COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Who must move their coins

tftc-who-must-move

https://www.tftc.io/coldcard-rng-failed-move-your-coins

Organisation
TFTC
Evidence role
Secondary analysis
Published
2026-07-31
Source changes
0
Detected differences
1
Unreviewed
0
Copies held
2

Migration protocol plus a warning about scam recovery services.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. Earliest copy held
    seen · Captured here 9,701 chars
    Extracted text as captured
    BTC–Block–Mempool–Diff–
    Live · mempool.space
    NewsArticlesBitcoin BriefPodcastRound Table
    Join the Round Table
    Read
    NewsArticlesBitcoin BriefPodcastEconomics
    TFTC
    AboutAdvertiseContactJoin the Round TableSign in
    Bitcoin Brief
    COLDCARD's RNG Failed. Move Your Coins.
    An urgent warning for anyone whose seed was generated on affected COLDCARD firmware. Updating the device will not repair the seed. Generate a new one and migrate carefully.
    Marty Bent
    ·July 31, 2026·8 min read
    Share
    Bitcoin BriefEmergency Edition
    TFTC · Truth for the Commoner
    Bitcoin Brief
    Sup, freaks.
    We are sending a single-story emergency edition of the Bitcoin Brief because time matters.
    URGENT WARNING
    COLDCARD's RNG Failed. Move Your Coins.
    I have been a vocal COLDCARD advocate for years. I have trusted the product, recommended it to people I care about, and used it as an example of serious bitcoin self-custody. What came to light overnight is an absolute disaster.
    Coinkite has now confirmed that affected COLDCARD firmware used the wrong random-number generator while creating wallet seeds. Instead of drawing the intended randomness from the device's hardware, seed generation reached a deterministic MicroPython software fallback. Block's Bitcoin Engineering and Security team independently found the same failure in the source code.
    That means some wallets that looked like normal cold storage were protected by keys drawn from a search space far smaller than users had every reason to expect.
    The most acute danger is on Mk2 and Mk3 devices running version 4 firmware. Coinkite's advisory warns about Mk3 seeds generated on firmware 4.0.1 or later and currently estimates an effective search space of roughly 40 bits under its attack assumptions. Block traces the vulnerable path to version 4.0.0. Do not gamble on that one-version discrepancy. If a Mk2 or Mk3 running version 4 firmware generated your seed, treat the seed as compromised and migrate.
    The problem extends beyond the Mk3. Coinkite now says seeds generated on Mk4 and Mk5 before firmware 5.6.0, and on Q before 1.5.0Q, are also affected. Coinkite currently estimates roughly 72 bits of entropy for those later devices instead of the intended 128 bits. The later models are less exposed than the Mk3, but Coinkite still calls the weakness serious and tells users to generate a new seed after installing the fixed firmware.
    A firmware update cannot repair a seed that already exists. The weakness is baked into the private keys derived from that seed. Updating the device and continuing to use the same words leaves the problem in place.
    This disclosure arrived after a coordinated on-chain sweep moved 594.47722484 BTC into one collector address across 500 transactions and four consecutive blocks. We independently reproduced that chain event. Several reported victims said they used COLDCARD single-sig wallets, but the blockchain cannot identify the hardware that generated a key. It would be irresponsible to claim that every coin in the sweep came from this bug or that 500 transactions equal 500 victims. The firmware failure is confirmed. The exact share of the theft tied to it is still being investigated.
    That is why the priority now is action, not tribal warfare between hardware-wallet brands.
    Who should move now
    Assume the seed is at risk and prepare a migration if any of these describe you:
    A Mk2 or Mk3 running version 4 firmware generated your seed.
    A Mk4 or Mk5 generated your seed before firmware 5.6.0.
    A Q generated your seed before firmware 1.5.0Q.
    Affected firmware generated your seed, regardless of whether you also used dice rolls or a passphrase.
    You cannot remember the model, firmware, or entropy method used when the seed was created.
    The affected cohort is defined by the firmware that generated the secret, not the firmware installed today. Updating the device or restoring the same seed onto newer hardware does not strengthen the keys. You still have to create a new seed and move the coins.
    What dice and a passphrase change
    Coinkite says the dice input was hashed together with the device-generated seed. Fair, independent, private dice rolls can add real entropy, and a strong, unique BIP39 passphrase can add another independent barrier. But neither should be treated as permission to keep using a seed created by affected firmware.
    If you cannot say with complete confidence that you used at least 100 fair, independent, private dice rolls when the original seed was created, assume the keys remain vulnerable. Even if you did use at least 100 rolls or a genuinely strong passphrase, the safe response is still to replace the seed and move the coins. A device PIN is not a BIP39 passphrase.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

1 presentation-noise difference. Sidebar, ticker and other page chrome churn that our review classified as not being a change to what the source says.
  • +10 -10 Only rotating related-content cards below the article changed.
How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.