COLDCARD vulnerability what happened, and what to do
Informational only, and this site never asks for your recovery words. details

Informational only. This is independent analysis and an evidence-backed explainer, not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite, Block, or any other party named here. Published estimates are attributed, and differing scenarios are kept separate with their assumptions. Act on your own judgement. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it. Deliberate recovery on independently verified offline equipment is a separate operation. Seed-word safety.

Who must move their coins

tftc-who-must-move

https://www.tftc.io/coldcard-rng-failed-move-your-coins

Organisation
TFTC
Evidence role
Secondary analysis
Published
2026-07-31
Source changes
0
Detected differences
1
Unreviewed
0
Copies held
2

Migration protocol plus a warning about scam recovery services.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked 2 Aug 2026, 00:59 UTC.

  1. capture noise difference between 1 Aug 2026, 00:46 UTC and 1 Aug 2026, 03:08 UTC Current capture noise +10 -10

    Only rotating related-content cards below the article changed.

    seen 1 Aug 2026, 03:08 UTC · Captured here text sha256 3605c8c2132eaabd85d281ff 9,704 chars
    What changed from the previous capture 20 lines
     News and analysis, not financial, investment, legal, or tax advice. Figures and quotes are verified against primary sources where possible. See our editorial and financial disclosures.
     Keep reading
     All of TFTC
    +Podcast
    +ColdCard Is Compromised: What You Need to Do Now
    +The ColdCard RNG vulnerability is real, it's expanding, and it's already cost people their coins. James O'Beirne joins me to walk…
    +Marty Bent
    +·August 1, 2026
    +Podcast
    +Michael Howell: Yields Must Rise, Fed Must Hike
    +Michael Howell returns to walk through the nominal GDP math that forces yields higher, the yield volatility control the Fed is qui…
    +Marty Bent
    +·August 1, 2026
     Bitcoin Brief
     The Fed Paused. The Bond Market Did Not.
     The Fed held rates steady. The front end relaxed, the long end revolted, stocks rolled over, and the monetary trap got tighter.
     Marty Bent
     ·July 30, 2026
    -Bitcoin Brief
    -Bitcoin's Liquidity Winter Is Not Over Yet
    -Michael Howell says the global-liquidity cycle peaked in 2025 and may remain a headwind for months. Bitcoin's monetary case can su…
    -Marty Bent
    -·July 29, 2026
    -Podcast
    -Dave Collum: The Private Credit Bomb Is Coming
    -Dave Collum and Rudy Havenstein join me to lay out the private credit bomb, the AI bubble stacked on top of it, and why there are…
    -Marty Bent
    -·July 28, 2026
     The Bitcoin Brief
     Bitcoin, markets, energy, and the tech reshaping all three.
     A daily brief on the freedom tech building a parallel economy, written for the curious and the convicted alike. Signal, not noise. Truth for the Commoner.
    
    Extracted text as captured
    BTC–Block–Mempool–Diff–
    Live · mempool.space
    NewsArticlesBitcoin BriefPodcastRound Table
    Join the Round Table
    Read
    NewsArticlesBitcoin BriefPodcastEconomics
    TFTC
    AboutAdvertiseContactJoin the Round TableSign in
    Bitcoin Brief
    COLDCARD's RNG Failed. Move Your Coins.
    An urgent warning for anyone whose seed was generated on affected COLDCARD firmware. Updating the device will not repair the seed. Generate a new one and migrate carefully.
    Marty Bent
    ·July 31, 2026·8 min read
    Share
    Bitcoin BriefEmergency Edition
    TFTC · Truth for the Commoner
    Bitcoin Brief
    Sup, freaks.
    We are sending a single-story emergency edition of the Bitcoin Brief because time matters.
    URGENT WARNING
    COLDCARD's RNG Failed. Move Your Coins.
    I have been a vocal COLDCARD advocate for years. I have trusted the product, recommended it to people I care about, and used it as an example of serious bitcoin self-custody. What came to light overnight is an absolute disaster.
    Coinkite has now confirmed that affected COLDCARD firmware used the wrong random-number generator while creating wallet seeds. Instead of drawing the intended randomness from the device's hardware, seed generation reached a deterministic MicroPython software fallback. Block's Bitcoin Engineering and Security team independently found the same failure in the source code.
    That means some wallets that looked like normal cold storage were protected by keys drawn from a search space far smaller than users had every reason to expect.
    The most acute danger is on Mk2 and Mk3 devices running version 4 firmware. Coinkite's advisory warns about Mk3 seeds generated on firmware 4.0.1 or later and currently estimates an effective search space of roughly 40 bits under its attack assumptions. Block traces the vulnerable path to version 4.0.0. Do not gamble on that one-version discrepancy. If a Mk2 or Mk3 running version 4 firmware generated your seed, treat the seed as compromised and migrate.
    The problem extends beyond the Mk3. Coinkite now says seeds generated on Mk4 and Mk5 before firmware 5.6.0, and on Q before 1.5.0Q, are also affected. Coinkite currently estimates roughly 72 bits of entropy for those later devices instead of the intended 128 bits. The later models are less exposed than the Mk3, but Coinkite still calls the weakness serious and tells users to generate a new seed after installing the fixed firmware.
    A firmware update cannot repair a seed that already exists. The weakness is baked into the private keys derived from that seed. Updating the device and continuing to use the same words leaves the problem in place.
    This disclosure arrived after a coordinated on-chain sweep moved 594.47722484 BTC into one collector address across 500 transactions and four consecutive blocks. We independently reproduced that chain event. Several reported victims said they used COLDCARD single-sig wallets, but the blockchain cannot identify the hardware that generated a key. It would be irresponsible to claim that every coin in the sweep came from this bug or that 500 transactions equal 500 victims. The firmware failure is confirmed. The exact share of the theft tied to it is still being investigated.
    That is why the priority now is action, not tribal warfare between hardware-wallet brands.
    Who should move now
    Assume the seed is at risk and prepare a migration if any of these describe you:
    A Mk2 or Mk3 running version 4 firmware generated your seed.
    A Mk4 or Mk5 generated your seed before firmware 5.6.0.
    A Q generated your seed before firmware 1.5.0Q.
    Affected firmware generated your seed, regardless of whether you also used dice rolls or a passphrase.
    You cannot remember the model, firmware, or entropy method used when the seed was created.
    The affected cohort is defined by the firmware that generated the secret, not the firmware installed today. Updating the device or restoring the same seed onto newer hardware does not strengthen the keys. You still have to create a new seed and move the coins.
    What dice and a passphrase change
    Coinkite says the dice input was hashed together with the device-generated seed. Fair, independent, private dice rolls can add real entropy, and a strong, unique BIP39 passphrase can add another independent barrier. But neither should be treated as permission to keep using a seed created by affected firmware.
    If you cannot say with complete confidence that you used at least 100 fair, independent, private dice rolls when the original seed was created, assume the keys remain vulnerable. Even if you did use at least 100 rolls or a genuinely strong passphrase, the safe response is still to replace the seed and move the coins. A device PIN is not a BIP39 passphrase.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. Earliest copy held
    seen 1 Aug 2026, 00:46 UTC · Captured here text sha256 01016583ea50b5f1bfb226ab 9,701 chars
    Extracted text as captured
    BTC–Block–Mempool–Diff–
    Live · mempool.space
    NewsArticlesBitcoin BriefPodcastRound Table
    Join the Round Table
    Read
    NewsArticlesBitcoin BriefPodcastEconomics
    TFTC
    AboutAdvertiseContactJoin the Round TableSign in
    Bitcoin Brief
    COLDCARD's RNG Failed. Move Your Coins.
    An urgent warning for anyone whose seed was generated on affected COLDCARD firmware. Updating the device will not repair the seed. Generate a new one and migrate carefully.
    Marty Bent
    ·July 31, 2026·8 min read
    Share
    Bitcoin BriefEmergency Edition
    TFTC · Truth for the Commoner
    Bitcoin Brief
    Sup, freaks.
    We are sending a single-story emergency edition of the Bitcoin Brief because time matters.
    URGENT WARNING
    COLDCARD's RNG Failed. Move Your Coins.
    I have been a vocal COLDCARD advocate for years. I have trusted the product, recommended it to people I care about, and used it as an example of serious bitcoin self-custody. What came to light overnight is an absolute disaster.
    Coinkite has now confirmed that affected COLDCARD firmware used the wrong random-number generator while creating wallet seeds. Instead of drawing the intended randomness from the device's hardware, seed generation reached a deterministic MicroPython software fallback. Block's Bitcoin Engineering and Security team independently found the same failure in the source code.
    That means some wallets that looked like normal cold storage were protected by keys drawn from a search space far smaller than users had every reason to expect.
    The most acute danger is on Mk2 and Mk3 devices running version 4 firmware. Coinkite's advisory warns about Mk3 seeds generated on firmware 4.0.1 or later and currently estimates an effective search space of roughly 40 bits under its attack assumptions. Block traces the vulnerable path to version 4.0.0. Do not gamble on that one-version discrepancy. If a Mk2 or Mk3 running version 4 firmware generated your seed, treat the seed as compromised and migrate.
    The problem extends beyond the Mk3. Coinkite now says seeds generated on Mk4 and Mk5 before firmware 5.6.0, and on Q before 1.5.0Q, are also affected. Coinkite currently estimates roughly 72 bits of entropy for those later devices instead of the intended 128 bits. The later models are less exposed than the Mk3, but Coinkite still calls the weakness serious and tells users to generate a new seed after installing the fixed firmware.
    A firmware update cannot repair a seed that already exists. The weakness is baked into the private keys derived from that seed. Updating the device and continuing to use the same words leaves the problem in place.
    This disclosure arrived after a coordinated on-chain sweep moved 594.47722484 BTC into one collector address across 500 transactions and four consecutive blocks. We independently reproduced that chain event. Several reported victims said they used COLDCARD single-sig wallets, but the blockchain cannot identify the hardware that generated a key. It would be irresponsible to claim that every coin in the sweep came from this bug or that 500 transactions equal 500 victims. The firmware failure is confirmed. The exact share of the theft tied to it is still being investigated.
    That is why the priority now is action, not tribal warfare between hardware-wallet brands.
    Who should move now
    Assume the seed is at risk and prepare a migration if any of these describe you:
    A Mk2 or Mk3 running version 4 firmware generated your seed.
    A Mk4 or Mk5 generated your seed before firmware 5.6.0.
    A Q generated your seed before firmware 1.5.0Q.
    Affected firmware generated your seed, regardless of whether you also used dice rolls or a passphrase.
    You cannot remember the model, firmware, or entropy method used when the seed was created.
    The affected cohort is defined by the firmware that generated the secret, not the firmware installed today. Updating the device or restoring the same seed onto newer hardware does not strengthen the keys. You still have to create a new seed and move the coins.
    What dice and a passphrase change
    Coinkite says the dice input was hashed together with the device-generated seed. Fair, independent, private dice rolls can add real entropy, and a strong, unique BIP39 passphrase can add another independent barrier. But neither should be treated as permission to keep using a seed created by affected firmware.
    If you cannot say with complete confidence that you used at least 100 fair, independent, private dice rolls when the original seed was created, assume the keys remain vulnerable. Even if you did use at least 100 rolls or a genuinely strong passphrase, the safe response is still to replace the seed and move the coins. A device PIN is not a BIP39 passphrase.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

Each copy above is identified by the SHA-256 of its extracted text, shown beside it, and the diffs are plain unified diffs. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.