COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Technical Updated 15 Aug 2026

Firmware releases

Which firmware, on which model, generated an affected seed. Exposure is fixed by the build that was running when the seed was created, not by what is installed today.

Exposure is bounded by the firmware that was running when the seed was generated, not by the device in front of you today. A COLDCARD updated to a hotfix release can still hold a seed created on an affected build, and a device left on an affected build matters only if a seed was generated on it. The first table gives the affected ranges by model; the second identifies the individual releases and commits that mark each boundary. R1 U2 The device and update record below preserves what the held sources say about version display, downloads and what a firmware update does and does not change.

Whether a seed is exposed depends on the firmware the device was running when that seed was generated, not on what is installed today. Block's published analysis places the affected path in every Mk2 and Mk3 release from v4.0.0 in March 2021 to v4.1.9 in June 2023, and in every published Mk4, Mk5 and Q release before the 31 July 2026 hotfixes. R3 Coinkite's advisory starts the Mk2 and Mk3 range one release later, at v4.0.1, on the stated ground that v4.0.0 was built and signed but never released publicly as a binary. Block, whose range begins at v4.0.0, calls the same build released firmware. Both positions are recorded here rather than resolved: they differ over whether that build reached the public, not over what it contained. R4 R5 V6 The captured release history describes the hotfixes as correcting the entropy bug at source; the signed binaries have not been reproduced or disassembled here. U7

Firmware generation status by model and release range
ModelFirmware at generation StatusCandidate-space note
Mk1≤ v3.0.6final Mk1 build, 19 Dec 2019 Not affectednominal 128 or 256 bits
Predates the libngu migration.
Mk2 / Mk3≤ v3.2.2up to 14 Jan 2021 Not affectednominal 128 or 256 bits
Block's analysis describes seed generation on these releases as calling ckcc.rng_bytes(), which reaches the STM32 TRNG directly, and dates the switch away from that path to the next published release, v4.0.0.
Mk2v4.0.0 to v4.1.917 Mar 2021 to 26 Jun 2023Coinkite states v4.0.1 to v4.1.9 AffectedBlock: 2^0 fixed state;
<2^40.7 loose ceiling
Block's analysis describes generation on this range as moved to ngu.random, with no secure-element reseed on this hardware at all. Mk2 never received a v5.x release. Coinkite's advisory names this model directly, stating that the issue "is present on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 inclusive"; that wording dates from its revision of 1 August 2026 at 18:35 UTC, before which the advisory named only the Mk3. Other models use different assumptions.
Mk3v4.0.0 to v4.1.917 Mar 2021 to 26 Jun 2023Coinkite states v4.0.1 to v4.1.9 AffectedBlock: 2^0 fixed state;
<2^40.7 loose ceiling
Coinkite described the entropy as approximately 40 bits; LLFOURN published a separate ~2^40.3 model. Firmware v4.1.9 remained the last published Mk3 release until v4.2.0 was published on 31 July 2026, after the advisory had described the platform as deprecated and a further release as conditional. The model register states each assumption.
Mk4v5.0.0 to v5.5.114 Mar 2022 to 1 Jul 2026 Affected≤2^32 conditional scenario;
<2^73.3 loose ceiling
On the normal successful boot path, Block's analysis reports, rng_seeding() derives a value from secure-element output but carries at most 32 bits into libngu. Coinkite, LLFOURN and otaliptus publish different broader models.
Mk5v5.5.0 to v5.5.15 Mar to 1 Jul 2026 Affected≤2^32 conditional scenario;
<2^73.3 loose ceiling
The first repository release explicitly supporting Mk5 is v5.5.0. Both published pre-hotfix Mk5 releases are affected. Other models use different assumptions.
Qv0.0.3Q to v1.4.1Q8 Feb 2024 to 1 Jul 2026 Affected≤2^32 conditional scenario;
<2^73.3 loose ceiling
All Q builds recorded in the published release history before v1.5.0Q are affected, including the v1.0.0Q production release of 10 Mar 2024. Other models use different assumptions.
Mk2 / Mk3v4.2.0official Mk3 X update: 31 Jul 2026, 13:43 UTC Published fixnominal 128 or 256 bits per the vendor release history
The release history describes a hotfix that corrects the entropy bug and allows new seed generation. Coinkite's advisory lists the fixed release as "Mk2/Mk3: version 4.2.0 or later" and describes "Fixed Mk2/Mk3 firmware version 4.2.0" as released. Before the advisory's revision of 1 August 2026 at 18:35 UTC it named only the Mk3, and the vendor downloads-page listing of 4.2.0 for "COLDCARD Mk3 and Mk2" was the only vendor evidence covering the Mk2. This archive has not reproduced the vendor build, installed it on either model or independently inspected the signed binary.
Mk4 / Mk5v5.6.0signed release: 31 Jul 2026, 05:18 UTC Published fixnominal 128 or 256 bits per the vendor release history
The signed-release record precedes the vendor's source release commit 3238f6f at 05:19 UTC. The advisory separately names Edge v6.6.0X; this project did not independently review the source commit, and neither published binary has been independently checked here.
Qv1.5.0Qsigned release: 31 Jul 2026, 05:17 UTC Published fixnominal 128 or 256 bits per the vendor release history
The signed-release record precedes the vendor's source release commit 3238f6f at 05:19 UTC. The advisory separately names Edge v6.6.0QX; this project did not independently review the source commit, and neither published binary has been independently checked here.
OPENDIMEV3.0 r.Afirmware 2.2.0 One-device test reporteduser entropy incorporation reported for one unit
Foundation Devices co-founder and CEO Zach Herbert reports reconstructing the final private key from the exact user-provided test vector, USB serial and revealed nonce. Foundation sells competing hardware-wallet products. The test covers one unit, does not assess internal-nonce quality and was not independently reproduced here.
TAPSIGNERAll Vendor-reportednot independently assessed here
Coinkite reports that TAPSIGNER is not affected because it uses a different codebase. Rob Hamilton notes that its closed source prevents first-hand verification and reports only preliminary evidence that it does not use the affected libngu path.
SATSCARDAll Vendor-reportednot independently assessed here
Coinkite reports that SATSCARD is not affected because it uses a different codebase. This archive has not independently reviewed that codebase.

For the named 31 July hotfixes, the captured release history describes a source-level fix. The signed release files are vendor-published, and this archive has not reproduced the builds or independently inspected the binaries.

Release boundary record

Purchase date does not determine exposure; the published build in use at generation does. The selected releases below identify the relevant boundaries from the per-model history files.

Selected firmware and source release boundaries
VersionReleasedLineStatus
3.2.214 Jan 2021Mk2 / Mk3Last pre-regression release
Block's analysis describes seeds generated on this and earlier releases as using ckcc.rng_bytes(), before the migration that created the affected path.
b18723dddb6d751c39978e4364b56b2414f68b47named in Block's published analysis1 Mar 2021commitMigration commit
Not a release. Block's analysis describes this commit as moving wallet generation from ckcc.rng_bytes() to ngu.random.bytes(), where it combined with the pre-existing guard defect to create the affected path.
4.0.017 Mar 2021Mk2 / Mk3First affectedCoinkite starts at v4.0.1
Block's analysis describes the affected path as first appearing in this build, and the captured signed-release record lists the 17 Mar 2021 DFU image.
5.0.014 Mar 2022Mk4Affected
First Mk4 production firmware. Block's analysis describes this line as adding a boot-time rng_seeding() call whose secure reseed is limited to 32 bits.
4.1.926 Jun 2023Mk2 / Mk3Affected
The last Mk3 firmware for three years, and affected. Superseded by 4.2.0 on 31 Jul 2026.
0.0.3Q8 Feb 2024QAffected
Earliest public Q build. Production 1.0.0Q follows 10 Mar 2024.
5.5.0 / 1.4.0Q5 Mar 2026Mk4 / Mk5 / QAffected
The build the Mk5 shipped on when that hardware launched five days later.
5.5.1 / 1.4.1Q1 Jul 2026Mk4 / Mk5 / QLast affected release
The last published affected release before disclosure.
4.2.031 Jul 202613:43 UTC official Mk3 updateMk2 / Mk3Published fix
The release history says this corrects the entropy bug and allows new seed generation. Coinkite's advisory names it for both models as "Mk2/Mk3: version 4.2.0 or later", wording it adopted on 1 August 2026 at 18:35 UTC, and the vendor downloads page lists it for Mk2 and Mk3. Installation on either model and the signed binary remain unexamined by this project.
1.5.0Q31 Jul 202605:17 UTC, signed releaseQPublished fix
The signed-release record identifies this Q hotfix. The vendor's source release commit 3238f6f follows at 05:19 UTC; this project did not independently review it, and no local build or disassembly of the shipped image was attempted.
5.6.031 Jul 202605:18 UTC, signed releaseMk4 / Mk5Published fix
The signed-release record identifies this Mk4/Mk5 hotfix. The vendor's source release commit 3238f6f follows at 05:19 UTC; this project did not independently review it, and the shipped image was not reproduced here.
3238f6fd9977eed786012d0034a04d888c3263bbvendor source release commit31 Jul 202605:19 UTCMk4 / Mk5 / Q sourceVendor source fix
The vendor's commit message for this release states that entropy generation is corrected, and the captured release history describes the hotfix the same way. This project did not re-review the source change, which in any case says nothing about the contents of the earlier signed release files.
6.6.0X / 6.6.0QX31 Jul 202616:54 UTC official X updateMk4 / Mk5 / Q EdgeVendor-reported fix
Coinkite names these exact Edge releases in its advisory and official update. Their binaries fall outside what this archive has examined.
5 yr 4 mo
Mk3 affected interval
v4.0.0 on 17 Mar 2021 to the Mk2/Mk3 fix the vendor names on 31 Jul 2026.
4 yr 4 mo
Mk4 exposure
v5.0.0 on 14 Mar 2022 to the Mk4 fix on 31 Jul 2026, covering every release through v5.5.1.
2 yr 5 mo
Q exposure
v0.0.3Q on 8 Feb 2024 to the Q fix on 31 Jul 2026, covering every recorded Q build through v1.4.1Q.
3 yr 1 mo
Mk3 release interval
Time between v4.1.9 and the 4.2.0 hotfix.
The vendor's range starts at v4.0.1; Block's starts at v4.0.0 Both the Mk3 advisory and the technical backgrounder, in the newest states held here as of 9 August 2026, give the affected range as "4.0.1 (March 2021) thru 4.1.9 (inclusive)". Bitcoin Optech repeated it, citing the advisory. Block's published analysis instead gives v4.0.0 to v4.1.9. The upper bound agrees on both sides; the lower one does not. Neither boundary is a slip: the advisory states 4.0.1 twice, and Block dates the affected path to "released firmware v4.0.0 on March 17, 2021". Coinkite has already revised this range once, from a first advisory state that ran the issue "through firmware version 5.0.3".

The captured release history in the vendor's own repository puts 4.0.0 on 17 March 2021 and describes it as "Major internal changes... all crypto and BIP39 related code replaced", the migration Block identifies as introducing the bug. 4.0.1 did not arrive until 29 March, and its changelog entry is about a different defect: "Fixes security issue in v4.0.0." The vendor's disclosure history identifies that one as a USB serial REPL left enabled in 4.0.0, unrelated to seed generation.

This page therefore carries two attributed answers rather than one settled boundary: Block's wider range, from its published analysis, and Coinkite's narrower one, from its captured advisory. What neither account establishes is distribution: the captured signed-release record shows the 4.0.0 image was built and signed, not how many devices ran it during the twelve days before 4.0.1 superseded it.

Coinkite has since stated its reason. Coinkite gave its reason in the security disclosure history it published on 4 August 2026: v4.0.0 was "built, signed, and tested internally, but its binary was never released publicly", making v4.0.1 the first public 4.x binary, so "the affected-user range therefore begins at v4.0.1". Block, whose range is v4.0.0 to v4.1.9, instead describes the affected path as first appearing "in released firmware v4.0.0 on March 17, 2021". The two accounts differ over whether that build reached the public rather than over what it contained. That narrows the disagreement considerably. Both parties place the affected generation path in the 17 March 2021 build; what they disagree about is whether that build was distributed. This archive holds no evidence either way on distribution, having already recorded that the signed-release record shows 4.0.0 was built and signed but not how many devices ran it. Coinkite's account rests on records only it holds, its own signing manifest among them, and Block's wording that the path "first appeared in released firmware v4.0.0" is not accompanied by distribution evidence either. Both are reported here; neither is adjudicated.

One piece of outside evidence bears on the same boundary from a different direction. Chain analysis published by Galaxy Research on 1 August 2026 reports that no coin drained in its first three sweep waves was created before roughly block 674,951 on 17 March 2021, which is the v4.0.0 release date rather than the 29 March v4.0.1 date, so it corroborates a March 2021 onset without settling which of the two releases marks the boundary. Galaxy's wording is "The vulnerable Coldcard firmware shipped on March 17, 2021 around block 674,951. Not one of the coins we have identified in Waves 1-3 taken was created before that block." Three limits belong with that.
A correction to the original advisory The 30 July Mk3 advisory described the affected range as running "through version 5.0.3, the final release that supported Mk3". That wording survives only in the 01:56 UTC state of 31 July recovered from the Internet Archive; this project's own capture of the advisory began on 1 August, by which point the sentence was gone. History-Mk3.md contains no 5.x release at all. Its highest entry before the incident is v4.1.9, and the held capture now ends at the 4.2.0 hotfix, while v5.0.3 appears in the Mk4 history. Block's stated range of v4.0.0 to v4.1.9 matches the repository record. This does not change which published Mk3 builds are classified as affected, but v4.1.9 is the highest Mk3 version in that history.
The Mk2 and Mk3 line: deprecated, then given a hotfix What the vendor published about whether the older line would be fixed at all changed twice in under two days, and the held states record each position. In the advisory state of 31 July at 01:56 UTC no fixed Mk3 build is named: it gives v5.0.3 as "the final release that supported Mk3" and offers Mk3-only users a BIP-39 passphrase or a dice-only seed entered on 4.1.9, with migration to an unaffected model as the outcome to work toward. By the 07:30 UTC state that morning a section headed "Investigation and Mk3 Firmware Status" says Coinkite is "exploring whether we can safely publish one final firmware release for the deprecated Mk3", that "updating this legacy platform carries a significant risk of bricking some units", and that it would publish one "only if we can validate a sufficiently safe upgrade path" — while telling users not to wait for it. Both of those states come from the Internet Archive. This project's own capture begins at 00:17 UTC on 1 August, by which point the official 13:43 UTC update of 31 July had announced 4.2.0, the conditional passage had been removed, and the advisory described the fixed release as made. The wording covering the Mk2 as well as the Mk3 followed at 18:35 UTC on 1 August. V8

Karma-X, a security firm publishing its own post-hotfix disclosure on 2 August, wrote that "Coinkite has stated Mk3 will not receive further firmware updates" and told Mk3 users to treat a passphrase as a stopgap and plan for migration. On 6 August it appended to that item: "UPDATE: Apparently Coinkite has issued a 4.2.0 for Mk2 and Mk3 after previously saying they wouldn't." No capture held here contains a vendor statement in those terms. What the held vendor states contain is the deprecation wording and the conditional undertaking above, and the release itself, which had been announced two days before the Karma-X post was published. R9 The bricking risk the vendor named before publishing, the reports of devices showing a BRICKED screen after the hotfix and Coinkite's answer to them are recorded on the migration page rather than here.

No firmware release after the 31 July hotfixes appears in the vendor's published change log or in any of the three per-model release histories, which were polled without change through 15 August 2026. V10 The COLDCARD account said on 6 August that readers can follow the next firmware updates on GitHub and that it is "focusing the next release and customer key migration", naming no version, model line or date. R11 On the fixed builds themselves, one X account with no stated affiliation reports instrumenting the Mk4 firmware where it reads the STM32 hardware RNG and observing eight hardware reads on 5.6.0 for the same 32 bytes that seed generation requests, which the poster presents as a real-device path test rather than a statistical one. That account is reported here; this project has not reproduced it, and it bears on one model and one release. R12

Three limits on the Galaxy block-boundary corroboration

an approximate height, coin-creation dates, and a twelve-day interval

The block height is Galaxy's own approximation. The finding is about when coins were first received rather than about which firmware generated any particular seed, and Galaxy separately records that it has "not utilized compute to test whether the addresses we have identified as possible victims were indeed generated with low entropy". And twelve days is too narrow an interval for coin creation dates to separate 4.0.0 from 4.0.1, so an absence of earlier victim coins is consistent with the 4.0.0 boundary rather than decisive between the two. The wider range above follows Block's published analysis, which dates the affected path to released firmware 4.0.0; this is corroboration of a March 2021 onset set beside that account, not a replacement for it. R13

Published device and update documentation

what the held captures state, and what they do not establish

The held captures support a record of version display and update documentation, not a model-by-model operating procedure.

The COLDCARD shows its firmware version in the device's own settings and upgrade menus; the published release history records a "show firmware version" display added to the Advanced/Tools menu and an Upgrade Firmware item on the same branch. Menu labels differ between models and firmware generations, and this archive holds no capture of a per-model menu walkthrough and no screenshots of any device.

Coinkite publishes builds on its own downloads page, and this archive holds a capture of that page. At the 1 August 2026 capture it listed 4.2.0 for Mk3 and Mk2, 5.6.0 for Mk4 and Mk5, 1.5.0Q for Q, and 6.6.0X and 6.6.0QX for the Edge line; polls through 15 August 2026 record that page unchanged. The vendor's documentation describes the upgrade itself as copying the firmware file onto a MicroSD card. On verification the record is thinner still: the release history documents on-device verification of detached Bitcoin signature files under Advanced/Tools, which is a check for files the device exports rather than a published procedure for the firmware image, and no captured source held here sets out a step-by-step firmware-signature check, so this page does not print one.

An update does not repair a seed Installing a hotfix changes what the device will generate next. It does not alter a seed that already exists. The 31 July advisory state put it directly: "An update cannot repair a seed that was already generated by affected firmware." A device on 4.2.0, 5.6.0 or 1.5.0Q with funds still controlled by a seed generated on an affected build therefore remains controlled by the same seed after the update. R14
Evidence on this page 14 items
  1. R1
    Reported

    Coinkite's not-affected statements for OPENDIME, TAPSIGNER and SATSCARD, plus the reported one-device OPENDIME entropy-incorporation test

    Source Coinkite backgrounder and Zach Herbert's captured OPENDIME test report; one unit tested and no independent reproduction here

  2. U2
    Unverified

    The entropy implementation and runtime behaviour of TAPSIGNER and SATSCARD

    Source Coinkite reports separate codebases; those implementations were not independently available or reviewed here as of a 15 August 2026 recheck, in which every held source repeating the not-affected finding traces it to the vendor

  3. R3
    Reported · contested

    The affected release ranges, including the Mk2 and Mk3 range starting at v4.0.0, and the hotfix release dates

    Source Block's engineering disclosure, which publishes v4.0.0 to v4.1.9 for Mk2 and Mk3 and production v5.0.0 onward for Mk4; the release dates come from held captures of the vendor ChangeLog, the three per-model release histories and the signed-release record

  4. R4
    Reported

    Coinkite's currently published Mk2 and Mk3 lower bound of v4.0.1, recorded alongside the ranges above rather than adopted as this site's boundary

    Source Captured Mk3 advisory and entropy technical backgrounder, both stating 4.0.1 through 4.1.9; the earlier advisory state instead ran the issue through 5.0.3, so this wording has already been revised once

  5. R5
    Reported · contested

    Coinkite's stated reason for the v4.0.1 lower bound, that v4.0.0 was built, signed and tested internally but never publicly released as a binary, and Block's contrary description of v4.0.0 as released firmware

    Source Coinkite's security disclosure history of 4 August 2026, which sources the account to its own historical signing manifest and public binary archive, read against Block's engineering disclosure, which publishes v4.0.0 to v4.1.9 and dates the path to released firmware v4.0.0. Neither party publishes distribution figures, and this archive holds no independent evidence of how widely v4.0.0 was installed

  6. V6
    Verified

    Coinkite's advisory naming the Mk2 directly, in both the affected firmware range and the fixed 4.2.0 release, from its revision of 1 August 2026 at 18:35 UTC onward

    Source Held captures of the Coinkite Mk3 advisory and entropy technical backgrounder taken at 18:44 UTC on 1 August 2026, diffed against the states held at 14:02 UTC the same day, in which the equivalent sentences named only the Mk3; earlier, the vendor downloads-page listing was the only vendor evidence covering the Mk2, and the published lower bound remains v4.0.1 for both models

  7. U7
    Unverified

    Whether the vendor-published 4.2.0, 5.6.0, 1.5.0Q and Edge binaries exactly reproduce the source fixes described in the release history and provide the intended entropy at runtime

    Source The signed release images had not been independently reproduced, compared with local builds or disassembled by this project as of a 15 August 2026 recheck; one third-party instrumented device test of 5.6.0 on Mk4 is reported further down and was not reproduced here

  8. V8
    Verified

    The three published positions on a Mk2 and Mk3 fix in sequence: no fixed build named at 01:56 UTC on 31 July, a conditional undertaking to publish one final release at 07:30 UTC the same day, and 4.2.0 described as released in the states held from 1 August

    Source Held captures of the Coinkite Mk3 advisory and the diffs between them: the 01:56 and 07:30 UTC states of 31 July recovered from the Internet Archive, this project's capture at 00:17 UTC on 1 August in which the deprecation and bricking-risk passage is removed, and the 18:44 UTC state that extends the wording to the Mk2

  9. R9
    Reported

    Karma-X's statement that Coinkite had said the Mk3 would receive no further firmware updates, and its 6 August update recording that 4.2.0 was issued for Mk2 and Mk3 after that

    Source Karma-X post-hotfix disclosure, published 2 August 2026 and captured here on 4, 5 and 6 August, the last of which adds the update; no held vendor capture states in those terms that the line would receive no further updates, so the earlier position stands as Karma-X describes it

  10. V10
    Verified

    That no release later than the 31 July 2026 hotfixes appears in the vendor's published ChangeLog or in the Mk3, Mk4/Mk5 and Q release histories

    Source Held captures of ChangeLog.md, History-Mk3.md, History-Mk.md and History-Q.md, each polled without a text change through 15 August 2026

  11. R11
    Reported

    Coinkite's statement that it is focusing on the next release and customer key migration

    Source COLDCARD account post of 6 August 2026 at 19:45 UTC, captured here on 7 August; it names no version, model line or date, and no such release appears in the held release histories

  12. R12
    Reported

    The reported instrumented device test showing eight hardware-RNG reads for the seed request on Mk4 firmware 5.6.0

    Source X post of 7 August 2026 by an account with no affiliation stated in the held capture; a single first-hand account of one device and one release, not reproduced here and not a check of the published binary against the source

  13. R13
    Reported

    Galaxy Research's statement that the vulnerable firmware shipped on 17 March 2021 around block 674,951 and that no coin drained in its first three waves was created before that block, carried as corroboration of a March 2021 onset and not as a finding about which release generated any seed

    Source Galaxy Research's captured 1 August 2026 thread, in which the block height is its own approximation and which states that it has not tested whether the identified addresses were generated with low entropy; coin creation dates cannot separate releases twelve days apart

  14. R14
    Reported

    The vendor-published firmware versions, upgrade and verification descriptions, and the statement that an update cannot repair an existing seed

    Source Held captures of the COLDCARD downloads page and entropy FAQ, the vendor release histories, and the 31 July Mk3 advisory state recovered from the Internet Archive; no device menu path or firmware-signature procedure was independently exercised here