Is your COLDCARD wallet affected?

On July 30, 2026, a security flaw was found in Coldcard wallets.

If you have bitcoin on a COLDCARD and you are not sure whether this applies to you, start here.

COLDCARD wallet risk assessment

How it works
  • Only takes Yes, No and I don’t know as answers
  • Skips any question your earlier answers make irrelevant
  • Ends with a summary and a recommended next step

This assessment does NOT ask for sensitive wallet information.

Your answers stay in this browser tab and disappear when you exit the page.

On July 30, 2026, Coinkite disclosed that certain COLDCARD firmware versions created wallet seeds with less genuine randomness behind them than intended. Coinkite has since released corrected firmware for every affected model, but a firmware update cannot repair a seed that already exists. If your seed was generated by affected firmware, your bitcoin needs to end up under keys this issue never touched.

For peace-of-mind, our recommendation is to move your bitcoin to a new wallet on a device that was not affected by this issue.

Current status

Coinkite has published a security advisory and has released fixed firmware for every affected model and release track. Coinkite has destroyed its remaining inventory manufactured with the vulnerable firmware and halted shipment. Coinkite states that its investigation is ongoing and that a technical postmortem will follow.

Last verified

Official source: Coinkite Coldcard Security Advisory

What Coinkite has acknowledged

Coinkite states plainly that customers have lost money. It says the threat remains real and ongoing, that time is of the essence, and that its legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support identifying those responsible. In the technical deep dive Coinkite describes the reduced search space as a direct security risk rather than a theoretical possibility for funded wallets with neither the dice entropy nor a qualifying passphrase.

Coinkite asks owners of affected devices not to dispose of them, because a device may become essential if funds are recovered.

Recommended actions

If your seed was generated by affected firmware, our advice is direct: move your bitcoin to a new wallet, created on a device that was not affected by this issue.

Recommended

Send your bitcoin to a new wallet

Move your funds to a wallet created on a device or application that this issue never affected.

Why we recommend it

  • You do not have to reconstruct which firmware was running when the seed was generated, how many dice rolls you entered, or whether your passphrase is strong enough
  • The affected scope has already widened twice since disclosure, most recently to the Mk2, and this route does not depend on where it settles
  • The published estimates of how much unpredictability is left have not been reconciled, and this route does not depend on which one is right
  • Nothing about it requires trusting the same generator a second time

What it involves

  • Set up a wallet on a device or application this issue never affected
  • Record and verify the new backup, along with a receive address shown on the new device itself
  • Send a small test amount first, then move the rest, keeping the old backup until the full balance has confirmed

The care each step needs is the same as for any migration, and the migration overview below sets out the full sequence.

This is our own recommendation rather than Coinkite guidance. We are not pointing you at a particular brand, and Bitcoin Well never holds your bitcoin.

At your own risk

Update firmware and migrate

Coinkite’s official guidance

Coinkite directs affected owners to install the corrected firmware, generate a completely new seed on it, and move their funds to that new wallet. It is a legitimate route and it is the one the official documentation supports in detail.

What it involves

  • Install the fixed firmware for your model and release track
  • Generate a completely new seed on that firmware
  • Verify the new backup and a receive address on the device, then test with a small amount before moving the rest

What to weigh

It returns you to the same device family whose generator is still being examined. Coinkite states that its investigation is ongoing and that a technical postmortem is still to come, so this route asks you to rely on a fix whose review is not yet complete.

Coinkite itself now points owners who need a device sooner than it can supply one, or who want an alternative while they decide, to other established hardware wallet makers and collaborative custody providers. Moving to an unaffected device is no longer a route only we suggest.

The fixed firmware versions and the migration overview are below.

Who may be affected

Everything here is what Coinkite has published. Where Coinkite has not addressed something, that is said plainly rather than filled in from elsewhere.

How Coinkite states the risk, and where we are more cautious

Coinkite’s advisory now puts it conditionally: funds controlled by a seed from affected firmware are at risk if the seed was created without at least 50 independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP39 passphrase.

On the dice we follow Coinkite exactly: enough independent, private rolls and the assessment places the seed outside the issue. The passphrase is where we are more cautious. An affected seed stays on the migration path here regardless, with a strong passphrase lowering the urgency rather than settling the question, because a passphrase protects the wallet built on top of a weak seed, but it does not make the seed itself unguessable. Coinkite still advises passphrase users to migrate as soon as practical, so the two readings end in the same action. Where you land under Coinkite’s own wording is stated plainly throughout, so you can act on the official reading if you prefer.

Official source: Coinkite Coldcard Security Advisory

Device and firmware scope

Which models and release tracks Coinkite has addressed.

COLDCARD Mk2 and Mk3Affected
Coinkite warns everyone who generated a seed on an Mk2 or Mk3 running firmware 4.0.1 through 4.1.9 inclusive that their funds are at risk, unless the seed was created with at least 50 independent, private dice rolls or the funded wallet is protected by a strong, unique BIP39 passphrase. Coinkite estimates the effective search space at about 40 bits and describes that figure as preliminary.
Preliminary estimate
COLDCARD Mk4, Mk5 and QAffected
Seeds generated before the fixed release for the relevant track are also affected, with about 72 bits of entropy rather than the expected 128, subject to the same dice and passphrase conditions. Coinkite describes the impact on these models as not as severe as on the Mk2 and Mk3 but still serious.
Preliminary estimate
Standard and Edge firmware tracksDepends on your setup
Standard and Edge are separate release tracks with separate fixes. Coinkite warns specifically against assuming that an older Edge 6.x release is fixed merely because its version number is higher than the standard release.
Confirmed by Coinkite
TAPSIGNER, OPENDIME and SATSCARDOutside the disclosed issue
Coinkite states that these products are not affected by this bug because they use different codebases.
Confirmed by Coinkite
COLDCARD Mk1Not addressed by Coinkite
Coinkite’s advisory addresses the Mk2, Mk3, Mk4, Mk5 and Q. It does not address the Mk1 either way. Independent researchers have published findings about the earliest model; those are summarised separately below and are not Coinkite guidance. See the independent analysis.
Not addressed by Coinkite

Setup and seed-generation factors

How your seed was created, and what can change the answer.

Seeds generated by affected firmwareDepends on your setup
Exposure depends on the firmware that was running when the seed was generated, not on when the device was bought. Coinkite is explicit that updating the firmware does not change or repair a seed that already exists.
Confirmed by Coinkite
Seeds imported from another sourceOutside the disclosed issue
The disclosed issue concerns secrets generated by affected COLDCARD firmware. A seed that was generated elsewhere and then imported was not produced by the affected generator, so it is outside this particular issue. That is a narrow statement about this issue only and says nothing about the security of wherever that seed did come from.
Confirmed by Coinkite
Seeds supplemented with independent dice entropyDepends on your setup
On affected firmware, COLDCARD hashed the device-generated seed together with every roll entered through Add Dice Rolls, so the issue does not remove entropy you supplied yourself. With at least 50 fair, independent rolls that were never recorded or exposed, Coinkite does not consider the resulting seed at risk from this issue alone. With fewer than 50 rolls, or if you do not remember, Coinkite directs you to migrate.
Confirmed by Coinkite
BIP39 passphrasesDepends on your setup
Coinkite states that a strong, unique BIP39 passphrase adds an independent barrier, and that the reduced seed entropy alone is not enough to reach funds in that passphrase wallet because an attacker must also discover the passphrase. It has to be strong, unique, secret and stored separately from the seed backup. Coinkite is explicit that a short, common, patterned, quoted, reused, exposed or uncertain passphrase does not qualify, and advises migrating to a newly generated seed as soon as practical even with a strong one.
Confirmed by Coinkite
Single-signature and multisig walletsNot addressed by Coinkite
Coinkite’s advisory is written in terms of the seed that a device generated, and does not address multisig configurations either way. Independent researchers have published an assessment of multisig quorums; it is summarised separately below and is not Coinkite guidance. See the independent analysis.
Not addressed by Coinkite

If you are not sure

Coinkite’s own guidance on the dice exception resolves uncertainty toward migrating, and the same reasoning applies more broadly. Not being able to reconstruct how a seed was created years ago is a common position, and owners who appear to fall outside the confirmed scope can still choose to move to newly generated entropy — either of the routes above is open to you, chosen rather than directed.

Moving funds carries its own handling risks, so hurrying it is not the cautious option. What moving to new keys settles is the narrow question of how the seed was generated; it does not answer any other question about a wallet.

Official source: Coinkite Coldcard Security Advisory

Updating is not migrating

These are two different actions with two different effects. This is the point most likely to be misunderstood.

Updating firmware

Changes how the device generates secrets from this point forward. It is a fix for the future.

  • Protects future seed generation on that device
  • Does not alter, repair or strengthen a seed that already exists

Migrating a seed

Changes which seed your funds live under. It replaces the entropy behind your wallet entirely.

  • Creates entirely new wallet entropy on corrected firmware
  • Requires moving your funds to the new wallet
  • Is not accomplished by installing an update

Fixed firmware by model and release track

If you are staying on your COLDCARD, this is where to start. Standard and Edge are separate release tracks with separate fixes, and Coinkite warns specifically against assuming that an older Edge 6.x release is fixed just because its version number is higher than the standard release. Install the fixed release for the track you actually use.

Official source: Coinkite Coldcard Security Advisory

If you are unsure which page applies to your device, Coinkite’s downloads index lists every model.

Migration overview

A summary of the sequence Coinkite publishes, in two phases. The first step is specific to staying on a COLDCARD; everything after it applies just as much when the new wallet lives on a different device. It is not a substitute for the advisory, which includes per-model detail and the two special cases summarised below.

Read Coinkite’s official instructions before you begin

Phase 1

Prepare and verify

Get onto fixed firmware and prove the new wallet is what you think it is, before any funds are involved.

  1. Install verified fixed firmware

    Confirm the fixed version for your model and release track is actually installed before going further.

  2. Generate a completely new seed

    Coinkite states that the fixed firmware’s device-generated seed is sufficient, and that dice rolls are optional rather than required to address this issue.

  3. Record and verify the new backup

    Verify the written backup and the wallet fingerprint before any funds are deposited. If you set a BIP39 passphrase, back it up exactly and separately from the seed words: Coinkite warns that every passphrase produces a valid wallet, including one containing a typo, so the fingerprint is what tells you which wallet you are actually in.

  4. Power-cycle, then verify a receive address on the device screen

    Coinkite directs you to power-cycle the COLDCARD before checking the wallet fingerprint and a receive address. Read the address from the device screen rather than trusting only what your computer or phone displays.

Phase 2

Test and complete the move

Prove the new wallet works with a small amount first, then move the rest and only then retire the old backup.

  1. Send a small test transaction

    A small amount first, so a mistake is a small mistake rather than the whole balance.

  2. Confirm the new wallet works correctly

    Check that the test funds arrived and that the wallet fingerprint still matches what you recorded.

  3. Transfer the remaining balance

    Only once the new wallet has demonstrably worked end to end.

  4. Retain the old backup until the migration is fully confirmed

    Keep it until the complete balance has arrived and confirmed in the new wallet.

Two special cases Coinkite documents separately

Both were added to the advisory on August 1 and both apply to the Mk2 and Mk3. Read the advisory itself before attempting either.

If the Mk2 or Mk3 is your only device

Firmware 4.2.0 lets the Mk2 and Mk3 generate a replacement seed correctly, so you do not need to buy a newer COLDCARD to migrate. Coinkite publishes a seven-step procedure for doing it on a single device, which means restoring the old seed and the new one in turn as you verify each stage and move the funds.

Coinkite is clear that a second device with fixed firmware is easier and safer if you have one. Verify the written backup and fingerprint of each seed before erasing either from the device.

Official source: Coinkite Coldcard Security Advisory

Optional dice-only replacement seed

After updating to 4.2.0, Coinkite documents an optional path that creates a replacement seed without using the device’s random-number generator at all: Import Existing, then Dice Rolls, entering at least 99 independent rolls of a fair six-sided die. That path hashes the roll sequence directly.

This is an advanced procedure and it is optional — Coinkite states the corrected New Wallet flow is sufficient. The roll sequence is secret key material: never photograph it, store it digitally, or enter it into a networked computer.

Official source: Coinkite Coldcard Security Advisory

Independent research, not Coinkite guidance

Independent technical analysis

Other security researchers have published their own analyses. Coinkite links to some of them, but they are not Coinkite findings and they are not official guidance. They go further than the advisory in several places, and they may be revised as more work is done.

If you are deciding what to do, the official guidance above is the basis for that decision. What follows is context.

Detailed findings

Additional device scope

Mk1 and pre-4.x firmware
Block assesses the Mk1 across all its released firmware, and the Mk2 and Mk3 through v3.2.2, as using the STM32 hardware generator directly and therefore falling outside this regression.

Independent analysis: Block Bitcoin Engineering and Security — not Coinkite guidance

Exported seeds and multisig

Seeds exported to another wallet
Block notes that a seed generated on an affected COLDCARD remains affected after it is moved to a different wallet. Restoring it elsewhere does not change how it was generated.

Independent analysis: Block Bitcoin Engineering and Security — not Coinkite guidance

Multisig quorums
Block states that where a multisig arrangement is composed exclusively of affected devices, the impact of the issue remains, and that a quorum of unaffected signers is needed to protect against it.

Independent analysis: Block Bitcoin Engineering and Security — not Coinkite guidance

Other generated secrets

Secrets other than wallet seeds
Block reports that the same generator was used for other values, including paper-wallet private keys, randomly generated Seed XOR masks, some cloning, USB, Key Teleport and Web2FA keys, generated Secure Notes passwords, and HSM local-code material. Block is explicit that this does not mean every feature carries the same severity. Coinkite’s advisory addresses wallet seeds.

Independent analysis: Block Bitcoin Engineering and Security — not Coinkite guidance

Attack-cost modelling

Attack-cost modelling
A separate attack-cost model for the affected generations has been published by the researcher LLFOURN and is linked from Coinkite’s technical deep dive.

Supporting model: LLFOURN — not Coinkite guidance

Unresolved disagreement

Where the two analyses do not agree

On two points the official advisory and the independent analysis reach different conclusions. Both positions are shown below with their own sources. This page does not resolve either disagreement, and it does not speculate about why the sources differ, because neither source explains it.

Compare both positions

Where the affected range begins

Which firmware version first contained the vulnerable path?

Coinkite’s position
Coinkite’s advisory begins the affected Mk2 and Mk3 range at firmware 4.0.1, released in March 2021, and runs it through 4.1.9 inclusive.

Official source: Coinkite Coldcard Security Advisory

Block’s position
Block states that v4.0.0 already contained the vulnerable path, and gives the Mk2 and Mk3 range as v4.0.0 through v4.1.9.

Independent analysis: Block Bitcoin Engineering and Security — not Coinkite guidance

What this means in practice: The two now agree on which models are affected — Coinkite added the Mk2 on August 1 — and differ only by a single version at the start of the range. Neither source explains that difference, and this page does not attempt to resolve it. For an owner the distinction rarely matters in practice: telling 4.0.0 apart from 4.0.1 is not something most people can reconstruct years later, so anyone who generated a seed on a 4.x Mk2 or Mk3 from March 2021 onward is better served by treating themselves as potentially in scope.

Search space on Mk4, Mk5 and Q

How much unpredictability is left on the newer models?

Coinkite’s position
Coinkite estimates the effective search space at about 72 bits, short of the intended 128-bit target, and describes the figure as preliminary.

Official source: Coinkite Coldcard Security Advisory

Block’s position
Block calculates that once the fallback state and call history are fixed, a successful secure-element reseed leaves at most 2^32 distinguishable output streams — a considerably more pessimistic assessment.

Independent analysis: Block Bitcoin Engineering and Security — not Coinkite guidance

What this means in practice: The two estimates have not been reconciled publicly. This page presents both rather than choosing between them, and the guidance elsewhere on this page follows Coinkite’s figure because it is the official one.

Full analyses: Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware by Block Bitcoin Engineering and Security, and the attack-cost model published by LLFOURN.

Frequently asked questions

Grouped by the question you are most likely to be starting from.

Am I affected?

Firmware and migration

Dice, passphrases and multisig

Unauthorized activity and next steps

Takeaways from this incident

Bitcoin was not hacked.
Self-custody was not broken.

A wallet implementation created a single point of failure in the generation of certain secrets.

All six takeaways
The bitcoin network
Bitcoin’s consensus rules and cryptography are not implicated in any way. No protocol weakness was found and nothing about how bitcoin works has changed.
Self-custody as a principle
Holding your own keys still does what it is supposed to do. The principle is intact; one implementation of one step within it was not.
Where the failure actually sat
In the randomness available to a particular firmware build at the moment it created a seed. Not in signing, not in storage, not in the secure elements protecting the device, and not in how the wallet held funds afterwards.
Why one mistake reached so many seeds
Every seed generated through the affected path drew on the same faulty source of randomness. One integration mistake, in one library binding, applied to every seed that path produced.
Hardware-wallet trust
Self-custody removes the risk that someone else loses or freezes your bitcoin. It does not remove the need to ask how a specific tool works, who reviews it, and whether a claim about it can be independently verified. This incident is a reminder that the second set of questions still has to be asked.
Affected owners did nothing wrong
Choosing a well-reviewed, open-source, air-gapped hardware wallet from an established manufacturer was a reasonable decision, and it still is. Owners had no practical way to detect this from outside the device. Coinkite states it was unaware of the bug, and that a review using current AI tooling a few weeks earlier did not find it either.

What to take from this

Not your entropy, not your coins

COLDCARD owners did what self-custody asks of them: they generated and protected their own keys. The failure occurred inside the process they reasonably trusted to generate those keys securely.

The practical lesson is about verification rather than blame. The randomness behind a seed is invisible from the outside: a weak seed and a strong one produce word lists that look identical. That is precisely why independent review of how secrets are generated matters, and why the option to supply your own entropy exists at all.

Sources and update history

Every source is labelled with its classification, because official guidance and independent research are not interchangeable here.

Official sources

Published by Coinkite. These are the basis for every factual claim about this issue on this page. Where Bitcoin Well recommends something Coinkite does not, it is labelled as ours.

7 official sources

Independent analysis

Published by researchers other than Coinkite. Referenced only in the independent technical analysis section, and not official COLDCARD guidance.

2 independent sources

Update history for this page

Dated changes
  • Brought the page up to date with Coinkite’s advisory as updated on August 1, 2026 at 2:35 p.m. EDT and with the further update Coinkite published on August 2. The substantial change is the Mk2: Coinkite now covers it on the same 4.0.1 through 4.1.9 terms as the Mk3, with firmware 4.2.0 as the fix for both, so the Mk2 has moved out of the independent-analysis section and into the official scope throughout. The risk assessment follows: an Mk2 seed is now assessed against Coinkite’s advisory rather than Block’s research, is offered the dice exception that was previously withheld, is asked the same 4.0.0 lower-bound question as the Mk3, and is pointed at a real fixed release instead of being told none exists. Coinkite now also states the risk conditionally — at risk unless the seed carries at least 50 independent, private dice rolls or the wallet has a strong, unique passphrase — which is set out alongside our own more cautious reading rather than replacing it. Added Coinkite’s newly documented single-device Mk2 and Mk3 migration and its optional dice-only replacement seed, its expanded passphrase requirements, its instruction not to dispose of an affected device, and two extra verification steps. The exploitation section was reframed: Coinkite has now acknowledged customer losses itself, so that acknowledgement is presented as official rather than left in the independent-research section, where only Block’s account of active exploitation now sits. No firmware version changed for the Mk3, Mk4, Mk5 or Q.
  • Page published. Reflects Coinkite’s advisory as updated on July 31, 2026 at 12:39 p.m. EDT, which added fixed firmware for every affected model and release track and extended the affected scope to seeds generated on Mk4, Mk5 and Q before those releases. Later the same day the guidance was reframed: moving your bitcoin to a wallet created on a device this issue never affected is now presented as Bitcoin Well’s strong recommendation, with Coinkite’s route of updating the firmware and migrating to a new seed on the COLDCARD as the other option. The interactive risk assessment was added the same evening and now opens the page: it asks how your seed was created and works out whether it falls inside the scope that has been identified, separating throughout what Coinkite has stated from what independent researchers have found and from where the conclusion is our own conservative reading. It runs entirely in your browser — nothing is submitted, stored or transmitted, no sensitive wallet information is requested, and reloading the page clears your answers. No official finding changed, and the firmware versions and migration steps are unchanged.

Bitcoin Well is not affiliated with Coinkite or COLDCARD. If the official guidance has changed since this page was last verified, the official advisory takes precedence over anything written here.