COLDCARD security disclosure history
coinkite-historical-disclosures
Latest reviewed change
source content difference between and
The page updated its coverage date to August 8, replaced the 'COLDCARD Security Advisory' heading with 'COLDCARD Security Status', rewrote the entropy issue description as a build-integration and symbol-resolution defect rather than an intentional fallback, and added upstream MicroPython and build-configuration sources.
-COLDCARD Security Advisory
-Seeds generated on firmware 4.0.1 (2021 or later) are at risk.
-Read advisory →
+COLDCARD Security Status
+Fixed firmware is available. Existing affected seeds still require migration.
+Check status →
Newsletter
Blog
First lines only. The complete diff is in the timeline below.
- Organisation
- Coinkite
- Evidence role
- Vendor publication index
- Published
- 2026-08-04
- Source changes
- 1
- Detected differences
- 1
- Unreviewed
- 0
- Copies held
- 2
Coinkite's own chronology of public security research, coordinated disclosures, paid private reviews, internal findings and advisories affecting COLDCARD, announced in the vendor's 4 August public-record post (coldcardwallet-2084731768632991801). At first capture it self-reports 23 security-relevant events from 2019 onward, 12 of them with public evidence of coordinated disclosure, with coverage stated through 4 August 2026.
The page states its own limits, and they are worth preserving: it presents itself as a chronology rather than a count of independent vulnerabilities or a product score, and its "no public evidence" label means none was found in the cited record rather than that nothing happened privately. Several entries cite private correspondence or paid review that this archive cannot inspect. Selection, classification and wording are the vendor's throughout, which is why it is held for dated revision comparison: what is added, reworded or dropped from a self-published disclosure history is itself the record.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The page updated its coverage date to August 8, replaced the 'COLDCARD Security Advisory' heading with 'COLDCARD Security Status', rewrote the entropy issue description as a build-integration and symbol-resolution defect rather than an intentional fallback, and added upstream MicroPython and build-configuration sources.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 17 lines
-COLDCARD Security Advisory -Seeds generated on firmware 4.0.1 (2021 or later) are at risk. -Read advisory → +COLDCARD Security Status +Fixed firmware is available. Existing affected seeds still require migration. +Check status → Newsletter Blog OpResearch professional reviews, internal findings, and security advisories affecting COLDCARD. It is a chronology, not a count of independent vulnerabilities or a product score. +For current product status and related company notices, start with the +Security & Transparency directory. To report a new security issue, follow our responsible disclosure process. Do not publish sensitive findings before we have had a reasonable opportunity 12 records with public evidence of coordinated disclosure 2019–2026 -coverage through August 4, 2026 +coverage through August 8, 2026 How to read this history “Coordinated” means the public record shows advance private reporting, an embargo, or explicit coordination. “Professional audit” identifies a July 30, 2026 Incident/advisory Seed-generation RNG weakness and theft incident -A random-byte fallback introduced during a library migration provided very weak entropy for device-generated seeds. Updating corrects future seed generation but does not repair an existing affected seed. +During the 2021 libNgU migration, the seed-generation path resolved rng_get() to MicroPython’s Yasmarang software PRNG implementation instead of COLDCARD’s intended board-specific hardware TRNG path. This was a build-integration and symbol-resolution defect, not an intentional runtime fallback: the hardware RNG did not fail and trigger a weaker source. Updating corrects future seed generation but does not repair an existing affected seed. +MicroPython added that software implementation upstream in May 2018 for general runtime use on boards without an enabled hardware RNG. It entered COLDCARD seed generation with the March 2021 libNgU migration. Block traces the implementation to the v4.0.0 source lineage. Coinkite did not release v4.0.0 publicly as a signed firmware binary; the first public signed release in that series was v4.0.1. The affected-user range therefore begins at v4.0.1. -Sources: Coinkite advisory, technical backgrounder, Block, and public binary archive. +Sources: Coinkite advisory, technical backgrounder, upstream MicroPython implementation, COLDCARD build configuration, libNgU guard, Block analysis, and public binary archive. Product or scope Mk2/Mk3 4.0.1–4.1.9; Mk4/Mk5 before 5.6.0 or Edge 6.6.0X; Q before 1.5.0Q or Edge 6.6.0QX Public status Seedplate Blockclock Support +Security & Transparency Responsible Disclosure Terms of Sale Terms of Use Home Blog OpResearch +Security & Transparency Careers Contact StoreExtracted text as captured
COLDCARD Security Status Fixed firmware is available. Existing affected seeds still require migration. Check status → Newsletter Blog OpResearch Careers Resellers Contact Store Security Disclosure History This page records public security research, coordinated disclosures, professional reviews, internal findings, and security advisories affecting COLDCARD. It is a chronology, not a count of independent vulnerabilities or a product score. For current product status and related company notices, start with the Security & Transparency directory. To report a new security issue, follow our responsible disclosure process. Do not publish sensitive findings before we have had a reasonable opportunity to investigate and protect users. 23 security-relevant events in this chronology 12 records with public evidence of coordinated disclosure 2019–2026 coverage through August 8, 2026 How to read this history “Coordinated” means the public record shows advance private reporting, an embargo, or explicit coordination. “Professional audit” identifies a paid private review. “Credited fix” means a release note names a reporter but does not establish the disclosure process. Later physical research may overlap earlier work. “No public evidence” means none was found in the cited record; it does not prove that something never happened privately. “AI” identifies an AI-generated check that was reviewed privately by Coinkite. Coordinated Credited fix Vendor/internal Cross-wallet OverlapExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
COLDCARD Security Advisory Seeds generated on firmware 4.0.1 (2021 or later) are at risk. Read advisory → Newsletter Blog OpResearch Careers Resellers Contact Store Security Disclosure History This page records public security research, coordinated disclosures, professional reviews, internal findings, and security advisories affecting COLDCARD. It is a chronology, not a count of independent vulnerabilities or a product score. To report a new security issue, follow our responsible disclosure process. Do not publish sensitive findings before we have had a reasonable opportunity to investigate and protect users. 23 security-relevant events in this chronology 12 records with public evidence of coordinated disclosure 2019–2026 coverage through August 4, 2026 How to read this history “Coordinated” means the public record shows advance private reporting, an embargo, or explicit coordination. “Professional audit” identifies a paid private review. “Credited fix” means a release note names a reporter but does not establish the disclosure process. Later physical research may overlap earlier work. “No public evidence” means none was found in the cited record; it does not prove that something never happened privately. “AI” identifies an AI-generated check that was reviewed privately by Coinkite. Coordinated Credited fix Vendor/internal Cross-wallet Overlap Incident/advisory AIExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.