Post-hotfix full disclosure and 39 unpatched findings
karmax-post-hotfix-disclosure
Latest reviewed change
source content difference between and
Post edited: the Mk3 action item gained an UPDATE noting Coinkite has issued firmware 4.2.0 for Mk2 and Mk3 after previously saying the line would receive no further updates.
As noted above, the full comprehensive audit with detailed reproduction steps for each finding is being delivered to Coinkite in parallel with the publication of this post. I hope this time it goes somewhere that produces both fixes and public advisories, so that users get both a safer device and visibility into the security state of the device they own.
What you should do
⚠️ IMMEDIATE ACTION (all users):
-Coldcard Mk3: regenerate your seed immediately following Coinkite's blog post instructions. Coinkite has stated Mk3 will not receive further firmware updates; if you keep using it, add a BIP-39 passphrase as a stopgap and plan for migration.
+Coldcard Mk3: regenerate your seed immediately following Coinkite's blog post instructions. Coinkite has stated Mk3 will not receive further firmware updates; if you keep using it, add a BIP-39 passphrase as a stopgap and plan for migration. UPDATE: Apparently Coinkite has issued a 4.2.0 for Mk2 and Mk3 after previously saying they wouldn't.
Coldcard Mk4/Mk5/Q: update to v5.6.0 (Mk4/Mk5) or v1.5.0Q (Q). Regenerate any seeds created on pre-v5.6.0 firmware. Regenerate any long-lived derived material — backup files, USB session keys, teleport pairings, web2fa keys, multisig receive-key derivation indices. All of these used the affected RNG on pre-v5.6.0 firmware.
If you use Delta mode as part of your security model: do not use Coldcard's message-signing feature until the Delta-mode message-signing gap is patched. If a coercer asks you to sign a message, the signature is real. Avoid workflows that require message signatures for authentication (some exchange KYC processes, proof-of-reserves attestations) if you rely on Delta-mode plausible deniability.
If you use HSM mode: understand that HSM mode maximizes exposure to the kleptography channel described above. In HSM mode, a compromised firmware exfiltrates faster and more thoroughly than a user-driven scenario. This is a consideration even setting aside kleptography — HSM mode inherently trades security for convenience.
First lines only. The complete diff is in the timeline below.
- Organisation
- Karma-X
- Evidence role
- Independent technical analysis
- Published
- 2026-08-02
- Source changes
- 2
- Detected differences
- 2
- Unreviewed
- 0
- Copies held
- 3
Primary source behind the VULN-109 prior-discovery claim. States that a September 2025 private audit flagged the single-source RNG class (SE TRNG disabled at the source, ae.c:666) and was never submitted after an earlier report (VULN-023) got a same-day fix but no CVE or advisory. Cross-checks the audit against v5.6.0 and claims 39 findings remain unfixed, plus two new ones (Delta-mode message-signing gap, kleptography channel via R-value grinding), with full detail said to be delivered to Coinkite in parallel with publication. The September 2025 audit itself is not public, so the prior-discovery claim rests on the author's account.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Post edited: the Mk3 action item gained an UPDATE noting Coinkite has issued firmware 4.2.0 for Mk2 and Mk3 after previously saying the line would receive no further updates.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 2 lines
As noted above, the full comprehensive audit with detailed reproduction steps for each finding is being delivered to Coinkite in parallel with the publication of this post. I hope this time it goes somewhere that produces both fixes and public advisories, so that users get both a safer device and visibility into the security state of the device they own. What you should do ⚠️ IMMEDIATE ACTION (all users): -Coldcard Mk3: regenerate your seed immediately following Coinkite's blog post instructions. Coinkite has stated Mk3 will not receive further firmware updates; if you keep using it, add a BIP-39 passphrase as a stopgap and plan for migration. +Coldcard Mk3: regenerate your seed immediately following Coinkite's blog post instructions. Coinkite has stated Mk3 will not receive further firmware updates; if you keep using it, add a BIP-39 passphrase as a stopgap and plan for migration. UPDATE: Apparently Coinkite has issued a 4.2.0 for Mk2 and Mk3 after previously saying they wouldn't. Coldcard Mk4/Mk5/Q: update to v5.6.0 (Mk4/Mk5) or v1.5.0Q (Q). Regenerate any seeds created on pre-v5.6.0 firmware. Regenerate any long-lived derived material — backup files, USB session keys, teleport pairings, web2fa keys, multisig receive-key derivation indices. All of these used the affected RNG on pre-v5.6.0 firmware. If you use Delta mode as part of your security model: do not use Coldcard's message-signing feature until the Delta-mode message-signing gap is patched. If a coercer asks you to sign a message, the signature is real. Avoid workflows that require message signatures for authentication (some exchange KYC processes, proof-of-reserves attestations) if you rely on Delta-mode plausible deniability. If you use HSM mode: understand that HSM mode maximizes exposure to the kleptography channel described above. In HSM mode, a compromised firmware exfiltrates faster and more thoroughly than a user-driven scenario. This is a consideration even setting aside kleptography — HSM mode inherently trades security for convenience.Extracted text as captured
Karma-X Company Karma-X Inc. Main About Us Contact Us Karma-X Inc. Main About Us Contact Us Products Get Karma-X Endpoint Upgrade your security with Karma-X Get Karma-X TimeCapsule Secure passphrases to Digital Assets with TimeCapsule Get Vitamin-K for Free Stop advanced actors with a daily vitamin! Get Karma Browser Add Karma protection to your browser! Get KarmaVPN Browse the Internet with Privacy! Free Karma Internet Tools Check out our free Internet tools! Get Karma-X Endpoint Upgrade your security with Karma-X Get Karma-X TimeCapsule Secure passphrases to Digital Assets with TimeCapsule Get Vitamin-K for Free Stop advanced actors with a daily vitamin! Get Karma Browser Add Karma protection to your browser! Get KarmaVPN Browse the Internet with Privacy! Free Karma Internet Tools Check out our free Internet tools! Blog News Top Ten Threats Login DownloadExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The author revised their account of why the prior finding was not submitted, adding that it had not been fully analysed and replacing an explicit retrospective admission with a statement that they lost interest in unpaid, unacknowledged research.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 4 lines
A note on my own disclosure history In September 2025 I completed a broad audit of Coldcard firmware. One finding — VULN-023, a Delta PIN key-recovery issue — I submitted to Coinkite privately. They responded technically and shipped a fix within hours (commit fcd848d8 "deltamode timing fix," dated the same day, September 29, 2025). Credit where it's due: their engineering turnaround was fast. But no CVE was filed. No security advisory was published. No public acknowledgment of the vulnerability was issued. Users had no way to know a vulnerability had existed in their device, that a fix was in the firmware they should update to, or that other researchers had found the vulnerability worth reporting through their channel. Coinkite is under no obligation to publicly credit external researchers — that's a matter of good ecosystem practice, not a strict duty — but the absence of CVE and advisory is a broader problem than credit. Users lose visibility into their own device's security state. Other researchers lose a signal about whether reporting through the channel produces public benefit. Regulators and downstream integrators lose an audit trail. -Reading the lack of any public trail as a signal that further submissions would land the same way, I did not send the rest of my findings — including VULN-109, which flagged the exact class of bug that would later cause the July 2026 catastrophic loss: single-source RNG in critical paths, with the Secure Element's independent TRNG disabled at the source (#if 0) in the bootloader. That finding sat in my private research notes for ten months. -That was my call, and I own it. In hindsight, given the July 2026 loss, users would have been better served if I'd pushed through and submitted anyway. Vendors and researchers each hold half of the disclosure feedback loop; when either side stops participating in good faith, users pay the price. My half of that failure is that I judged based on a single interaction and let it stop me from submitting subsequent findings. Coinkite's half is that the interaction produced no public artifact that would have told me — or any other researcher — the channel was working as intended. +Reading the lack of any public trail as a signal that further submissions would land the same way, I did not send the rest of my findings — including VULN-109, which flagged the exact class of bug that would later cause the July 2026 catastrophic loss: single-source RNG in critical paths, with the Secure Element's independent TRNG disabled at the source (#if 0) in the bootloader. That finding sat in my private research notes for ten months without being fully analyzed. +Due to the circumstances, I lost interest in providing further free and unacknowledged analysis and research. Vendors and researchers each hold half of the disclosure feedback loop; when either side stops participating in good faith, users pay the price. My half is that I lost interest in the side-project and moved on to other priorities. Coinkite's half is that the interaction produced no public artifact that would have told me — or any other researcher — the channel was working as intended. Two things follow, and both are happening in parallel with this post: The full comprehensive September 2025 audit — including all 28 findings never previously submitted — is being sent to Coinkite today, alongside the new August 2026 kleptography findings and my cross-check of which items remain in the current v5.6.0 code. They will have every detail I have, with reproduction context, in a form they can act on. This post publishes the high-level shape publicly, because users need actionable information now, and because in the current threat landscape the assumption that private research remains solely private is untenable regardless.Extracted text as captured
Karma-X Company Karma-X Inc. Main About Us Contact Us Karma-X Inc. Main About Us Contact Us Products Get Karma-X Endpoint Upgrade your security with Karma-X Get Karma-X TimeCapsule Secure passphrases to Digital Assets with TimeCapsule Get Vitamin-K for Free Stop advanced actors with a daily vitamin! Get Karma Browser Add Karma protection to your browser! Get KarmaVPN Browse the Internet with Privacy! Free Karma Internet Tools Check out our free Internet tools! Get Karma-X Endpoint Upgrade your security with Karma-X Get Karma-X TimeCapsule Secure passphrases to Digital Assets with TimeCapsule Get Vitamin-K for Free Stop advanced actors with a daily vitamin! Get Karma Browser Add Karma protection to your browser! Get KarmaVPN Browse the Internet with Privacy! Free Karma Internet Tools Check out our free Internet tools! Blog News Top Ten Threats Login DownloadExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
Karma-X Company Karma-X Inc. Main About Us Contact Us Karma-X Inc. Main About Us Contact Us Products Get Karma-X Endpoint Upgrade your security with Karma-X Get Karma-X TimeCapsule Secure passphrases to Digital Assets with TimeCapsule Get Vitamin-K for Free Stop advanced actors with a daily vitamin! Get Karma Browser Add Karma protection to your browser! Get KarmaVPN Browse the Internet with Privacy! Free Karma Internet Tools Check out our free Internet tools! Get Karma-X Endpoint Upgrade your security with Karma-X Get Karma-X TimeCapsule Secure passphrases to Digital Assets with TimeCapsule Get Vitamin-K for Free Stop advanced actors with a daily vitamin! Get Karma Browser Add Karma protection to your browser! Get KarmaVPN Browse the Internet with Privacy! Free Karma Internet Tools Check out our free Internet tools! Blog News Top Ten Threats Login DownloadExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.