COLDCARD vulnerability

What owners need to know

On July 30, 2026, Coinkite disclosed that certain COLDCARD firmware versions created wallet seeds with less genuine randomness behind them than intended. Coinkite has since released corrected firmware for every affected model, but a firmware update cannot repair a seed that already exists. If your seed was generated by affected firmware, your bitcoin needs to end up under keys this issue never touched.

For peace-of-mind, our recommendation is to move your bitcoin to a new wallet on a device that was not affected by this issue.

Bitcoin moving from a hardware wallet marked with a warning symbol to a second hardware wallet and a freshly recorded seed backup marked with a shield

Current status

Coinkite has published a security advisory and has released fixed firmware for every affected model and release track. Coinkite states that its investigation is ongoing and that a formal technical review will follow.

Last verified

This situation is still developing, and the official guidance has already changed materially once. The advisory published on July 30 was updated on July 31 to add fixed firmware for every model and release track, and to extend the affected scope to seeds generated on the Mk4, Mk5 and Q. Treat this page as a snapshot and check the official advisory before you act on anything here.

Official source: Coinkite Mk3 Security Advisory

Recommended actions

If your seed was generated by affected firmware, our advice is direct: move your bitcoin to a new wallet, created on a device that was not affected by this issue.

Recommended

Send your bitcoin to a new wallet

Move your funds to a wallet created on a device or application that this issue never affected.

Why we recommend it

  • You do not have to reconstruct which firmware was running when the seed was generated, how many dice rolls you entered, or whether your passphrase is strong enough
  • The affected scope has already widened once since disclosure, and this route does not depend on where it settles
  • The published estimates of how much unpredictability is left have not been reconciled, and this route does not depend on which one is right
  • Nothing about it requires trusting the same generator a second time

What it involves

  • Set up a wallet on a device or application this issue never affected
  • Record and verify the new backup, along with a receive address shown on the new device itself
  • Send a small test amount first, then move the rest, keeping the old backup until the full balance has confirmed

The care each step needs is the same as for any migration, and the migration overview below sets out the full sequence.

This is our own recommendation rather than Coinkite guidance. We are not pointing you at a particular brand, and Bitcoin Well never holds your bitcoin.

At your own risk

Update firmware and migrate

Coinkite’s official guidance

Coinkite directs affected owners to install the corrected firmware, generate a completely new seed on it, and move their funds to that new wallet. It is a legitimate route and it is the one the official documentation supports in detail.

What it involves

  • Install the fixed firmware for your model and release track
  • Generate a completely new seed on that firmware
  • Verify the new backup and a receive address on the device, then test with a small amount before moving the rest

What to weigh

It returns you to the same device family whose generator is still being examined. Coinkite states that its investigation is ongoing and that a formal technical review is still to come, so this route asks you to rely on a fix whose review is not yet complete.

The fixed firmware versions and the migration overview are below.

Official source: Coinkite Mk3 Security Advisory

Who may be affected

Everything here is what Coinkite has published. Where Coinkite has not addressed something, that is said plainly rather than filled in from elsewhere.

The one thing that decides it: which firmware was running when the seed was generated. Not when you bought the device, and not which firmware it runs today.

Device and firmware scope

Which models and release tracks Coinkite has addressed.

COLDCARD Mk3Affected
Coinkite warns everyone who generated a seed on an Mk3 running firmware 4.0.1 through 4.1.9 inclusive that their funds may be at risk. Coinkite estimates the effective search space at about 40 bits and describes that figure as preliminary.
Preliminary estimate
COLDCARD Mk4, Mk5 and QAffected
Seeds generated before the fixed release for the relevant track are also affected, with about 72 bits of entropy rather than the expected 128. Coinkite describes the impact on these models as not as severe as on the Mk3 but still serious.
Preliminary estimate
Standard and Edge firmware tracksDepends on your setup
Standard and Edge are separate release tracks with separate fixes. Coinkite warns specifically against assuming that an older Edge 6.x release is fixed merely because its version number is higher than the standard release.
Confirmed by Coinkite
TAPSIGNER, OPENDIME and SATSCARDOutside the disclosed issue
Coinkite states that these products are not affected by this bug because they use different codebases.
Confirmed by Coinkite
COLDCARD Mk1 and Mk2Not addressed by Coinkite
Coinkite’s advisory addresses the Mk3, Mk4, Mk5 and Q. It does not address the Mk1 or the Mk2 either way. Independent researchers have published findings about earlier models; those are summarised separately below and are not Coinkite guidance. See the independent analysis.
Not addressed by Coinkite

Setup and seed-generation factors

How your seed was created, and what can change the answer.

Seeds generated by affected firmwareDepends on your setup
Exposure depends on the firmware that was running when the seed was generated, not on when the device was bought. Coinkite is explicit that updating the firmware does not change or repair a seed that already exists.
Confirmed by Coinkite
Seeds imported from another sourceOutside the disclosed issue
The disclosed issue concerns secrets generated by affected COLDCARD firmware. A seed that was generated elsewhere and then imported was not produced by the affected generator, so it is outside this particular issue. That is a narrow statement about this issue only and says nothing about the security of wherever that seed did come from.
Confirmed by Coinkite
Seeds supplemented with independent dice entropyDepends on your setup
On affected firmware, COLDCARD hashed the device-generated seed together with every roll entered through Add Dice Rolls, so the issue does not remove entropy you supplied yourself. With at least 50 fair, independent rolls that were never recorded or exposed, Coinkite does not consider the resulting seed at risk from this issue alone. With fewer than 50 rolls, or if you do not remember, Coinkite directs you to migrate.
Confirmed by Coinkite
BIP39 passphrasesDepends on your setup
A strong, unique BIP39 passphrase adds an independent barrier, but the risk depends on its strength: Coinkite states that a short, common, patterned, quoted or reused passphrase may be guessable and should not be assumed to give minimal risk. Coinkite advises migrating to a newly generated seed as soon as practical even with a strong passphrase.
Confirmed by Coinkite
Single-signature and multisig walletsNot addressed by Coinkite
Coinkite’s advisory is written in terms of the seed that a device generated, and does not address multisig configurations either way. Independent researchers have published an assessment of multisig quorums; it is summarised separately below and is not Coinkite guidance. See the independent analysis.
Not addressed by Coinkite

If you are not sure

Coinkite’s own guidance on the dice exception resolves uncertainty toward migrating, and the same reasoning applies more broadly. Not being able to reconstruct how a seed was created years ago is a common position, and owners who appear to fall outside the confirmed scope can still choose to move to newly generated entropy — either of the routes above is open to you, chosen rather than directed.

Moving funds carries its own handling risks, so hurrying it is not the cautious option. What moving to new keys settles is the narrow question of how the seed was generated; it does not answer any other question about a wallet.

Official source: Coinkite Mk3 Security Advisory

Updating is not migrating

These are two different actions with two different effects. This is the point most likely to be misunderstood.

Updating firmware

Changes how the device generates secrets from this point forward. It is a fix for the future.

  • Protects future seed generation on that device
  • Does not alter, repair or strengthen a seed that already exists

Migrating a seed

Changes which seed your funds live under. It replaces the entropy behind your wallet entirely.

  • Creates entirely new wallet entropy on corrected firmware
  • Requires moving your funds to the new wallet
  • Is not accomplished by installing an update

Fixed firmware by model and release track

If you are staying on your COLDCARD, this is where to start. Standard and Edge are separate release tracks with separate fixes, and Coinkite warns specifically against assuming that an older Edge 6.x release is fixed just because its version number is higher than the standard release. Install the fixed release for the track you actually use.

Official source: Coinkite Mk3 Security Advisory

If you are unsure which page applies to your device, Coinkite’s downloads index lists every model.

Migration overview

A summary of the sequence Coinkite publishes, in two phases. The first step is specific to staying on a COLDCARD; everything after it applies just as much when the new wallet lives on a different device. It is not a substitute for the advisory, which includes per-model detail and a separate procedure for owners whose Mk3 is their only device.

Read Coinkite’s official instructions before you begin

Phase 1

Prepare and verify

Get onto fixed firmware and prove the new wallet is what you think it is, before any funds are involved.

  1. Install verified fixed firmware

    Confirm the fixed version for your model and release track is actually installed before going further.

  2. Generate a completely new seed

    Coinkite states that the fixed firmware’s device-generated seed is sufficient, and that dice rolls are optional rather than required to address this issue.

  3. Record and verify the new backup

    Verify the written backup and the wallet fingerprint before any funds are deposited.

  4. Verify a receive address on the device screen

    Read the address from the device screen rather than trusting only what your computer or phone displays.

Phase 2

Test and complete the move

Prove the new wallet works with a small amount first, then move the rest and only then retire the old backup.

  1. Send a small test transaction

    A small amount first, so a mistake is a small mistake rather than the whole balance.

  2. Confirm the new wallet works correctly

    Check that the test funds arrived and that the wallet fingerprint still matches what you recorded.

  3. Transfer the remaining balance

    Only once the new wallet has demonstrably worked end to end.

  4. Retain the old backup until the migration is fully confirmed

    Keep it until the complete balance has arrived and confirmed in the new wallet.

What happened

Each part below is explained twice: once in plain English, and once in the technical terms Coinkite uses.

What went wrong

In plain English

A wallet seed is only as unguessable as the randomness used to create it. Because of a build-configuration mistake, certain COLDCARD firmware versions asked for randomness from what the code appeared to treat as the dedicated hardware random-number generator, but the request was quietly served by a predictable software substitute instead. Seeds created that way had less unpredictability behind them than intended.

Technical detail

Entropy is the measure of how much genuine unpredictability went into a secret. A 24-word BIP39 seed is meant to carry 256 bits of entropy, and a 12-word seed 128 bits. That number, not the length of the phrase, is what makes a seed infeasible to guess.

Coinkite describes the cause as a complex and subtle series of bugs that prevented the hardware random-number generator from contributing randomness in certain firmware versions. In 2021, COLDCARD moved its elliptic-curve operations to the same libsecp256k1 implementation used by Bitcoin Core, which required adding libNgU, an embedded MicroPython library. During that migration, seed generation moved from ckcc.rng_bytes() to ngu.random.bytes(). Coinkite states that the second path resolved to MicroPython’s software fallback rather than COLDCARD’s hardware implementation.

The build did not fail, because both implementations exposed the same function signature. Coinkite explains that MICROPY_HW_ENABLE_RNG was explicitly set to zero on the assumption that neither MicroPython implementation was needed, while the guard meant to catch a missing hardware generator used #ifndef, which tests only whether a macro is defined and not whether its value is non-zero. A macro defined as zero satisfied that test, so compilation proceeded with the software fallback linked in.

Coinkite notes that the MicroPython fallback itself was introduced upstream in May 2018, and did not enter COLDCARD wallet seed generation until the libNgU migration in March 2021. The eight-year figure that circulated describes the age of the upstream code, not the span of affected seed generation.

Official source: Coinkite technical deep dive

Why reduced entropy weakens a seed

In plain English

If the pool of possible seeds a device could have produced is small enough to search through, then someone who knows a wallet’s public information can work through the candidates offline until they find the one that matches. The seed words look completely ordinary either way. Nothing about the phrase itself reveals how much randomness went into producing it.

Technical detail

A predictable generator narrows the set of seeds that a device could possibly have produced. Coinkite estimates the effective search space at about 40 bits on the Mk3, and describes that as a preliminary figure under current attack assumptions that may change as analysis continues.

For the Mk4, Mk5 and Q, Coinkite explains that values from the secure elements were mixed into the generator state during Mk4 development as an additional layer, which materially improves the situation for those models. Coinkite estimates the effective search space at about 72 bits, short of the intended 128-bit target.

Hashing does not help. A hash can make output look statistically uniform, but it cannot increase the number of distinct inputs that could have produced it, so no amount of hashing after the fact restores unpredictability the generator never had. The BIP39 checksum adds no entropy either.

This is why the fix and the remedy are separate actions. Corrected firmware changes how the next seed is generated; it has no access to the randomness that produced a seed years ago.

Official source: Coinkite technical deep dive

The role of independent dice entropy

In plain English

COLDCARD can mix in randomness that you generate yourself by rolling physical dice. That randomness never came from the device, so the issue with the device’s generator does not take it away. If you supplied enough independent rolls, they carry the security of the seed on their own.

Technical detail

Coinkite states that on affected firmware, COLDCARD hashed the device-generated seed together with every roll entered through Add Dice Rolls. The dice input is therefore an independent contribution rather than a cosmetic addition.

Coinkite quantifies it: 50 to 98 independent, private rolls contributed at least 128 bits from the dice alone, and 99 or more rolls contributed approximately 256 bits.

The qualifiers matter as much as the counts. The rolls must have been fair, independent and private. Coinkite is clear that if the rolls were recorded or exposed, or if you are uncertain how many you entered or which words you ended up using, the exception does not apply and you should migrate.

A dice-roll sequence is secret key material in its own right. Coinkite warns against photographing it, storing it digitally, or entering it into a networked computer.

Official source: Coinkite Mk3 Security Advisory

Independent research, not Coinkite guidance

Independent technical analysis

Other security researchers have published their own analyses. Coinkite links to some of them, but they are not Coinkite findings and they are not official guidance. They go further than the advisory in several places, and they may be revised as more work is done.

If you are deciding what to do, the official guidance above is the basis for that decision. What follows is context.

Detailed findings

Additional device scope

COLDCARD Mk2
Block places the Mk2 on the same confirmed vulnerable path as the Mk3 for firmware v4.0.0 through v4.1.9. Coinkite’s advisory does not cover the Mk2.

Independent analysis: Block Bitcoin Engineering and Security — not Coinkite guidance

Mk1 and pre-4.x firmware
Block assesses the Mk1 across all its released firmware, and the Mk2 and Mk3 through v3.2.2, as using the STM32 hardware generator directly and therefore falling outside this regression.

Independent analysis: Block Bitcoin Engineering and Security — not Coinkite guidance

Exported seeds and multisig

Seeds exported to another wallet
Block notes that a seed generated on an affected COLDCARD remains affected after it is moved to a different wallet. Restoring it elsewhere does not change how it was generated.

Independent analysis: Block Bitcoin Engineering and Security — not Coinkite guidance

Multisig quorums
Block states that where a multisig arrangement is composed exclusively of affected devices, the impact of the issue remains, and that a quorum of unaffected signers is needed to protect against it.

Independent analysis: Block Bitcoin Engineering and Security — not Coinkite guidance

Other generated secrets

Secrets other than wallet seeds
Block reports that the same generator was used for other values, including paper-wallet private keys, randomly generated Seed XOR masks, some cloning, USB, Key Teleport and Web2FA keys, generated Secure Notes passwords, and HSM local-code material. Block is explicit that this does not mean every feature carries the same severity. Coinkite’s advisory addresses wallet seeds.

Independent analysis: Block Bitcoin Engineering and Security — not Coinkite guidance

Attack-cost modelling

Attack-cost modelling
A separate attack-cost model for the affected generations has been published by the researcher LLFOURN and is linked from Coinkite’s technical deep dive.

Supporting model: LLFOURN — not Coinkite guidance

Unresolved disagreement

Where the two analyses do not agree

On two points the official advisory and the independent analysis reach different conclusions. Both positions are shown below with their own sources. This page does not resolve either disagreement, and it does not speculate about why the sources differ, because neither source explains it.

Compare both positions

Where the affected range begins

Which firmware version first contained the vulnerable path?

Coinkite’s position
Coinkite’s advisory begins the affected Mk3 range at firmware 4.0.1, released in March 2021, and runs it through 4.1.9 inclusive.

Official source: Coinkite Mk3 Security Advisory

Block’s position
Block states that v4.0.0 already contained the vulnerable path, and gives the Mk2 and Mk3 range as v4.0.0 through v4.1.9.

Independent analysis: Block Bitcoin Engineering and Security — not Coinkite guidance

What this means in practice: Neither source explains the difference, and this page does not attempt to resolve it. For an owner the distinction rarely matters in practice: telling 4.0.0 apart from 4.0.1 is not something most people can reconstruct years later, so anyone who generated a seed on a 4.x Mk2 or Mk3 from March 2021 onward is better served by treating themselves as potentially in scope.

Search space on Mk4, Mk5 and Q

How much unpredictability is left on the newer models?

Coinkite’s position
Coinkite estimates the effective search space at about 72 bits, short of the intended 128-bit target, and describes the figure as preliminary.

Official source: Coinkite Mk3 Security Advisory

Block’s position
Block calculates that once the fallback state and call history are fixed, a successful secure-element reseed leaves at most 2^32 distinguishable output streams — a considerably more pessimistic assessment.

Independent analysis: Block Bitcoin Engineering and Security — not Coinkite guidance

What this means in practice: The two estimates have not been reconciled publicly. This page presents both rather than choosing between them, and the guidance elsewhere on this page follows Coinkite’s figure because it is the official one.

Full analyses: Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware by Block Bitcoin Engineering and Security, and the attack-cost model published by LLFOURN.

Incident timeline

Only events that Coinkite has published, at the precision Coinkite published them. Coinkite gives the start of the affected range as a month rather than a specific day, so that is how it appears here.

  1. Affected range begins

    Coinkite identifies firmware 4.0.1 as the beginning of the affected Mk3 range, which runs through 4.1.9 inclusive.

    Official source: Coinkite Mk3 Security Advisory

  2. Public disclosure

    Coinkite publishes the Mk3 Security Advisory and a technical explanation of the entropy issue.

    Official source: Coinkite Mk3 Security Advisory

  3. Fixed firmware released

    Coinkite updates both posts. Fixed firmware is available for every affected model and release track, and Coinkite advises against generating a new seed on an affected model until the update is installed.

    Official source: Coinkite Mk3 Security Advisory

  4. Current status

    Investigation continues

    Coinkite states that its investigation is ongoing and that a formal technical review will be released as soon as possible.

    Official source: Coinkite Mk3 Security Advisory

Frequently asked questions

Grouped by the question you are most likely to be starting from.

Am I affected?

Firmware and migration

Dice, passphrases and multisig

Unauthorized activity and next steps

Takeaways from this incident

Bitcoin was not hacked.
Self-custody was not broken.

A wallet implementation created a single point of failure in the generation of certain secrets.

All six takeaways
The bitcoin network
Bitcoin’s consensus rules and cryptography are not implicated in any way. No protocol weakness was found and nothing about how bitcoin works has changed.
Self-custody as a principle
Holding your own keys still does what it is supposed to do. The principle is intact; one implementation of one step within it was not.
Where the failure actually sat
In the randomness available to a particular firmware build at the moment it created a seed. Not in signing, not in storage, not in the secure elements protecting the device, and not in how the wallet held funds afterwards.
Why one mistake reached so many seeds
Every seed generated through the affected path drew on the same faulty source of randomness. One integration mistake, in one library binding, applied to every seed that path produced.
Hardware-wallet trust
Self-custody removes the risk that someone else loses or freezes your bitcoin. It does not remove the need to ask how a specific tool works, who reviews it, and whether a claim about it can be independently verified. This incident is a reminder that the second set of questions still has to be asked.
Affected owners did nothing wrong
Choosing a well-reviewed, open-source, air-gapped hardware wallet from an established manufacturer was a reasonable decision, and it still is. Owners had no practical way to detect this from outside the device. Coinkite states it was unaware of the bug, and that a review using current AI tooling a few weeks earlier did not find it either.

What to take from this

Not your entropy, not your coins

COLDCARD owners did what self-custody asks of them: they generated and protected their own keys. The failure occurred inside the process they reasonably trusted to generate those keys securely.

The practical lesson is about verification rather than blame. The randomness behind a seed is invisible from the outside: a weak seed and a strong one produce word lists that look identical. That is precisely why independent review of how secrets are generated matters, and why the option to supply your own entropy exists at all.

Sources and update history

Every source is labelled with its classification, because official guidance and independent research are not interchangeable here.

Official sources

Published by Coinkite. These are the basis for every factual claim about this issue on this page. Where Bitcoin Well recommends something Coinkite does not, it is labelled as ours.

6 official sources

Independent analysis

Published by researchers other than Coinkite. Referenced only in the independent technical analysis section, and not official COLDCARD guidance.

2 independent sources

Update history for this page

Dated changes
  • Page published. Reflects Coinkite’s advisory as updated on July 31, 2026 at 12:39 p.m. EDT, which added fixed firmware for every affected model and release track and extended the affected scope to seeds generated on Mk4, Mk5 and Q before those releases. Later the same day the guidance was reframed: moving your bitcoin to a wallet created on a device this issue never affected is now presented as Bitcoin Well’s strong recommendation, with Coinkite’s route of updating the firmware and migrating to a new seed on the COLDCARD as the other option. No official finding changed, and the firmware versions and migration steps are unchanged.

Bitcoin Well is not affiliated with Coinkite or COLDCARD. If the official guidance has changed since this page was last verified, the official advisory takes precedence over anything written here.