Mk3 security advisory
coinkite-mk3-advisory
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
- Organisation
- Coinkite
- Evidence role
- Vendor advisory
- Published
- 2026-07-30
- Source changes
- 4
- Detected differences
- 4
- Unreviewed
- 0
- Copies held
- 5
The original narrow advisory. Stated Mk4/Q/Mk5 'not affected based on our early analysis'.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked 2 Aug 2026, 00:57 UTC.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain victim addresses. Integrity hashes, capture times and reviewed change summaries remain available below.
-
Fourth recorded revision of the advisory, and the one that resolves the Mk2 question this archive had tracked as open. The update stamp moved to August 1, 2026 at 2:35 p.m. EDT and every Mk3-only statement about the defect and its fix now names both models: the fixed-firmware list reads 'Mk2/Mk3: version 4.2.0 or later', the affected range reads 'The issue is present on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 inclusive', the at-risk sentence covers 'a seed generated on Mk2 or Mk3 version 4.0.1 (March 2021) through 4.1.9', and the release is described as 'Fixed Mk2/Mk3 firmware version 4.2.0' from the 'official Mk2/Mk3 download page'. The one-device migration section, the optional dice-only section and the closing migration steps were rewritten from Mk3-only to Mk2-or-Mk3 wording. Until this revision the vendor downloads-page listing was the only vendor evidence placing the Mk2 in the affected range or the hotfix. The published lower bound is unchanged at 4.0.1 for both models, so the v4.0.0 divergence recorded on the firmware page is untouched.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 59 lines
Coldcard Security Advisory Published Jul 30, 2026 Categories: ckcc -Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated +Updated August 1, 2026 at 2:35 p.m. EDT: Funds controlled by seeds generated on affected firmware are at risk if the seed was created without at least 50 independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase. Fixed firmware is now available for every affected model and release track: -Mk3: version 4.2.0 or later +Mk2/Mk3: version 4.2.0 or later Mk4/Mk5 standard: version 5.6.0 or later Q standard: version 1.5.0Q or later Mk4/Mk5 Edge: version 6.6.0X or later fixed merely because its version number is higher than the standard release. Do not generate a new seed on any of these models until the update is installed. -Funds controlled by a seed generated on Mk3 version 4.0.1 (March 2021) -through 4.1.9 inclusive are at risk if the seed was created without at least 50 -fair, independent, private dice rolls and the funded wallet is not protected by -a strong, unique BIP-39 passphrase. +Funds controlled by a seed generated on Mk2 or Mk3 version 4.0.1 (March +2021) through 4.1.9 inclusive are at risk if the seed was created without at +least 50 fair, independent, private dice rolls and the funded wallet is not +protected by a strong, unique BIP-39 passphrase. Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits. Updating the firmware does not change or repair an existing seed. If your seed repair the affected seed; passphrase users should also migrate as soon as practical. TAPSIGNER, OPENDIME and SATSCARD are not affected by this bug as they are different codebases -The issue is present on Mk3 firmware versions 4.0.1 through 4.1.9 +The issue is present on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 inclusive. It also affects seeds generated on Mk4 and Mk5 before standard version 5.6.0 or Edge version 6.6.0X, and on Q before standard version 1.5.0Q or Edge version 6.6.0QX. The impact on Mk4, Mk5 uncertain which words you used, how many rolls you entered, or whether the rolls were private, migrate to a new seed. Investigation and Firmware Status -Fixed Mk3 firmware version 4.2.0 has been released. Install it from the -official Mk3 download page before generating a replacement seed. +Fixed Mk2/Mk3 firmware version 4.2.0 has been released. Install it from the +official Mk2/Mk3 download page before generating a replacement seed. Version 4.2.0 corrects new seed generation. It cannot repair a seed that was already generated by affected firmware. This advisory reflects our early analysis. Our investigation is ongoing, passphrase, migrate to a newly generated seed as soon as practical. Continue to protect the passphrase and do not enter it into a website or an untrusted device. -If the Mk3 Is Your Only Device -Firmware 4.2.0 allows the Mk3 to generate a replacement seed correctly. You do -not need a newer COLDCARD to complete the migration. Updating does not repair -the affected seed already stored on the device. -Using one Mk3 for both wallets requires carefully switching between the old and -new seeds. If a second device with fixed firmware is available, use it instead. -If the Mk3 is your only device: +If the Mk2 or Mk3 Is Your Only Device +Firmware 4.2.0 allows the Mk2 and Mk3 to generate a replacement seed correctly. +You do not need a newer COLDCARD to complete the migration. Updating does not +repair the affected seed already stored on the device. +Using one Mk2 or Mk3 for both wallets requires carefully switching between the +old and new seeds. If a second device with fixed firmware is available, use it +instead. If the Mk2 or Mk3 is your only device: Verify the written backup and wallet fingerprint of the affected seed. Install firmware 4.2.0 or later and -confirm the version on the Mk3. -On an empty Mk3, generate a new seed. Record and verify its backup, wallet -fingerprint, and a receive address. +confirm the version on the device. +On an empty Mk2 or Mk3, generate a new seed. Record and verify its backup, +wallet fingerprint, and a receive address. Restore the affected seed and send a small test transaction to the verified address. Restore the new seed and confirm that its fingerprint matches and the test optional and are not required to address this issue. A BIP-39 passphrase is a separate wallet-security choice; if used, back it up exactly and separately from the seed words. -Optional Dice-Only Seed on Mk3 +Optional Dice-Only Seed on Mk2 or Mk3 After updating to version 4.2.0, users who are confident in their ability to perform and verify a dice-only migration can create a replacement seed without using the device’s random-number generator. This is optional; the normal New Wallet flow is corrected in version 4.2.0. -On an empty Mk3 running 4.2.0, select Import Existing > Dice Rolls and enter -at least 99 independent rolls of a fair six-sided die. This dedicated dice-only -path hashes the roll sequence directly; it does not use the device’s generator. +On an empty Mk2 or Mk3 running 4.2.0, select Import Existing > Dice Rolls and +enter at least 99 independent rolls of a fair six-sided die. This dedicated +dice-only path hashes the roll sequence directly; it does not use the device’s +generator. This is an advanced procedure. A one-device migration requires safely alternating between the old and new seeds. Before erasing either seed from -the Mk3, verify its written backup and XFP. Verify a receive address for the +the device, verify its written backup and XFP. Verify a receive address for the dice-generated wallet, restore and verify the original wallet, and send a small test transaction before moving the remainder. Keep the original backup until the entire migration is confirmed. When migrating to a new key, calm and care should be applied. Rushing a wallet migration can create a more immediate risk than the issue you are trying to address. -Seeds generated on Mk3 versions 4.0.1 through 4.1.9; Mk4 and Mk5 before +Seeds generated on Mk2 or Mk3 versions 4.0.1 through 4.1.9; Mk4 and Mk5 before standard version 5.6.0 or Edge version 6.6.0X; or Q before standard version 1.5.0Q or Edge version 6.6.0QX are affected unless the independent dice-entropy -exception applies. Before generating a replacement seed, update Mk3 to version -4.2.0 or later; Mk4 and Mk5 to standard version 5.6.0 or later, or Edge version -6.6.0X or later; or Q to standard version 1.5.0Q or later, or Edge version -6.6.0QX or later: +exception applies. Before generating a replacement seed, update Mk2 or Mk3 to +version 4.2.0 or later; Mk4 and Mk5 to standard version 5.6.0 or later, or Edge +version 6.6.0X or later; or Q to standard version 1.5.0Q or later, or Edge +version 6.6.0QX or later: Confirm the fixed firmware version is installed. Generate a new seed on the updated COLDCARD. Record and verify its backup before depositing funds.Extracted text as captured
Blog Careers Contact RSS Email Newsletter Store × Home Blog Careers Contact RSS Email Newsletter Store ← Back to posts Coldcard Security Advisory Published Jul 30, 2026 Categories: ckcc Updated August 1, 2026 at 2:35 p.m. EDT: Funds controlled by seeds generated on affected firmware are at risk if the seed was created without at least 50 independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase. Fixed firmware is now available for every affected model and release track: Mk2/Mk3: version 4.2.0 or later Mk4/Mk5 standard: version 5.6.0 or later Q standard: version 1.5.0Q or later Mk4/Mk5 Edge: version 6.6.0X or later Q Edge: version 6.6.0QX or later Standard and Edge are separate release tracks. If you use Edge, install the fixed Edge release for your model. Do not assume an older Edge 6.x release is fixed merely because its version number is higher than the standard release. Do not generate a new seed on any of these models until the update is installed. Funds controlled by a seed generated on Mk2 or Mk3 version 4.0.1 (March 2021) through 4.1.9 inclusive are at risk if the seed was created without at least 50 fair, independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase. Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits. Updating the firmware does not change or repair an existing seed. If your seedExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Third recorded revision of the advisory. It now carries 'Updated August 1, 2026 at 9:35 a.m. EDT' and replaces the blanket warning that Mk3 4.0.1 to 4.1.9 users' funds 'may be at risk' with a conditional statement that funds are at risk unless the seed was created with at least 50 fair, independent, private dice rolls and the wallet is protected by a strong, unique BIP-39 passphrase. The passphrase section changed in both directions: it now states that reduced seed entropy alone is not enough to reach a passphrase wallet, and separately that a strong passphrase does not repair the seed, that passphrase users should also migrate, and that an uncertain passphrase means treating funds as at risk and migrating immediately.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 29 lines
Coldcard Security Advisory Published Jul 30, 2026 Categories: ckcc -Updated July 31, 2026 at 12:39 p.m. EDT: Fixed firmware is now available -for every affected model and release track: +Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated +on affected firmware are at risk if the seed was created without at least 50 +independent, private dice rolls and the funded wallet is not protected by a +strong, unique BIP-39 passphrase. +Fixed firmware is now available for every affected model and release track: Mk3: version 4.2.0 or later Mk4/Mk5 standard: version 5.6.0 or later Q standard: version 1.5.0Q or later fixed merely because its version number is higher than the standard release. Do not generate a new seed on any of these models until the update is installed. -Coinkite is warning all users who -generated a seed using a Mk3 on version 4.0.1 (March 2021) thru 4.1.9 (inclusive) -that their funds may be at risk. +Funds controlled by a seed generated on Mk3 version 4.0.1 (March 2021) +through 4.1.9 inclusive are at risk if the seed was created without at least 50 +fair, independent, private dice rolls and the funded wallet is not protected by +a strong, unique BIP-39 passphrase. Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits. Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies -to you. +to you. A strong passphrase reduces the immediate exposure, but it does not +repair the affected seed; passphrase users should also migrate as soon as +practical. TAPSIGNER, OPENDIME and SATSCARD are not affected by this bug as they are different codebases The issue is present on Mk3 firmware versions 4.0.1 through 4.1.9 inclusive. It also affects seeds generated This advisory reflects our early analysis. Our investigation is ongoing, and a formal technical review will be released as soon as possible. If You Used a Passphrase -If the affected Mk3 seed was used with a strong, unique BIP-39 passphrase, that -passphrase adds an independent barrier. The risk depends on the strength of the -passphrase: a short, common, patterned, quoted, or reused passphrase may be -guessable and should not be assumed to provide minimal risk. +If the affected seed was used with a strong, unique BIP-39 passphrase, that +passphrase adds an independent barrier. The reduced seed entropy alone is not +enough to reach funds in that passphrase wallet; an attacker must also discover +the passphrase. +A short, common, patterned, quoted, or reused passphrase may be guessable. If +that describes your passphrase, or you are uncertain about its strength, treat +the funds as at risk and migrate immediately. This means a BIP-39 passphrase, not the COLDCARD PIN. Even with a strong passphrase, migrate to a newly generated seed as soon as practical. Continue to protect the passphrase and do not enter it into a website or an untrustedExtracted text as captured
Blog Careers Contact RSS Email Newsletter Store × Home Blog Careers Contact RSS Email Newsletter Store ← Back to posts Coldcard Security Advisory Published Jul 30, 2026 Categories: ckcc Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated on affected firmware are at risk if the seed was created without at least 50 independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase. Fixed firmware is now available for every affected model and release track: Mk3: version 4.2.0 or later Mk4/Mk5 standard: version 5.6.0 or later Q standard: version 1.5.0Q or later Mk4/Mk5 Edge: version 6.6.0X or later Q Edge: version 6.6.0QX or later Standard and Edge are separate release tracks. If you use Edge, install the fixed Edge release for your model. Do not assume an older Edge 6.x release is fixed merely because its version number is higher than the standard release. Do not generate a new seed on any of these models until the update is installed. Funds controlled by a seed generated on Mk3 version 4.0.1 (March 2021) through 4.1.9 inclusive are at risk if the seed was created without at least 50 fair, independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase. Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits. Updating the firmware does not change or repair an existing seed. If your seedExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Coinkite announced fixed firmware for every affected model and release track, including Mk3 4.2.0, and rewrote the one-device migration guidance.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 119 lines
Email Newsletter Store ← Back to posts -Mk3 Security Advisory +Coldcard Security Advisory Published Jul 30, 2026 Categories: ckcc -Out of an abundance of caution, Coinkite is warning all users who -generated a seed using a Mk3 on version 4.0.1 (March 2021) or any -subsequent version that their funds may be at risk. +Updated July 31, 2026 at 12:39 p.m. EDT: Fixed firmware is now available +for every affected model and release track: +Mk3: version 4.2.0 or later +Mk4/Mk5 standard: version 5.6.0 or later +Q standard: version 1.5.0Q or later +Mk4/Mk5 Edge: version 6.6.0X or later +Q Edge: version 6.6.0QX or later +Standard and Edge are separate release tracks. If you use Edge, install the +fixed Edge release for your model. Do not assume an older Edge 6.x release is +fixed merely because its version number is higher than the standard release. +Do not generate a new seed on any +of these models until the update is installed. +Coinkite is warning all users who +generated a seed using a Mk3 on version 4.0.1 (March 2021) thru 4.1.9 (inclusive) +that their funds may be at risk. Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits. +Updating the firmware does not change or repair an existing seed. If your seed +was generated before the fixed firmware version for your model, follow the +migration guidance below unless the independent dice-entropy exception applies +to you. TAPSIGNER, OPENDIME and SATSCARD are not affected by this bug as they are different codebases -The issue is present on every Mk3 firmware version since -4.0.1. It also affects seeds generated on -Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on -Mk4, Mk5 and Q is not as severe but is still serious. +The issue is present on Mk3 firmware versions 4.0.1 through 4.1.9 +inclusive. It also affects seeds generated +on Mk4 and Mk5 before standard version 5.6.0 or Edge version 6.6.0X, and on Q +before standard version 1.5.0Q or Edge version 6.6.0QX. The impact on Mk4, Mk5 +and Q is not as severe but is still serious. If You Added Dice When Creating the Seed This issue affects the device-generated entropy. It does not remove independent entropy that you supplied with dice. This applies to the final seed words shown after the dice were added. If you are uncertain which words you used, how many rolls you entered, or whether the rolls were private, migrate to a new seed. -Investigation and Mk3 Firmware Status +Investigation and Firmware Status +Fixed Mk3 firmware version 4.2.0 has been released. Install it from the +official Mk3 download page before generating a replacement seed. +Version 4.2.0 corrects new seed generation. It cannot repair a seed that +was already generated by affected firmware. This advisory reflects our early analysis. Our investigation is ongoing, and a formal technical review will be released as soon as possible. -We are also exploring whether we can safely publish one final firmware -release for the deprecated Mk3. Updating this legacy platform carries a -significant risk of bricking some units, so we will publish it only if we -can validate a sufficiently safe upgrade path. -If the migration guidance applies to your seed, do not wait for a possible -firmware release before protecting your funds. An update cannot repair a seed -that was already generated by affected firmware. If You Used a Passphrase If the affected Mk3 seed was used with a strong, unique BIP-39 passphrase, that passphrase adds an independent barrier. The risk depends on the strength of the passphrase, migrate to a newly generated seed as soon as practical. Continue to protect the passphrase and do not enter it into a website or an untrusted device. -If the Mk3 Is Your Only Option -If you cannot immediately move to an unaffected device, create a strong, -unique BIP-39 passphrase on the Mk3 and move the funds from the original -wallet to the new passphrase-protected wallet. Treat this as an interim -measure until you can migrate to a new seed generated on an unaffected -device. -Proceed calmly and carefully: -Read the COLDCARD BIP-39 passphrase -instructions before starting. -On the Mk3, select Passphrase and enter a long, random, unique -passphrase. Do not use a quotation, familiar phrase, name, or reused -password. Do not enter the passphrase on a computer, phone, or website. -Back up the passphrase exactly and separately from the seed words. Losing -it means losing access to the funds. -Select APPLY and record the new wallet’s eight-digit fingerprint -(XFP). -Power the Mk3 off, turn it back on, re-enter the passphrase, and confirm -that the same XFP appears before using the new wallet. -Export the new passphrase wallet to your coordinator and verify its -receive address on the Mk3 screen. -Power-cycle the Mk3 and sign in without applying the passphrase to return -to the original wallet. Send a small test transaction to the verified -address. Re-enter the passphrase and confirm the test funds arrived -before moving the remainder. -Every passphrase, including one with a typo, creates a different valid -wallet. Verify the XFP every time before sending funds. -Advanced Fallback: Dice-Only Seed on Mk3 -If the Mk3 is your only available device and you are confident in your ability -to perform and verify a dice-only migration, you can create a replacement seed -without using its random-number generator. This is not required when generating -a new seed on fixed Mk4, Mk5 or Q firmware. -On an empty Mk3 running 4.1.9, select Import Existing > Dice Rolls and enter +If the Mk3 Is Your Only Device +Firmware 4.2.0 allows the Mk3 to generate a replacement seed correctly. You do +not need a newer COLDCARD to complete the migration. Updating does not repair +the affected seed already stored on the device. +Using one Mk3 for both wallets requires carefully switching between the old and +new seeds. If a second device with fixed firmware is available, use it instead. +If the Mk3 is your only device: +Verify the written backup and wallet fingerprint of the affected seed. +Install firmware 4.2.0 or later and +confirm the version on the Mk3. +On an empty Mk3, generate a new seed. Record and verify its backup, wallet +fingerprint, and a receive address. +Restore the affected seed and send a small test transaction to the verified +address. +Restore the new seed and confirm that its fingerprint matches and the test +funds arrived. +Restore the affected seed and move the remaining funds. +Restore the new seed and confirm the migration. Keep the old backup until +the complete balance has arrived and is confirmed. +The fixed firmware’s device-generated seed is sufficient. Dice rolls are +optional and are not required to address this issue. A BIP-39 passphrase is a +separate wallet-security choice; if used, back it up exactly and separately +from the seed words. +Optional Dice-Only Seed on Mk3 +After updating to version 4.2.0, users who are confident in their ability to +perform and verify a dice-only migration can create a replacement seed without +using the device’s random-number generator. This is optional; the normal New +Wallet flow is corrected in version 4.2.0. +On an empty Mk3 running 4.2.0, select Import Existing > Dice Rolls and enter at least 99 independent rolls of a fair six-sided die. This dedicated dice-only path hashes the roll sequence directly; it does not use the device’s generator. -Do not use the normal New Wallet flow if your goal is to exclude the device -generator. This is an advanced procedure. A one-device migration requires safely alternating between the old and new seeds. Before erasing either seed from the Mk3, verify its written backup and XFP. Verify a receive address for the When migrating to a new key, calm and care should be applied. Rushing a wallet migration can create a more immediate risk than the issue you are trying to address. -Seeds generated on Mk4, Mk5 and Q before the fixed firmware releases are also -affected. Before using one of these models to generate a replacement seed, -upgrade Mk4 and Mk5 to version 5.6.0 or later, or Q to version 1.5.0Q or later: +Seeds generated on Mk3 versions 4.0.1 through 4.1.9; Mk4 and Mk5 before +standard version 5.6.0 or Edge version 6.6.0X; or Q before standard version +1.5.0Q or Edge version 6.6.0QX are affected unless the independent dice-entropy +exception applies. Before generating a replacement seed, update Mk3 to version +4.2.0 or later; Mk4 and Mk5 to standard version 5.6.0 or later, or Edge version +6.6.0X or later; or Q to standard version 1.5.0Q or later, or Edge version +6.6.0QX or later: Confirm the fixed firmware version is installed. Generate a new seed on the updated COLDCARD. Record and verify its backup before depositing funds.Extracted text as captured
Blog Careers Contact RSS Email Newsletter Store × Home Blog Careers Contact RSS Email Newsletter Store ← Back to posts Coldcard Security Advisory Published Jul 30, 2026 Categories: ckcc Updated July 31, 2026 at 12:39 p.m. EDT: Fixed firmware is now available for every affected model and release track: Mk3: version 4.2.0 or later Mk4/Mk5 standard: version 5.6.0 or later Q standard: version 1.5.0Q or later Mk4/Mk5 Edge: version 6.6.0X or later Q Edge: version 6.6.0QX or later Standard and Edge are separate release tracks. If you use Edge, install the fixed Edge release for your model. Do not assume an older Edge 6.x release is fixed merely because its version number is higher than the standard release. Do not generate a new seed on any of these models until the update is installed. Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) thru 4.1.9 (inclusive) that their funds may be at risk. Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits. Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you. TAPSIGNER, OPENDIME and SATSCARD are not affected by this bug as they are different codebasesExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Coinkite expanded the affected scope to Mk4, Mk5 and Q, added dice guidance, and revised the passphrase and migration sections.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 75 lines
Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk. -Mk4, Q and Mk5 are not affected based on our early analysis of the issue. -The issue is present through firmware version 5.0.3, -the final release that supported Mk3. -Investigation Ongoing +Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also +affected, with about 72 bits of entropy rather than the expected 128 bits. +TAPSIGNER, OPENDIME and SATSCARD are not affected by this bug as they are different codebases +The issue is present on every Mk3 firmware version since +4.0.1. It also affects seeds generated on +Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on +Mk4, Mk5 and Q is not as severe but is still serious. +If You Added Dice When Creating the Seed +This issue affects the device-generated entropy. It does not remove independent +entropy that you supplied with dice. +On affected firmware, COLDCARD hashed the device-generated seed together with +every dice roll +entered through Add Dice Rolls: +50 to 98 independent, private rolls: the dice input alone contributed at +least 128 bits of entropy. +99 or more independent, private rolls: the dice input contributed +approximately 256 bits of entropy. +Fewer than 50 rolls, or you do not remember: follow the migration +guidance in this advisory. +If you entered at least 50 fair and independent rolls, and the rolls were not +recorded or exposed, we do not consider the resulting seed at risk from this +RNG issue alone. +This applies to the final seed words shown after the dice were added. If you are +uncertain which words you used, how many rolls you entered, or whether the +rolls were private, migrate to a new seed. +Investigation and Mk3 Firmware Status This advisory reflects our early analysis. Our investigation is ongoing, and a formal technical review will be released as soon as possible. +We are also exploring whether we can safely publish one final firmware +release for the deprecated Mk3. Updating this legacy platform carries a +significant risk of bricking some units, so we will publish it only if we +can validate a sufficiently safe upgrade path. +If the migration guidance applies to your seed, do not wait for a possible +firmware release before protecting your funds. An update cannot repair a seed +that was already generated by affected firmware. If You Used a Passphrase -If the affected Mk3 seed was used with a BIP-39 passphrase, our early -analysis indicates that your funds are at minimal risk from this issue. -This means a BIP-39 passphrase, not the COLDCARD PIN. Continue to protect -that passphrase and do not enter it into a website or an untrusted device. +If the affected Mk3 seed was used with a strong, unique BIP-39 passphrase, that +passphrase adds an independent barrier. The risk depends on the strength of the +passphrase: a short, common, patterned, quoted, or reused passphrase may be +guessable and should not be assumed to provide minimal risk. +This means a BIP-39 passphrase, not the COLDCARD PIN. Even with a strong +passphrase, migrate to a newly generated seed as soon as practical. Continue to +protect the passphrase and do not enter it into a website or an untrusted +device. If the Mk3 Is Your Only Option If you cannot immediately move to an unaffected device, create a strong, unique BIP-39 passphrase on the Mk3 and move the funds from the original before moving the remainder. Every passphrase, including one with a typo, creates a different valid wallet. Verify the XFP every time before sending funds. -Advanced Alternative: Dice-Only Seed -If you are confident in your ability to perform and verify a dice-only -migration, you can also create a replacement seed on the Mk3 without using -its random-number generator. On an empty Mk3 running 4.1.9, select Import -Existing > Dice Rolls and enter at least 99 independent rolls of a fair -six-sided die. This dedicated dice-only path hashes the roll sequence -directly; it does not use the device’s generator. Do not use the normal -New Wallet flow if your goal is to exclude the device generator. +Advanced Fallback: Dice-Only Seed on Mk3 +If the Mk3 is your only available device and you are confident in your ability +to perform and verify a dice-only migration, you can create a replacement seed +without using its random-number generator. This is not required when generating +a new seed on fixed Mk4, Mk5 or Q firmware. +On an empty Mk3 running 4.1.9, select Import Existing > Dice Rolls and enter +at least 99 independent rolls of a fair six-sided die. This dedicated dice-only +path hashes the roll sequence directly; it does not use the device’s generator. +Do not use the normal New Wallet flow if your goal is to exclude the device +generator. This is an advanced procedure. A one-device migration requires safely alternating between the old and new seeds. Before erasing either seed from the Mk3, verify its written backup and XFP. Verify a receive address for the When migrating to a new key, calm and care should be applied. Rushing a wallet migration can create a more immediate risk than the issue you are trying to address. -Mk4, Mk5, and later COLDCARD models are not affected based on our early -analysis and can be used to generate the new seed: -Generate a new seed on the unaffected COLDCARD. +Seeds generated on Mk4, Mk5 and Q before the fixed firmware releases are also +affected. Before using one of these models to generate a replacement seed, +upgrade Mk4 and Mk5 to version 5.6.0 or later, or Q to version 1.5.0Q or later: +Confirm the fixed firmware version is installed. +Generate a new seed on the updated COLDCARD. Record and verify its backup before depositing funds. Verify a new receive address on the COLDCARD screen. Send a small test transaction and confirm that the new wallet works.Extracted text as captured
Blog Careers Contact RSS Email Newsletter Store × Home Blog Careers Contact RSS Email Newsletter Store ← Back to posts Mk3 Security Advisory Published Jul 30, 2026 Categories: ckcc Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk. Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits. TAPSIGNER, OPENDIME and SATSCARD are not affected by this bug as they are different codebases The issue is present on every Mk3 firmware version since 4.0.1. It also affects seeds generated on Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on Mk4, Mk5 and Q is not as severe but is still serious. If You Added Dice When Creating the Seed This issue affects the device-generated entropy. It does not remove independent entropy that you supplied with dice. On affected firmware, COLDCARD hashed the device-generated seed together with every dice roll entered through Add Dice Rolls: 50 to 98 independent, private rolls: the dice input alone contributed at least 128 bits of entropy. 99 or more independent, private rolls: the dice input contributed approximately 256 bits of entropy. Fewer than 50 rolls, or you do not remember: follow the migration guidance in this advisory.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
Blog Careers Contact RSS Email Newsletter Store × Home Blog Careers Contact RSS Email Newsletter Store ← Back to posts Mk3 Security Advisory Published Jul 30, 2026 Categories: ckcc Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk. Mk4, Q and Mk5 are not affected based on our early analysis of the issue. The issue is present through firmware version 5.0.3, the final release that supported Mk3. Investigation Ongoing This advisory reflects our early analysis. Our investigation is ongoing, and a formal technical review will be released as soon as possible. If You Used a Passphrase If the affected Mk3 seed was used with a BIP-39 passphrase, our early analysis indicates that your funds are at minimal risk from this issue. This means a BIP-39 passphrase, not the COLDCARD PIN. Continue to protect that passphrase and do not enter it into a website or an untrusted device. If the Mk3 Is Your Only Option If you cannot immediately move to an unaffected device, create a strong, unique BIP-39 passphrase on the Mk3 and move the funds from the original wallet to the new passphrase-protected wallet. Treat this as an interim measure until you can migrate to a new seed generated on an unaffected device. Proceed calmly and carefully: Read the COLDCARD BIP-39 passphraseExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
Each copy above is identified by the SHA-256 of its extracted text, shown beside it, and the diffs are plain unified diffs. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
The SHA-256 prefixes above identify each held copy without turning this page into a mirror of somebody else's post. Compare a quotation against the original. If the post has since been edited or deleted, ask and the held copy can be produced.