COLDCARD vulnerability what happened, and what to do
Informational only, and this site never asks for your recovery words. details

Informational only. This is independent analysis and an evidence-backed explainer, not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite, Block, or any other party named here. Published estimates are attributed, and differing scenarios are kept separate with their assumptions. Act on your own judgement. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it. Deliberate recovery on independently verified offline equipment is a separate operation. Seed-word safety.

COLDCARD firmware changelog

cc-changelog

https://raw.githubusercontent.com/Coldcard/firmware/master/releases/ChangeLog.md

Organisation
Coinkite
Evidence role
Repository file
Published
continuously updated
Source changes
0
Detected differences
0
Unreviewed
0
Copies held
1

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked 2 Aug 2026, 00:57 UTC.

  1. Earliest copy held Current
    seen 1 Aug 2026, 00:17 UTC · Captured here text sha256 1ea3af585e992dc7942f8fb8 878 chars
    Extracted text as captured
    # Change Log
    This lists the changes in the most recent firmware, for each hardware platform.
    ## 2026-07-31 Hotfix Versions: 5.6.0 (Mk4, MK5) and 1.5.0Q (Q1) and 4.2.0 (Mk3)
    **Urgent hotfix to correct a limited entropy bug**
    Please regenerate seeds only with this new version of the firmware and any
    later updates from today onwards.
    **Mk3 users must regenerate any seeds** made on earlier versions
    as their entropy is critically low at just ~40 bits.
    On **Mk4, Mk5 and Q entropy** may be as low as ~72 bits. This is
    well below our target of 128 bits.
    Follow the steps listed in
    [our blog announcement](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/)
    to be safe, and please be careful not to cut corners or rush this process.
    # Release History
    - [`History-Q.md`](History-Q.md)
    - [`History-Mk.md` (Mk4 and Mk5)](History-Mk.md)
    - [`History-Mk3.md`](History-Mk3.md)
How to check this yourself

Each copy above is identified by the SHA-256 of its extracted text, shown beside it, and the diffs are plain unified diffs. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.