COLDCARD vulnerability what happened, and what to do
Informational only, and this site never asks for your recovery words. details

Informational only. This is independent analysis and an evidence-backed explainer, not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite, Block, or any other party named here. Published estimates are attributed, and differing scenarios are kept separate with their assumptions. Act on your own judgement. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it. Deliberate recovery on independently verified offline equipment is a separate operation. Seed-word safety.

Entropy technical backgrounder

coinkite-backgrounder

https://blog.coinkite.com/entropy-technical-backgrounder/

Organisation
Coinkite
Evidence role
Vendor advisory
Published
2026-07-30
Source changes
2
Detected differences
2
Unreviewed
0
Copies held
3

Publisher-dated 30 July. Revised to add Mk4/Q/Mk5 scope and later the Mk3 4.2.0 fix; exact revision times are unresolved.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked 2 Aug 2026, 00:57 UTC.

  1. source content difference between 1 Aug 2026, 14:02 UTC and 1 Aug 2026, 18:44 UTC Current source content +11 -10

    Coinkite moved the backgrounder's update stamp to August 1, 2026 at 2:35 p.m. EDT and replaced Mk3 with Mk2 or Mk3 throughout: the affected firmware range became 'The affected Mk2 and Mk3 firmware range is 4.0.1 through 4.1.9', the seeded-PRNG analysis became 'On Mk2 and Mk3, the active PRNG was seeded primarily from device and timing state', the hotfix list became 'Version 4.2.0 for Mk2 and Mk3', and the migration steps and the pointer to the dedicated advisory were rewritten the same way.

    seen 1 Aug 2026, 18:44 UTC · Captured here text sha256 a69c0037655baa99da6b0f8b 9,137 chars
    What changed from the previous capture 21 lines
     Technical Deep Dive into the Entropy Issue
     Published Jul 30, 2026
     Categories: ckcc
    -Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated
    +Updated August 1, 2026 at 2:35 p.m. EDT: Funds controlled by seeds generated
     on affected firmware are at risk if the seed was created without at least 50
     independent, private dice rolls and the funded wallet is not protected by a
     strong, unique BIP-39 passphrase.
     passphrase reduces the immediate exposure, it does not repair an affected seed.
     Unless the independent dice-entropy exception applies, replace the seed and
     migrate as soon as practical.
    -If your seed was generated on a Mk3 running firmware 4.0.1 through 4.1.9
    +If your seed was generated on a Mk2 or Mk3 running firmware 4.0.1 through 4.1.9
     without at least 50 independent, private dice rolls:
    -Update the Mk3 to firmware version 4.2.0 or
    +Update the Mk2 or Mk3 to firmware version 4.2.0 or
     later before generating a replacement
     seed.
    -Generate a completely new seed on the updated Mk3.
    +Generate a completely new seed on the updated COLDCARD.
     Record and verify the new backup, wallet fingerprint, and a receive address.
     Send a small test transaction before moving the remaining funds.
     Keep the old backup until the migration is complete and confirmed.
    -Follow the dedicated Mk3 Security Advisory and migration
    +Follow the dedicated Mk2/Mk3 Security Advisory and migration
     instructions.
     Proceed calmly and verify every step.
     If you added at least 50 fair, independent, private dice rolls when originally
     submodule, Micropython). At the same time the carefully crafted
     TRNG code I wrote was being used, but just by chance, and only for
     less important things.
    -On Mk3, the active PRNG was seeded primarily from device and timing
    +On Mk2 and Mk3, the active PRNG was seeded primarily from device and timing
     state. Under our current attack assumptions, we estimate the effective
     search space at about 40 bits. This is a preliminary estimate and may
     change as analysis continues.
     It did not enter COLDCARD wallet seed generation until the
     libNgU migration in March
     2021.
    -The affected Mk3 firmware range is 4.0.1 through 4.1.9. Version 4.2.0 corrects
    -new seed generation. The eight-year figure therefore describes the age of the
    -upstream fallback code, not the duration of affected COLDCARD seed generation.
    +The affected Mk2 and Mk3 firmware range is 4.0.1 through 4.1.9. Version 4.2.0
    +corrects new seed generation. The eight-year figure therefore describes the
    +age of the upstream fallback code, not the duration of affected COLDCARD seed
    +generation.
     Existing review confirmed that the intended TRNG implementation was present in
     the firmware binary, but did not verify which rng_get() implementation the
     wallet seed-generation path actually reached across the two submodules. No
     Next Steps
     We have released emergency hotfixes for every affected model and release
     track:
    -Version 4.2.0 for Mk3
    +Version 4.2.0 for Mk2 and Mk3
     Standard version 5.6.0 for Mk4 and Mk5
     Standard version 1.5.0Q for Q
     Edge version 6.6.0X for Mk4 and Mk5, and Edge version 6.6.0QX for
    
    Extracted text as captured
    Blog
    Careers
    Contact
    RSS
    Email Newsletter
    Store
    ×
    Home
    Blog
    Careers
    Contact
    RSS
    Email Newsletter
    Store
    ← Back to posts
    Technical Deep Dive into the Entropy Issue
    Published Jul 30, 2026
    Categories: ckcc
    Updated August 1, 2026 at 2:35 p.m. EDT: Funds controlled by seeds generated
    on affected firmware are at risk if the seed was created without at least 50
    independent, private dice rolls and the funded wallet is not protected by a
    strong, unique BIP-39 passphrase.
    Fixed firmware is now available for every affected model and release track,
    including Edge firmware versions 6.6.0X for Mk4/Mk5 and 6.6.0QX for Q.
    What You Should Do
    The passphrase must be strong, unique, secret, and separate from the seed
    backup. A short, common, patterned, quoted, reused, exposed, or uncertain
    passphrase does not qualify; treat those funds as at risk. Even when a strong
    passphrase reduces the immediate exposure, it does not repair an affected seed.
    Unless the independent dice-entropy exception applies, replace the seed and
    migrate as soon as practical.
    If your seed was generated on a Mk2 or Mk3 running firmware 4.0.1 through 4.1.9
    without at least 50 independent, private dice rolls:
    Update the Mk2 or Mk3 to firmware version 4.2.0 or
    later before generating a replacement
    seed.
    Generate a completely new seed on the updated COLDCARD.
    Record and verify the new backup, wallet fingerprint, and a receive address.
    Send a small test transaction before moving the remaining funds.
    Keep the old backup until the migration is complete and confirmed.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between 1 Aug 2026, 00:17 UTC and 1 Aug 2026, 14:02 UTC source content +15 -3

    Coinkite replaced the backgrounder's fixed-firmware banner with an August 1 update stating that funds are at risk unless the seed was created with at least 50 independent private dice rolls and the wallet is protected by a strong, unique BIP-39 passphrase, added a paragraph qualifying what counts as such a passphrase, and added a sentence calling the reduced search space a direct security risk rather than a theoretical possibility for wallets meeting neither condition.

    seen 1 Aug 2026, 14:02 UTC · Captured here text sha256 3310bcbfacd5b249e13baec0 9,090 chars
    What changed from the previous capture 18 lines
     Technical Deep Dive into the Entropy Issue
     Published Jul 30, 2026
     Categories: ckcc
    -Updated July 31, 2026 at 12:39 p.m. EDT: Fixed firmware is now available
    -for every affected model and release track, including Edge firmware versions
    -6.6.0X for Mk4/Mk5 and 6.6.0QX for Q.
    +Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated
    +on affected firmware are at risk if the seed was created without at least 50
    +independent, private dice rolls and the funded wallet is not protected by a
    +strong, unique BIP-39 passphrase.
    +Fixed firmware is now available for every affected model and release track,
    +including Edge firmware versions 6.6.0X for Mk4/Mk5 and 6.6.0QX for Q.
     What You Should Do
    +The passphrase must be strong, unique, secret, and separate from the seed
    +backup. A short, common, patterned, quoted, reused, exposed, or uncertain
    +passphrase does not qualify; treat those funds as at risk. Even when a strong
    +passphrase reduces the immediate exposure, it does not repair an affected seed.
    +Unless the independent dice-entropy exception applies, replace the seed and
    +migrate as soon as practical.
     If your seed was generated on a Mk3 running firmware 4.0.1 through 4.1.9
     without at least 50 independent, private dice rolls:
     Update the Mk3 to firmware version 4.2.0 or
     security issues, and it did not find this bug or anything serious.
     Both attackers and defenders have the same AI tools, but today
     it did not help us, and only helped the bad guys.
    +For funded wallets with neither the independent dice entropy nor a strong,
    +unique BIP-39 passphrase described above, the reduced search space is a direct
    +security risk, not a theoretical possibility.
     Technical Background
     In 2021, we moved COLDCARD’s elliptic-curve operations to Bitcoin Core’s
     libsecp256k1, using the same implementation trusted by Bitcoin Core instead
    
    Extracted text as captured
    Blog
    Careers
    Contact
    RSS
    Email Newsletter
    Store
    ×
    Home
    Blog
    Careers
    Contact
    RSS
    Email Newsletter
    Store
    ← Back to posts
    Technical Deep Dive into the Entropy Issue
    Published Jul 30, 2026
    Categories: ckcc
    Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated
    on affected firmware are at risk if the seed was created without at least 50
    independent, private dice rolls and the funded wallet is not protected by a
    strong, unique BIP-39 passphrase.
    Fixed firmware is now available for every affected model and release track,
    including Edge firmware versions 6.6.0X for Mk4/Mk5 and 6.6.0QX for Q.
    What You Should Do
    The passphrase must be strong, unique, secret, and separate from the seed
    backup. A short, common, patterned, quoted, reused, exposed, or uncertain
    passphrase does not qualify; treat those funds as at risk. Even when a strong
    passphrase reduces the immediate exposure, it does not repair an affected seed.
    Unless the independent dice-entropy exception applies, replace the seed and
    migrate as soon as practical.
    If your seed was generated on a Mk3 running firmware 4.0.1 through 4.1.9
    without at least 50 independent, private dice rolls:
    Update the Mk3 to firmware version 4.2.0 or
    later before generating a replacement
    seed.
    Generate a completely new seed on the updated Mk3.
    Record and verify the new backup, wallet fingerprint, and a receive address.
    Send a small test transaction before moving the remaining funds.
    Keep the old backup until the migration is complete and confirmed.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. Earliest copy held
    seen 1 Aug 2026, 00:17 UTC · Captured here text sha256 544518f57e0285894bc1ac54 8,255 chars
    Extracted text as captured
    Blog
    Careers
    Contact
    RSS
    Email Newsletter
    Store
    ×
    Home
    Blog
    Careers
    Contact
    RSS
    Email Newsletter
    Store
    ← Back to posts
    Technical Deep Dive into the Entropy Issue
    Published Jul 30, 2026
    Categories: ckcc
    Updated July 31, 2026 at 12:39 p.m. EDT: Fixed firmware is now available
    for every affected model and release track, including Edge firmware versions
    6.6.0X for Mk4/Mk5 and 6.6.0QX for Q.
    What You Should Do
    If your seed was generated on a Mk3 running firmware 4.0.1 through 4.1.9
    without at least 50 independent, private dice rolls:
    Update the Mk3 to firmware version 4.2.0 or
    later before generating a replacement
    seed.
    Generate a completely new seed on the updated Mk3.
    Record and verify the new backup, wallet fingerprint, and a receive address.
    Send a small test transaction before moving the remaining funds.
    Keep the old backup until the migration is complete and confirmed.
    Follow the dedicated Mk3 Security Advisory and migration
    instructions.
    Proceed calmly and verify every step.
    If you added at least 50 fair, independent, private dice rolls when originally
    creating the seed, read the dice guidance in the advisory before migrating. We
    do not consider that seed at risk from this RNG issue alone.
    If your seed was generated on affected Mk4, Mk5, or Q firmware without at
    least 50 independent, private dice rolls:
    Upgrade to the fixed firmware for the release track you use before

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

Each copy above is identified by the SHA-256 of its extracted text, shown beside it, and the diffs are plain unified diffs. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.