COLDCARD COMPROMISED!!! IMMEDIATE ACTION REQUIRED!!

On July 30, Coinkite disclosed that a firmware bug had been silently disabling the hardware random number generator on Coldcard wallets since March 2021. Instead of true randomness, affected devices fell back to predictable entropy sourced from device details like the serial number and internal clock. An attacker exploited this and swept 594 BTC, worth approximately $38 million, from about 500 wallets in a 25-minute window early Friday morning. Coinkite has since released fixed firmware for every affected model. If you own a Coldcard and generated your seed using the device itself, read this now.

TL;DR

  • A firmware bug going back to March 2021 silently disabled the hardware RNG on Coldcard devices, replacing true randomness with predictable, guessable entropy.

  • $38 million was stolen from about 500 wallets in a 25-minute sweep. This is confirmed, not theoretical.

  • Fixed firmware is now available for every model: Mk3 (4.2.0), Mk4/Mk5 standard (5.6.0), Q standard (1.5.0Q), Mk4/Mk5 Edge (6.6.0X), Q Edge (6.6.0QX). Install the correct fix for your specific model and track.

  • Updating firmware does not fix an existing seed. You must generate a brand new seed on the updated firmware and migrate funds.

  • 50 or more private, independent dice rolls at creation take your seed fully outside this risk. A strong passphrase reduces risk but Coinkite still recommends migrating regardless.

  • If this applies to you, stop reading social media takes and go move your funds. Full steps below.

What Actually Broke

The bug traces to a single commit from March 2021. A build flag meant to control whether the hardware RNG was active got set incorrectly, and the code checking that flag only verified that the setting existed, not whether it was turned on. The device silently fell back to a software pseudo-random number generator seeded from predictable device state instead of true hardware randomness.

On Mk3 devices, this reduced effective entropy from the intended 128 bits down to roughly 40 bits, a search space small enough to brute force. Mk4, Mk5, and Q devices had partial protection from a secondary entropy source mixed in during development, bringing their effective entropy to roughly 72 bits, weaker than intended but harder to crack than Mk3. Coinkite has stated this is a preliminary estimate and the investigation is ongoing.

The bug sat undiscovered in open-source firmware for five years. Coinkite's own note on the disclosure raises the possibility that AI-assisted code review is what finally surfaced it, for whoever exploited it first. That is speculation on their part, not a confirmed attribution.

Who Is At Risk

Mk3 devices, firmware version 4.0.1 through 4.1.9 inclusive, where the seed was generated using the device's built-in random number generator.

Mk4 and Mk5 devices, on standard firmware before 5.6.0 or Edge firmware before 6.6.0X, where the seed was generated using the device's built-in random number generator.

Q devices, on standard firmware before 1.5.0Q or Edge firmware before 6.6.0QX, same condition.

Standard and Edge are separate release tracks. If you run Edge, you need the Edge-specific fix. Do not assume an older Edge 6.x build is safe just because its version number looks higher than the current standard release. Check your track and version explicitly.

Updating the firmware does not retroactively fix a seed that was already generated. It only protects seeds generated after the update. If your existing seed predates the fixed firmware for your model, it remains exposed until you migrate.

Who Is Fully Outside This Risk

If you entered 50 or more independent, private dice rolls when your seed was created, and those rolls were never recorded or exposed, Coinkite does not consider the resulting seed at risk from this issue at all. The numbers matter: 50 to 98 rolls contributed at least 128 bits of entropy on their own, and 99 or more rolls contributed roughly 256 bits. This is independent of whatever the device's own RNG was doing in the background. If you are unsure how many rolls you entered, whether they were truly private, or don't remember, treat yourself as at risk and migrate.

TAPSIGNER, OPENDIME, and SATSCARD use separate codebases and are not affected by this issue.

If You Used a Passphrase: Reduced Risk, Not Zero Risk

A strong, unique BIP-39 passphrase, not your Coldcard PIN, adds an independent barrier and meaningfully lowers your exposure. But a short, common, patterned, quoted, or reused passphrase should not be assumed to protect you. Even with a genuinely strong passphrase, Coinkite is now recommending migration to a newly generated seed as soon as practical. A passphrase reduces the risk here. It does not remove the reason to migrate.

What To Do Right Now

Fixed firmware exists for every model. Confirm the exact version for your specific model and track before doing anything else:

  • Mk3: version 4.2.0 or later

  • Mk4/Mk5 standard: version 5.6.0 or later

  • Q standard: version 1.5.0Q or later

  • Mk4/Mk5 Edge: version 6.6.0X or later

  • Q Edge: version 6.6.0QX or later

Do not generate a new seed on any device until the correct fix is installed.

Once updated, generate a completely new seed on the fixed firmware. Record and verify its backup, verify the wallet fingerprint, verify a new receive address on the device screen, and send a small test transaction before moving anything meaningful. Keep your old backup until the full balance has arrived and is confirmed.

If a Mk3 is your only device, you do not need a second device to do this. The fixed firmware generates a correct seed on its own. Using one device for both the old and new wallet just means being careful to verify which seed is active at each step before moving funds, restoring the old seed, confirming test funds landed, then finishing the migration.

Advanced users who want to skip the device RNG entirely can use Import Existing > Dice Rolls on updated firmware with 99 or more independent rolls of a fair die. This is optional. The standard New Wallet flow is fully corrected on the fixed firmware.

Every migration, regardless of device: verify the fingerprint before depositing meaningful funds, send a test transaction first, never photograph or digitize dice rolls or passphrases, and never enter either into a networked device. Move calmly. Rushing this creates more risk than the bug you're responding to.

If you want to be as safe as possible till the dust settles: move your funds off any COLDCARD HWW into any other trusted-brand HWW, a mobile wallet until you figure out a long term set-up, or send to an exchange (but consider the KYC implications).

FOLLOW US

Subscribe on YouTube

Follow on X

Reply

Avatar

or to participate

Keep Reading