Entropy technical backgrounder
coinkite-backgrounder
- Organisation
- Coinkite
- Evidence role
- Vendor advisory
- Published
- 2026-07-30
- Source changes
- 2
- Detected differences
- 2
- Unreviewed
- 0
- Copies held
- 3
Publisher-dated 30 July. Revised to add Mk4/Q/Mk5 scope and later the Mk3 4.2.0 fix; exact revision times are unresolved.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked 2 Aug 2026, 00:57 UTC.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain victim addresses. Integrity hashes, capture times and reviewed change summaries remain available below.
-
Coinkite moved the backgrounder's update stamp to August 1, 2026 at 2:35 p.m. EDT and replaced Mk3 with Mk2 or Mk3 throughout: the affected firmware range became 'The affected Mk2 and Mk3 firmware range is 4.0.1 through 4.1.9', the seeded-PRNG analysis became 'On Mk2 and Mk3, the active PRNG was seeded primarily from device and timing state', the hotfix list became 'Version 4.2.0 for Mk2 and Mk3', and the migration steps and the pointer to the dedicated advisory were rewritten the same way.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 21 lines
Technical Deep Dive into the Entropy Issue Published Jul 30, 2026 Categories: ckcc -Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated +Updated August 1, 2026 at 2:35 p.m. EDT: Funds controlled by seeds generated on affected firmware are at risk if the seed was created without at least 50 independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase. passphrase reduces the immediate exposure, it does not repair an affected seed. Unless the independent dice-entropy exception applies, replace the seed and migrate as soon as practical. -If your seed was generated on a Mk3 running firmware 4.0.1 through 4.1.9 +If your seed was generated on a Mk2 or Mk3 running firmware 4.0.1 through 4.1.9 without at least 50 independent, private dice rolls: -Update the Mk3 to firmware version 4.2.0 or +Update the Mk2 or Mk3 to firmware version 4.2.0 or later before generating a replacement seed. -Generate a completely new seed on the updated Mk3. +Generate a completely new seed on the updated COLDCARD. Record and verify the new backup, wallet fingerprint, and a receive address. Send a small test transaction before moving the remaining funds. Keep the old backup until the migration is complete and confirmed. -Follow the dedicated Mk3 Security Advisory and migration +Follow the dedicated Mk2/Mk3 Security Advisory and migration instructions. Proceed calmly and verify every step. If you added at least 50 fair, independent, private dice rolls when originally submodule, Micropython). At the same time the carefully crafted TRNG code I wrote was being used, but just by chance, and only for less important things. -On Mk3, the active PRNG was seeded primarily from device and timing +On Mk2 and Mk3, the active PRNG was seeded primarily from device and timing state. Under our current attack assumptions, we estimate the effective search space at about 40 bits. This is a preliminary estimate and may change as analysis continues. It did not enter COLDCARD wallet seed generation until the libNgU migration in March 2021. -The affected Mk3 firmware range is 4.0.1 through 4.1.9. Version 4.2.0 corrects -new seed generation. The eight-year figure therefore describes the age of the -upstream fallback code, not the duration of affected COLDCARD seed generation. +The affected Mk2 and Mk3 firmware range is 4.0.1 through 4.1.9. Version 4.2.0 +corrects new seed generation. The eight-year figure therefore describes the +age of the upstream fallback code, not the duration of affected COLDCARD seed +generation. Existing review confirmed that the intended TRNG implementation was present in the firmware binary, but did not verify which rng_get() implementation the wallet seed-generation path actually reached across the two submodules. No Next Steps We have released emergency hotfixes for every affected model and release track: -Version 4.2.0 for Mk3 +Version 4.2.0 for Mk2 and Mk3 Standard version 5.6.0 for Mk4 and Mk5 Standard version 1.5.0Q for Q Edge version 6.6.0X for Mk4 and Mk5, and Edge version 6.6.0QX forExtracted text as captured
Blog Careers Contact RSS Email Newsletter Store × Home Blog Careers Contact RSS Email Newsletter Store ← Back to posts Technical Deep Dive into the Entropy Issue Published Jul 30, 2026 Categories: ckcc Updated August 1, 2026 at 2:35 p.m. EDT: Funds controlled by seeds generated on affected firmware are at risk if the seed was created without at least 50 independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase. Fixed firmware is now available for every affected model and release track, including Edge firmware versions 6.6.0X for Mk4/Mk5 and 6.6.0QX for Q. What You Should Do The passphrase must be strong, unique, secret, and separate from the seed backup. A short, common, patterned, quoted, reused, exposed, or uncertain passphrase does not qualify; treat those funds as at risk. Even when a strong passphrase reduces the immediate exposure, it does not repair an affected seed. Unless the independent dice-entropy exception applies, replace the seed and migrate as soon as practical. If your seed was generated on a Mk2 or Mk3 running firmware 4.0.1 through 4.1.9 without at least 50 independent, private dice rolls: Update the Mk2 or Mk3 to firmware version 4.2.0 or later before generating a replacement seed. Generate a completely new seed on the updated COLDCARD. Record and verify the new backup, wallet fingerprint, and a receive address. Send a small test transaction before moving the remaining funds. Keep the old backup until the migration is complete and confirmed.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Coinkite replaced the backgrounder's fixed-firmware banner with an August 1 update stating that funds are at risk unless the seed was created with at least 50 independent private dice rolls and the wallet is protected by a strong, unique BIP-39 passphrase, added a paragraph qualifying what counts as such a passphrase, and added a sentence calling the reduced search space a direct security risk rather than a theoretical possibility for wallets meeting neither condition.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 18 lines
Technical Deep Dive into the Entropy Issue Published Jul 30, 2026 Categories: ckcc -Updated July 31, 2026 at 12:39 p.m. EDT: Fixed firmware is now available -for every affected model and release track, including Edge firmware versions -6.6.0X for Mk4/Mk5 and 6.6.0QX for Q. +Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated +on affected firmware are at risk if the seed was created without at least 50 +independent, private dice rolls and the funded wallet is not protected by a +strong, unique BIP-39 passphrase. +Fixed firmware is now available for every affected model and release track, +including Edge firmware versions 6.6.0X for Mk4/Mk5 and 6.6.0QX for Q. What You Should Do +The passphrase must be strong, unique, secret, and separate from the seed +backup. A short, common, patterned, quoted, reused, exposed, or uncertain +passphrase does not qualify; treat those funds as at risk. Even when a strong +passphrase reduces the immediate exposure, it does not repair an affected seed. +Unless the independent dice-entropy exception applies, replace the seed and +migrate as soon as practical. If your seed was generated on a Mk3 running firmware 4.0.1 through 4.1.9 without at least 50 independent, private dice rolls: Update the Mk3 to firmware version 4.2.0 or security issues, and it did not find this bug or anything serious. Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys. +For funded wallets with neither the independent dice entropy nor a strong, +unique BIP-39 passphrase described above, the reduced search space is a direct +security risk, not a theoretical possibility. Technical Background In 2021, we moved COLDCARD’s elliptic-curve operations to Bitcoin Core’s libsecp256k1, using the same implementation trusted by Bitcoin Core insteadExtracted text as captured
Blog Careers Contact RSS Email Newsletter Store × Home Blog Careers Contact RSS Email Newsletter Store ← Back to posts Technical Deep Dive into the Entropy Issue Published Jul 30, 2026 Categories: ckcc Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated on affected firmware are at risk if the seed was created without at least 50 independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase. Fixed firmware is now available for every affected model and release track, including Edge firmware versions 6.6.0X for Mk4/Mk5 and 6.6.0QX for Q. What You Should Do The passphrase must be strong, unique, secret, and separate from the seed backup. A short, common, patterned, quoted, reused, exposed, or uncertain passphrase does not qualify; treat those funds as at risk. Even when a strong passphrase reduces the immediate exposure, it does not repair an affected seed. Unless the independent dice-entropy exception applies, replace the seed and migrate as soon as practical. If your seed was generated on a Mk3 running firmware 4.0.1 through 4.1.9 without at least 50 independent, private dice rolls: Update the Mk3 to firmware version 4.2.0 or later before generating a replacement seed. Generate a completely new seed on the updated Mk3. Record and verify the new backup, wallet fingerprint, and a receive address. Send a small test transaction before moving the remaining funds. Keep the old backup until the migration is complete and confirmed.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
Blog Careers Contact RSS Email Newsletter Store × Home Blog Careers Contact RSS Email Newsletter Store ← Back to posts Technical Deep Dive into the Entropy Issue Published Jul 30, 2026 Categories: ckcc Updated July 31, 2026 at 12:39 p.m. EDT: Fixed firmware is now available for every affected model and release track, including Edge firmware versions 6.6.0X for Mk4/Mk5 and 6.6.0QX for Q. What You Should Do If your seed was generated on a Mk3 running firmware 4.0.1 through 4.1.9 without at least 50 independent, private dice rolls: Update the Mk3 to firmware version 4.2.0 or later before generating a replacement seed. Generate a completely new seed on the updated Mk3. Record and verify the new backup, wallet fingerprint, and a receive address. Send a small test transaction before moving the remaining funds. Keep the old backup until the migration is complete and confirmed. Follow the dedicated Mk3 Security Advisory and migration instructions. Proceed calmly and verify every step. If you added at least 50 fair, independent, private dice rolls when originally creating the seed, read the dice guidance in the advisory before migrating. We do not consider that seed at risk from this RNG issue alone. If your seed was generated on affected Mk4, Mk5, or Q firmware without at least 50 independent, private dice rolls: Upgrade to the fixed firmware for the release track you use beforeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
Each copy above is identified by the SHA-256 of its extracted text, shown beside it, and the diffs are plain unified diffs. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
The SHA-256 prefixes above identify each held copy without turning this page into a mirror of somebody else's post. Compare a quotation against the original. If the post has since been edited or deleted, ask and the held copy can be produced.