COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

COLDCARD security disclosure history

coinkite-historical-disclosures

https://coinkite.com/historical-disclosures

Latest reviewed change

source content difference between and

The page updated its coverage date to August 8, replaced the 'COLDCARD Security Advisory' heading with 'COLDCARD Security Status', rewrote the entropy issue description as a build-integration and symbol-resolution defect rather than an intentional fallback, and added upstream MicroPython and build-configuration sources.

seen +11 -6 full history below
-COLDCARD Security Advisory
-Seeds generated on firmware 4.0.1 (2021 or later) are at risk.
-Read advisory →
+COLDCARD Security Status
+Fixed firmware is available. Existing affected seeds still require migration.
+Check status →
 Newsletter
 Blog

First lines only. The complete diff is in the timeline below.

Organisation
Coinkite
Evidence role
Vendor publication index
Published
2026-08-04
Source changes
1
Detected differences
1
Unreviewed
0
Copies held
2

Coinkite's own chronology of public security research, coordinated disclosures, paid private reviews, internal findings and advisories affecting COLDCARD, announced in the vendor's 4 August public-record post (coldcardwallet-2084731768632991801). At first capture it self-reports 23 security-relevant events from 2019 onward, 12 of them with public evidence of coordinated disclosure, with coverage stated through 4 August 2026.

The page states its own limits, and they are worth preserving: it presents itself as a chronology rather than a count of independent vulnerabilities or a product score, and its "no public evidence" label means none was found in the cited record rather than that nothing happened privately. Several entries cite private correspondence or paid review that this archive cannot inspect. Selection, classification and wording are the vendor's throughout, which is why it is held for dated revision comparison: what is added, reworded or dropped from a self-published disclosure history is itself the record.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +11 -6

    The page updated its coverage date to August 8, replaced the 'COLDCARD Security Advisory' heading with 'COLDCARD Security Status', rewrote the entropy issue description as a build-integration and symbol-resolution defect rather than an intentional fallback, and added upstream MicroPython and build-configuration sources.

    seen · Captured here 19,244 chars
    What changed from the previous capture 17 lines
    -COLDCARD Security Advisory
    -Seeds generated on firmware 4.0.1 (2021 or later) are at risk.
    -Read advisory →
    +COLDCARD Security Status
    +Fixed firmware is available. Existing affected seeds still require migration.
    +Check status →
     Newsletter
     Blog
     OpResearch
     professional reviews, internal findings, and security advisories affecting
     COLDCARD. It is a chronology, not a count of independent vulnerabilities
     or a product score.
    +For current product status and related company notices, start with the
    +Security & Transparency directory.
     To report a new security issue, follow our
     responsible disclosure process.
     Do not publish sensitive findings before we have had a reasonable opportunity
     12
     records with public evidence of coordinated disclosure
     2019–2026
    -coverage through August 4, 2026
    +coverage through August 8, 2026
     How to read this history
     “Coordinated” means the public record shows advance private reporting,
     an embargo, or explicit coordination. “Professional audit” identifies a
     July 30, 2026
     Incident/advisory
     Seed-generation RNG weakness and theft incident
    -A random-byte fallback introduced during a library migration provided very weak entropy for device-generated seeds. Updating corrects future seed generation but does not repair an existing affected seed.
    +During the 2021 libNgU migration, the seed-generation path resolved rng_get() to MicroPython’s Yasmarang software PRNG implementation instead of COLDCARD’s intended board-specific hardware TRNG path. This was a build-integration and symbol-resolution defect, not an intentional runtime fallback: the hardware RNG did not fail and trigger a weaker source. Updating corrects future seed generation but does not repair an existing affected seed.
    +MicroPython added that software implementation upstream in May 2018 for general runtime use on boards without an enabled hardware RNG. It entered COLDCARD seed generation with the March 2021 libNgU migration.
     Block traces the implementation to the v4.0.0 source lineage. Coinkite did not release v4.0.0 publicly as a signed firmware binary; the first public signed release in that series was v4.0.1. The affected-user range therefore begins at v4.0.1.
    -Sources: Coinkite advisory, technical backgrounder, Block, and public binary archive.
    +Sources: Coinkite advisory, technical backgrounder, upstream MicroPython implementation, COLDCARD build configuration, libNgU guard, Block analysis, and public binary archive.
     Product or scope
     Mk2/Mk3 4.0.1–4.1.9; Mk4/Mk5 before 5.6.0 or Edge 6.6.0X; Q before 1.5.0Q or Edge 6.6.0QX
     Public status
     Seedplate
     Blockclock
     Support
    +Security & Transparency
     Responsible Disclosure
     Terms of Sale
     Terms of Use
     Home
     Blog
     OpResearch
    +Security & Transparency
     Careers
     Contact
     Store
    
    Extracted text as captured
    COLDCARD Security Status
    Fixed firmware is available. Existing affected seeds still require migration.
    Check status →
    Newsletter
    Blog
    OpResearch
    Careers
    Resellers
    Contact
    Store
    Security Disclosure History
    This page records public security research, coordinated disclosures,
    professional reviews, internal findings, and security advisories affecting
    COLDCARD. It is a chronology, not a count of independent vulnerabilities
    or a product score.
    For current product status and related company notices, start with the
    Security & Transparency directory.
    To report a new security issue, follow our
    responsible disclosure process.
    Do not publish sensitive findings before we have had a reasonable opportunity
    to investigate and protect users.
    23
    security-relevant events in this chronology
    12
    records with public evidence of coordinated disclosure
    2019–2026
    coverage through August 8, 2026
    How to read this history
    “Coordinated” means the public record shows advance private reporting,
    an embargo, or explicit coordination. “Professional audit” identifies a
    paid private review. “Credited fix” means a release note names a reporter
    but does not establish the disclosure process. Later physical research may
    overlap earlier work. “No public evidence” means none was found in the cited
    record; it does not prove that something never happened privately. “AI”
    identifies an AI-generated check that was reviewed privately by Coinkite.
    Coordinated
    Credited fix
    Vendor/internal
    Cross-wallet
    Overlap

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. Earliest copy held
    seen · Captured here 18,540 chars
    Extracted text as captured
    COLDCARD Security Advisory
    Seeds generated on firmware 4.0.1 (2021 or later) are at risk.
    Read advisory →
    Newsletter
    Blog
    OpResearch
    Careers
    Resellers
    Contact
    Store
    Security Disclosure History
    This page records public security research, coordinated disclosures,
    professional reviews, internal findings, and security advisories affecting
    COLDCARD. It is a chronology, not a count of independent vulnerabilities
    or a product score.
    To report a new security issue, follow our
    responsible disclosure process.
    Do not publish sensitive findings before we have had a reasonable opportunity
    to investigate and protect users.
    23
    security-relevant events in this chronology
    12
    records with public evidence of coordinated disclosure
    2019–2026
    coverage through August 4, 2026
    How to read this history
    “Coordinated” means the public record shows advance private reporting,
    an embargo, or explicit coordination. “Professional audit” identifies a
    paid private review. “Credited fix” means a release note names a reporter
    but does not establish the disclosure process. Later physical research may
    overlap earlier work. “No public evidence” means none was found in the cited
    record; it does not prove that something never happened privately. “AI”
    identifies an AI-generated check that was reviewed privately by Coinkite.
    Coordinated
    Credited fix
    Vendor/internal
    Cross-wallet
    Overlap
    Incident/advisory
    AI

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.