build reached the public, not over what it contained. R4 R5 V6 The captured release history describes the hotfixes as correcting the entropy bug at source; the signed binaries have not been reproduced or disassembled here. U7
| Model | Firmware at generation | Status | Candidate-space note |
|---|---|---|---|
| Mk1 | ≤ v3.0.6final Mk1 build, 19 Dec 2019 |
Not affected | nominal 128 or 256 bits |
| Predates the libngu migration. | |||
| Mk2 / Mk3 | ≤ v3.2.2up to 14 Jan 2021 |
Not affected | nominal 128 or 256 bits |
Block's analysis describes seed generation on these releases as calling ckcc.rng_bytes(), which reaches the STM32 TRNG directly, and dates the switch away from that path to the next published release, v4.0.0. |
|||
| Mk2 | v4.0.0 to v4.1.917 Mar 2021 to 26 Jun 2023Coinkite states v4.0.1 to v4.1.9 |
Affected | Block: 2^0 fixed state;<2^40.7 loose ceiling |
Block's analysis describes generation on this range as moved to ngu.random, with no secure-element reseed on this hardware at all. Mk2 never received a v5.x release. Coinkite's advisory names this model directly, stating that the issue "is present on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 inclusive"; that wording dates from its revision of 1 August 2026 at 18:35 UTC, before which the advisory named only the Mk3. Other models use different assumptions. |
|||
| Mk3 | v4.0.0 to v4.1.917 Mar 2021 to 26 Jun 2023Coinkite states v4.0.1 to v4.1.9 |
Affected | Block: 2^0 fixed state;<2^40.7 loose ceiling |
Coinkite described the entropy as approximately 40 bits; LLFOURN published a separate ~2^40.3 model. Firmware v4.1.9 remained the last published Mk3 release until v4.2.0 was published on 31 July 2026, after the advisory had described the platform as deprecated and a further release as conditional. The model register states each assumption. |
|||
| Mk4 | v5.0.0 to v5.5.114 Mar 2022 to 1 Jul 2026 |
Affected | ≤2^32 conditional scenario;<2^73.3 loose ceiling |
On the normal successful boot path, Block's analysis reports, rng_seeding() derives a value from secure-element output but carries at most 32 bits into libngu. Coinkite, LLFOURN and otaliptus publish different broader models. |
|||
| Mk5 | v5.5.0 to v5.5.15 Mar to 1 Jul 2026 |
Affected | ≤2^32 conditional scenario;<2^73.3 loose ceiling |
| The first repository release explicitly supporting Mk5 is v5.5.0. Both published pre-hotfix Mk5 releases are affected. Other models use different assumptions. | |||
| Q | v0.0.3Q to v1.4.1Q8 Feb 2024 to 1 Jul 2026 |
Affected | ≤2^32 conditional scenario;<2^73.3 loose ceiling |
| All Q builds recorded in the published release history before v1.5.0Q are affected, including the v1.0.0Q production release of 10 Mar 2024. Other models use different assumptions. | |||
| Mk2 / Mk3 | v4.2.0official Mk3 X update: 31 Jul 2026, 13:43 UTC |
Published fix | nominal 128 or 256 bits per the vendor release history |
| The release history describes a hotfix that corrects the entropy bug and allows new seed generation. Coinkite's advisory lists the fixed release as "Mk2/Mk3: version 4.2.0 or later" and describes "Fixed Mk2/Mk3 firmware version 4.2.0" as released. Before the advisory's revision of 1 August 2026 at 18:35 UTC it named only the Mk3, and the vendor downloads-page listing of 4.2.0 for "COLDCARD Mk3 and Mk2" was the only vendor evidence covering the Mk2. This archive has not reproduced the vendor build, installed it on either model or independently inspected the signed binary. | |||
| Mk4 / Mk5 | v5.6.0signed release: 31 Jul 2026, 05:18 UTC |
Published fix | nominal 128 or 256 bits per the vendor release history |
The signed-release record precedes the vendor's source release commit 3238f6f at 05:19 UTC. The advisory separately names Edge v6.6.0X; this project did not independently review the source commit, and neither published binary has been independently checked here. |
|||
| Q | v1.5.0Qsigned release: 31 Jul 2026, 05:17 UTC |
Published fix | nominal 128 or 256 bits per the vendor release history |
The signed-release record precedes the vendor's source release commit 3238f6f at 05:19 UTC. The advisory separately names Edge v6.6.0QX; this project did not independently review the source commit, and neither published binary has been independently checked here. |
|||
| OPENDIME | V3.0 r.Afirmware 2.2.0 | One-device test reported | user entropy incorporation reported for one unit |
| Foundation Devices co-founder and CEO Zach Herbert reports reconstructing the final private key from the exact user-provided test vector, USB serial and revealed nonce. Foundation sells competing hardware-wallet products. The test covers one unit, does not assess internal-nonce quality and was not independently reproduced here. | |||
| TAPSIGNER | All | Vendor-reported | not independently assessed here |
| Coinkite reports that TAPSIGNER is not affected because it uses a different codebase. Rob Hamilton notes that its closed source prevents first-hand verification and reports only preliminary evidence that it does not use the affected libngu path. | |||
| SATSCARD | All | Vendor-reported | not independently assessed here |
| Coinkite reports that SATSCARD is not affected because it uses a different codebase. This archive has not independently reviewed that codebase. | |||
For the named 31 July hotfixes, the captured release history describes a source-level fix. The signed release files are vendor-published, and this archive has not reproduced the builds or independently inspected the binaries.
Release boundary record
Purchase date does not determine exposure; the published build in use at generation does. The selected releases below identify the relevant boundaries from the per-model history files.
| Version | Released | Line | Status |
|---|---|---|---|
3.2.2 | 14 Jan 2021 | Mk2 / Mk3 | Last pre-regression release |
Block's analysis describes seeds generated on this and earlier releases as using ckcc.rng_bytes(), before the migration that created the affected path. | |||
b18723dddb6d751c39978e4364b56b2414f68b47named in Block's published analysis | 1 Mar 2021 | commit | Migration commit |
Not a release. Block's analysis describes this commit as moving wallet generation from ckcc.rng_bytes() to ngu.random.bytes(), where it combined with the pre-existing guard defect to create the affected path. | |||
4.0.0 | 17 Mar 2021 | Mk2 / Mk3 | First affectedCoinkite starts at v4.0.1 |
| Block's analysis describes the affected path as first appearing in this build, and the captured signed-release record lists the 17 Mar 2021 DFU image. | |||
5.0.0 | 14 Mar 2022 | Mk4 | Affected |
First Mk4 production firmware. Block's analysis describes this line as adding a boot-time rng_seeding() call whose secure reseed is limited to 32 bits. | |||
4.1.9 | 26 Jun 2023 | Mk2 / Mk3 | Affected |
| The last Mk3 firmware for three years, and affected. Superseded by 4.2.0 on 31 Jul 2026. | |||
0.0.3Q | 8 Feb 2024 | Q | Affected |
Earliest public Q build. Production 1.0.0Q follows 10 Mar 2024. | |||
5.5.0 / 1.4.0Q | 5 Mar 2026 | Mk4 / Mk5 / Q | Affected |
| The build the Mk5 shipped on when that hardware launched five days later. | |||
5.5.1 / 1.4.1Q | 1 Jul 2026 | Mk4 / Mk5 / Q | Last affected release |
| The last published affected release before disclosure. | |||
4.2.0 | 31 Jul 202613:43 UTC official Mk3 update | Mk2 / Mk3 | Published fix |
| The release history says this corrects the entropy bug and allows new seed generation. Coinkite's advisory names it for both models as "Mk2/Mk3: version 4.2.0 or later", wording it adopted on 1 August 2026 at 18:35 UTC, and the vendor downloads page lists it for Mk2 and Mk3. Installation on either model and the signed binary remain unexamined by this project. | |||
1.5.0Q | 31 Jul 202605:17 UTC, signed release | Q | Published fix |
The signed-release record identifies this Q hotfix. The vendor's source release commit 3238f6f follows at 05:19 UTC; this project did not independently review it, and no local build or disassembly of the shipped image was attempted. | |||
5.6.0 | 31 Jul 202605:18 UTC, signed release | Mk4 / Mk5 | Published fix |
The signed-release record identifies this Mk4/Mk5 hotfix. The vendor's source release commit 3238f6f follows at 05:19 UTC; this project did not independently review it, and the shipped image was not reproduced here. | |||
3238f6fd9977eed786012d0034a04d888c3263bbvendor source release commit | 31 Jul 202605:19 UTC | Mk4 / Mk5 / Q source | Vendor source fix |
| The vendor's commit message for this release states that entropy generation is corrected, and the captured release history describes the hotfix the same way. This project did not re-review the source change, which in any case says nothing about the contents of the earlier signed release files. | |||
6.6.0X / 6.6.0QX | 31 Jul 202616:54 UTC official X update | Mk4 / Mk5 / Q Edge | Vendor-reported fix |
| Coinkite names these exact Edge releases in its advisory and official update. Their binaries fall outside what this archive has examined. | |||
The captured release history in the vendor's own repository puts
4.0.0 on 17 March 2021 and describes it as "Major internal changes... all crypto and BIP39 related code replaced", the migration Block identifies as introducing the bug. 4.0.1 did not arrive until 29 March, and its changelog entry is about a different defect: "Fixes security issue in v4.0.0." The vendor's disclosure history identifies that one as a USB serial REPL left enabled in 4.0.0, unrelated to seed generation.
This page therefore carries two attributed answers rather than one settled boundary: Block's wider range, from its published analysis, and Coinkite's narrower one, from its captured advisory. What neither account establishes is distribution: the captured signed-release record shows the 4.0.0 image was built and signed, not how many devices ran it during the twelve days before 4.0.1 superseded it.
Coinkite has since stated its reason. Coinkite gave its reason in the security disclosure history it published on 4 August 2026: v4.0.0 was "built, signed, and tested internally, but its binary was never released publicly", making v4.0.1 the first public 4.x binary, so "the affected-user range therefore begins at v4.0.1". Block, whose range is v4.0.0 to v4.1.9, instead describes the affected path as first appearing "in released firmware v4.0.0 on March 17, 2021". The two accounts differ over whether that build reached the public rather than over what it contained. That narrows the disagreement considerably. Both parties place the affected generation path in the 17 March 2021 build; what they disagree about is whether that build was distributed. This archive holds no evidence either way on distribution, having already recorded that the signed-release record shows 4.0.0 was built and signed but not how many devices ran it. Coinkite's account rests on records only it holds, its own signing manifest among them, and Block's wording that the path "first appeared in released firmware v4.0.0" is not accompanied by distribution evidence either. Both are reported here; neither is adjudicated.
One piece of outside evidence bears on the same boundary from a different direction. Chain analysis published by Galaxy Research on 1 August 2026 reports that no coin drained in its first three sweep waves was created before roughly block 674,951 on 17 March 2021, which is the v4.0.0 release date rather than the 29 March v4.0.1 date, so it corroborates a March 2021 onset without settling which of the two releases marks the boundary. Galaxy's wording is "The vulnerable Coldcard firmware shipped on March 17, 2021 around block 674,951. Not one of the coins we have identified in Waves 1-3 taken was created before that block." Three limits belong with that.
History-Mk3.md contains no 5.x release at all. Its highest entry before the incident is v4.1.9, and the held capture now ends at the 4.2.0 hotfix, while v5.0.3 appears in the Mk4 history. Block's stated range of v4.0.0 to v4.1.9 matches the repository record. This does not change which published Mk3 builds are classified as affected, but v4.1.9 is the highest Mk3 version in that history.
Karma-X, a security firm publishing its own post-hotfix disclosure on 2 August, wrote that "Coinkite has stated Mk3 will not receive further firmware updates" and told Mk3 users to treat a passphrase as a stopgap and plan for migration. On 6 August it appended to that item: "UPDATE: Apparently Coinkite has issued a 4.2.0 for Mk2 and Mk3 after previously saying they wouldn't." No capture held here contains a vendor statement in those terms. What the held vendor states contain is the deprecation wording and the conditional undertaking above, and the release itself, which had been announced two days before the Karma-X post was published. R9 The bricking risk the vendor named before publishing, the reports of devices showing a BRICKED screen after the hotfix and Coinkite's answer to them are recorded on the migration page rather than here.
No firmware release after the 31 July hotfixes appears in the vendor's published change log or in any of the three per-model release histories, which were polled without change through 15 August 2026. V10 The COLDCARD account said on 6 August that readers can follow the next firmware updates on GitHub and that it is "focusing the next release and customer key migration", naming no version, model line or date. R11 On the fixed builds themselves, one X account with no stated affiliation reports instrumenting the Mk4 firmware where it reads the STM32 hardware RNG and observing eight hardware reads on 5.6.0 for the same 32 bytes that seed generation requests, which the poster presents as a real-device path test rather than a statistical one. That account is reported here; this project has not reproduced it, and it bears on one model and one release. R12
Three limits on the Galaxy block-boundary corroboration
an approximate height, coin-creation dates, and a twelve-day interval
The block height is Galaxy's own approximation. The finding is about when
coins were first received rather than about which firmware generated any
particular seed, and Galaxy separately records that it has "not utilized
compute to test whether the addresses we have identified as possible
victims were indeed generated with low entropy". And twelve days is too
narrow an interval for coin creation dates to separate 4.0.0
from 4.0.1, so an absence of earlier victim coins is
consistent with the 4.0.0 boundary rather than decisive
between the two. The wider range above follows Block's published
analysis, which dates the affected path to released firmware
4.0.0; this is corroboration of a March 2021 onset set
beside that account, not a replacement for it.
R13
Published device and update documentation
what the held captures state, and what they do not establish
The held captures support a record of version display and update documentation, not a model-by-model operating procedure.
The COLDCARD shows its firmware version in the device's own settings and
upgrade menus; the published release history records a "show firmware
version" display added to the Advanced/Tools menu and an
Upgrade Firmware item on the same branch. Menu labels differ
between models and firmware generations, and this archive holds no capture
of a per-model menu walkthrough and no screenshots of any device.
Coinkite publishes builds on its own downloads page, and this archive holds a capture of that page. At the 1 August 2026 capture it listed 4.2.0 for Mk3 and Mk2, 5.6.0 for Mk4 and Mk5, 1.5.0Q for Q, and 6.6.0X and 6.6.0QX for the Edge line; polls through 15 August 2026 record that page unchanged. The vendor's documentation describes the upgrade itself as copying the firmware file onto a MicroSD card. On verification the record is thinner still: the release history documents on-device verification of detached Bitcoin signature files under Advanced/Tools, which is a check for files the device exports rather than a published procedure for the firmware image, and no captured source held here sets out a step-by-step firmware-signature check, so this page does not print one.
Evidence on this page 14 items
- R1 Reported · contested
Coinkite's not-affected statements for OPENDIME, TAPSIGNER and SATSCARD, plus the reported one-device OPENDIME entropy-incorporation test
Source Coinkite backgrounder and Zach Herbert's captured OPENDIME test report; one unit tested and no independent reproduction here
Evidence → captured 1 Aug 2026
- U2 Unverified · contested
The entropy implementation and runtime behaviour of TAPSIGNER and SATSCARD
Source Coinkite reports separate codebases; those implementations were not independently available or reviewed here as of a 15 August 2026 recheck, in which every held source repeating the not-affected finding traces it to the vendor
Evidence → captured
- R3 Reported · contested
The affected release ranges, including the Mk2 and Mk3 range starting at v4.0.0, and the hotfix release dates
Source Block's engineering disclosure, which publishes v4.0.0 to v4.1.9 for Mk2 and Mk3 and production v5.0.0 onward for Mk4; the release dates come from held captures of the vendor ChangeLog, the three per-model release histories and the signed-release record
Evidence → captured 31 Jul 2026
- R4 Reported · contested
Coinkite's currently published Mk2 and Mk3 lower bound of v4.0.1, recorded alongside the ranges above rather than adopted as this site's boundary
Source Captured Mk3 advisory and entropy technical backgrounder, both stating 4.0.1 through 4.1.9; the earlier advisory state instead ran the issue through 5.0.3, so this wording has already been revised once
Evidence → captured 4 Aug 2026
- R5 Reported · contested
Coinkite's stated reason for the v4.0.1 lower bound, that v4.0.0 was built, signed and tested internally but never publicly released as a binary, and Block's contrary description of v4.0.0 as released firmware
Source Coinkite's security disclosure history of 4 August 2026, which sources the account to its own historical signing manifest and public binary archive, read against Block's engineering disclosure, which publishes v4.0.0 to v4.1.9 and dates the path to released firmware v4.0.0. Neither party publishes distribution figures, and this archive holds no independent evidence of how widely v4.0.0 was installed
Evidence → captured 5 Aug 2026
- V6 Verified · contested
Coinkite's advisory naming the Mk2 directly, in both the affected firmware range and the fixed 4.2.0 release, from its revision of 1 August 2026 at 18:35 UTC onward
Source Held captures of the Coinkite Mk3 advisory and entropy technical backgrounder taken at 18:44 UTC on 1 August 2026, diffed against the states held at 14:02 UTC the same day, in which the equivalent sentences named only the Mk3; earlier, the vendor downloads-page listing was the only vendor evidence covering the Mk2, and the published lower bound remains v4.0.1 for both models
Evidence → captured
- U7 Unverified · contested
Whether the vendor-published 4.2.0, 5.6.0, 1.5.0Q and Edge binaries exactly reproduce the source fixes described in the release history and provide the intended entropy at runtime
Source The signed release images had not been independently reproduced, compared with local builds or disassembled by this project as of a 15 August 2026 recheck; one third-party instrumented device test of 5.6.0 on Mk4 is reported further down and was not reproduced here
Evidence → captured
- V8 Verified · contested
The three published positions on a Mk2 and Mk3 fix in sequence: no fixed build named at 01:56 UTC on 31 July, a conditional undertaking to publish one final release at 07:30 UTC the same day, and 4.2.0 described as released in the states held from 1 August
Source Held captures of the Coinkite Mk3 advisory and the diffs between them: the 01:56 and 07:30 UTC states of 31 July recovered from the Internet Archive, this project's capture at 00:17 UTC on 1 August in which the deprecation and bricking-risk passage is removed, and the 18:44 UTC state that extends the wording to the Mk2
Evidence → captured 1 Aug 2026
- R9 Reported · contested
Karma-X's statement that Coinkite had said the Mk3 would receive no further firmware updates, and its 6 August update recording that 4.2.0 was issued for Mk2 and Mk3 after that
Source Karma-X post-hotfix disclosure, published 2 August 2026 and captured here on 4, 5 and 6 August, the last of which adds the update; no held vendor capture states in those terms that the line would receive no further updates, so the earlier position stands as Karma-X describes it
Evidence → captured 6 Aug 2026
- V10 Verified · contested
That no release later than the 31 July 2026 hotfixes appears in the vendor's published ChangeLog or in the Mk3, Mk4/Mk5 and Q release histories
Source Held captures of ChangeLog.md, History-Mk3.md, History-Mk.md and History-Q.md, each polled without a text change through 15 August 2026
Evidence → captured 7 Aug 2026
- R11 Reported · contested
Coinkite's statement that it is focusing on the next release and customer key migration
Source COLDCARD account post of 6 August 2026 at 19:45 UTC, captured here on 7 August; it names no version, model line or date, and no such release appears in the held release histories
Evidence → captured 7 Aug 2026
- R12 Reported · contested
The reported instrumented device test showing eight hardware-RNG reads for the seed request on Mk4 firmware 5.6.0
Source X post of 7 August 2026 by an account with no affiliation stated in the held capture; a single first-hand account of one device and one release, not reproduced here and not a check of the published binary against the source
Evidence → captured 7 Aug 2026
- R13 Reported · contested
Galaxy Research's statement that the vulnerable firmware shipped on 17 March 2021 around block 674,951 and that no coin drained in its first three waves was created before that block, carried as corroboration of a March 2021 onset and not as a finding about which release generated any seed
Source Galaxy Research's captured 1 August 2026 thread, in which the block height is its own approximation and which states that it has not tested whether the identified addresses were generated with low entropy; coin creation dates cannot separate releases twelve days apart
Evidence → captured
- R14 Reported · contested
The vendor-published firmware versions, upgrade and verification descriptions, and the statement that an update cannot repair an existing seed
Source Held captures of the COLDCARD downloads page and entropy FAQ, the vendor release histories, and the 31 July Mk3 advisory state recovered from the Internet Archive; no device menu path or firmware-signature procedure was independently exercised here
Evidence → captured