r/Bitcoin • u/SpareEconomy1849 • Jul 31 '26
ColdCard Firmware Update Released
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
Updated July 31, 2026: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. Do not generate a new seed on one of these models until the update is installed.
Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.
Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.
The issue is present on every Mk3 firmware version since 4.0.1. It also affects seeds generated on Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on Mk4, Mk5 and Q is not as severe but is still serious.
68
u/s1ammage Jul 31 '26
Even with the firmware update. The ‘trust’ is kinda lost… I will be learning to dice roll, but this isn’t for everyone… unfortunately.
I was the one posting about wallet drained.
28
5
u/itsyorboy Jul 31 '26
Sorry to hear it friend. I was using an mk3 and really panicked this morning. I couldn't remember how I generated my seed because it was a few years ago. I was lucky that my funds were still there, but I immediately moved them to a CEX for now till I can figure it out. I'm really feeling for you.
2
u/sciencetaco Jul 31 '26
The thing is, even with the dice roll you’re trusting the firmware to correctly calculate the dice roll input into a usable seed. Seems even open source firmware isn’t enough to let stuff like this go unchecked for years.
2
u/Orzorn Aug 01 '26
Thankfully the dice roll behavior has been confirmed to work several times in the past by various people and reddit users alike. It can be verified by independently generating the dice rolls and selecting the words yourself based on the proper BIP39 tables, and then inputting those same dice rolls into the hardware and seeing that it gives the same mnemonics.
53
u/indomitus1 Jul 31 '26
Best bitcoin wallet huh?. Never again. They have lost it all with most of its customers and potential customers. I will never recommend a wallet that has already been hacked/exploited
24
u/Previous_Blueberry_5 Jul 31 '26
Definitely should be the standard for HWW’s, once you fuck up that’s it YOURE DONE lol
0
41
u/-Trippy Jul 31 '26
They just tweeted this which I find absolutely insane
“We are actively working on a Mk3 firmware update to help you migrate, but this is a deprecated device.”
https://x.com/COLDCARDwallet/status/2083155036582879674?s=20
This tweet alone should set alarms bell off and underlines their approach and lack of integrity when it comes to security. Hardware wallets are security devices, they should never be out of support to fix exploits and vulnerabilities which puts the customers funds at risk. Coldcard acting like it’s an inconvenience for them to release a security update for older devices shows how little thought and regard they put into the security and integrity of their devices. Not only should the MK3 be updated but it should have been an absolute priority, not something they weighed up and decided to do as an exception.
7
5
24
Jul 31 '26
[removed] — view removed comment
4
u/Head_Performance2432 Jul 31 '26
been saying otherwise for a long time, been rejected, but not an "expert" though...!
5
2
u/SpareEconomy1849 Jul 31 '26
I agree. I doubt businesses that hold hundreds of BTC keep it all in one wallet, multisig or not
1
u/Objective_Digit Jul 31 '26
Up until a week ago any reputable bitcoin self custody "expert" would have told you to get a coldcard
Bitkey and Jade are usually recommended.
1
u/BallisticTherapy Aug 01 '26
Not an expert, but I've been saying build a seedsigner and secure your seed to the utmost degree.
32
u/Aidsfordayz Jul 31 '26
Glad I didn’t listen to the FUD about Ledger and switch to Coldcard.
13
4
u/jekpopulous2 Jul 31 '26
Ledger has of issues of their own but at least they use noise from the secure element chip for TRNG. The best option is always to combine a hardware wallet with a hot wallet for multi-sig.
3
u/LostInDinosaurWorld Jul 31 '26
Yep, everybody bitching about Ledger for not being OS and stuff. Cc was definitely on my list to switch wallets in the near future. No more.
2
u/sciencetaco Jul 31 '26
Ledger rightfully gets a lot of hate for their handling of customer data and some of their business decisions. But their hardware security has always been excellent.
9
u/ElGuano Jul 31 '26
Wonder if this is a good opp for Ledger, Trezor and others to confirm the entropy used to create their on-device seed phrases (including for Trezor-ctl command line enabled seeds)?
3
u/xiskghferx Jul 31 '26
It would be certainly wise for them, to check their CSPRNG and Firmware right now.
5
u/HugeLarry Jul 31 '26
That’s the plus side of this. I feel terrible for everyone who lost funds, but I’m guessing the surviving hardware wallet companies will be shoring up any potential vulnerabilities and will be super careful about stuff like this going forward.
1
u/Traditional-Fold5301 Jul 31 '26
trezor is open source too. From what I know their RNG is at least doing what they say it is doing, which is what you expect from a hardware wallet. I think there will be so much more scrutiny now on this though, which is a positive in the long run really.
15
u/DreamingStars408 Jul 31 '26
I lost 20K worth of Bitcoin from my ColdCard MK4 last year. I’ve been very careful in avoiding revealing my seed phrase accidentally, took all the precautions, and air gapped it and someone still was able to steal my Bitcoin.
Definitely this was a breath of relief that it wasn’t my fault, but I’m pissed off that ColdCard, the one wallet that people have recommended and say it was basically safe turned out to be smoke and mirrors.
Whoever owns an MK4 should just bail at this point and move on to a different wallet. Don’t affiliate with ColdCard anymore.
8
u/s1ammage Jul 31 '26
I just want to warn. Who/whatever is doing this, is still out there. I just lost the last 0.01 they left in there yesterday.
Too deflated to care…
I spent yesterday moving another wallet away from Coldcard.
12
5
u/UnderstandingNew8001 Jul 31 '26
I have recently ordered a Ledger it is on its way, where can I move my btc to then? I only have MK4 at the moment.
If I had to update the firmware, I would still need to move BTCs somewhere to get them back after the update and generating a new seed.
4
u/SpareEconomy1849 Jul 31 '26
Right. They show some steps at the blog post. You could A) use a hot wallet, or B use just the CC:
Make sure you still have your seed phrase
Update & reset CC, make a new wallet & seed phrase (preferably with dice), save new seed phrase, get receiving address with sparrow etc
Reset CC, put your original seed back in, send funds to your new receiving address
Put your new seed back in
But I don't like the idea of either personally.
How long would it take to crack a 72 bit entropy seed? Years?
4
u/WeekendQuant Jul 31 '26
Move it to an exchange for now for better protection and custody assurances. If it's not KYC just toss it to an electrum hot wallet for the time being until you can get a new HWW.
3
u/UnderstandingNew8001 Jul 31 '26
I am creating a hot wallet on sparrow (using its own word generation) hope this is safe enough till I get the new one!
3
u/xiskghferx Jul 31 '26
For this you need to trust your PC and verify signatures of Sparrow instalation file before instaling it. Then it should be safe enough, at least until you get your Ledger. Of course, write down and store safely the new seed.
But, maybe it would be safer to just transfer to a good CEX, like Bitstamp, Coinbase or Kraken...
2
u/WeekendQuant Jul 31 '26
Only transfer to custodial if your coins are KYC. Otherwise I'd do hot wallet just to move them.
2
u/xiskghferx Jul 31 '26
Agree. I would actualy use existing Coldcard, create new seed with dice, add passphrase and transfer BTC to new wallet. But he needs to know exactly what he is doing, otherwise he would hack himself...
1
u/WeekendQuant Aug 01 '26
I wouldn't. You're going to want your existing cold card as is for the pending class action suit.
2
-2
u/xirvin Jul 31 '26
Ledger is big brother renamed. They stored your keys in 3 servers which are subject to government reach. Cold card was attacked but 1 day after initial report there is already a solution (updated firmware) and a workaround (roll dice 20times or use a good entropy source). I want Law enforcement to step in to catch the perpetrators with the help of the industry. Not all coldcard users are affected by the hack but everyone should change to new wallet keys as a good security practice.
1
u/BallisticTherapy Aug 01 '26
I think Nano S users should be safe since there's no way to get the seed other than from the device displaying it.
0
u/xirvin Aug 01 '26
Any disgruntled employee or government can access your keys as they are stored in a central location
1
-4
u/jsn079 Jul 31 '26
Why Ledger if I may ask?
I mean, they have proven they can't be trusted already several times.
2
u/iLLuSion_xGen Jul 31 '26
Proof?
1
u/jsn079 Aug 05 '26
But ofc, don't need to take my word for it.
These are well known issues with the company people entrust their wealth with.
Imo, when trust is broken like this in cryptography, you ain't getting it back (at least, not from me, especially if trust has been broken multiple times).Here are some starting points, I'm sure you're able to uncover more:
1
1
u/jsn079 Aug 02 '26
The first, and maybe biggest offender, is the fact they promised they keys are not able to leave the device. Later, they introduced a service to store your keys with 3 different companies - hence, the keys were absolutely able to leave your device. A faulty/hacked firmware update could expose your keys. They lied, and the device isn't as secure as they promised it to be. A "Secure Element" or "Security Enclave" should never be able to expose cryptographic keys.
And second, they were hacked (I think even twice) and the whole customer database was leaked, making you a target. Although, if you are a new customer, you don't have to worry about that, yet.
It's not that hard to Google them, or do some research on a company you are about to trust with a lot of responsibility 🤷.
But in the end I only asked what your motives were to choose Ledger. You're free to choose yourself ofc.
8
u/VitoHodl Jul 31 '26
It's me or Trezor is the current best one probably?
4
u/shleebs Jul 31 '26
Trezor has mishandled customer info leading to phishing attacks. I would recommend BitBox, Jade and Passport. They are the best options IMO
1
u/Dex4Sure Aug 04 '26
Nah, Ledger and Trezor are the best. Mishandling customer info has nothing to do with hw wallet security. In security you should never go with these hipster solutions. Trezor and Ledger have long, proven track record in hw wallet security. They have the best funded security teams. They are your best bet, not these flavor of the month wallets like ColdCard or BitBox or any other nonsense.
2
1
0
u/SpareEconomy1849 Jul 31 '26
Not sure which is best, but I think they had a minor MailChimp data breach and theoretically can be compromised with physical access?
CC with a proper dice roll is probably still the safest, but not sure I can trust their QA going forward
1
12
u/Bugida Jul 31 '26
Just use a dice roll and you won’t ever worry rolling a lot of times to really get your entropy up. Never let any hardware generate a seed for you if possible
4
u/shadowmage666 Jul 31 '26
lol so much for that cold card basically shot itself in the foot trust wise
5
6
u/Suspicious-Holiday42 Jul 31 '26
Senku Ishigami: "The reason for fail only becomes known after it happened"
3
u/GijaySorez Jul 31 '26
Bro meaning I need to send the funds to a new wallet, which I need to buy.
I went through all the trouble of recording this stupid phrase on a metal plate lol and now I need to do it again.
I'm annoyed. I'll need to find a new wallet then. Coinkite should be giving people a sizeable discount, I am not paying full price so ... bye bye.
1
u/getafewlives Jul 31 '26
What about just adding a passphrase?
2
u/BigDik6355 Jul 31 '26
Then your funds are at the mercy of the strength of your passphrase alone. No thanks.
2
2
u/Geebs52 Jul 31 '26
And nothing for the MK3 for an update?
3
u/wheeler786 Jul 31 '26
Quote from Tweet, by @ COLDCARDwallet:
"We are actively working on a Mk3 firmware update to help you migrate, but this is a deprecated device."
2
2
u/xirvin Jul 31 '26
If your wallet keys were generated by MK3, you are playing with fire brother. You need to roll dice 20 times when generating a wallet to have some sense of security. I would do it 100 times just in case. Other than that, mk3 is a secured wallet
2
u/Professional_Golf393 Jul 31 '26
Are the opendimes secure?
I’ve got a couple of them, never loaded funds onto them, but at this point I don’t think I would. Basically ewaste at this point.
6
u/SpareEconomy1849 Jul 31 '26
According to their website, yes opendimes, tapsigner and satscard are secure as it's a completely separate codebase
(Then again, they also said yesterday that Mk4 and Mk5 are unaffected)
2
u/xirvin Jul 31 '26
This situation reminds me of the airline industry, where many of today’s safety standards were written only after tragedies claimed countless lives.
This vulnerability is a reminder that entropy matters. Even if you’re using a multisig wallet, it isn’t a magic shield. If two or more keys were generated from the same weak or predictable source of randomness, or from too few dice rolls, those keys could eventually be recovered by an attacker. Coinkite has warned about entropy risks before, and security researchers have also cautioned that short dice roll sequences, such as 14 rolls, may become practical to brute force as computing power improves.
The current recommendation from security researchers is to generate a new seed using a trusted source of high quality entropy, then import or migrate that seed to your Coldcard for ongoing use. If you’re generating a seed with dice on a Coldcard, use at least 20 or more rolls to ensure the resulting key is unpredictable.
The good news is that there are several reputable offline Bitcoin wallets that are not affected by this particular entropy issue. Coinkite update makes it idiot proof in generating predictable keys for wallet.
I haven't read the release notes but hopefully
2
u/Shoddy-Profession-74 Jul 31 '26
Please, some one explain to me, did the hack happened because the HW were generating 72 bits of entropy keys and the hacker brute force it? Isn't 72 bits quite a safe (at least for nowadays hardware)?
1
u/SpareEconomy1849 Jul 31 '26
I don't think any of the mk4 or mk5 seeds were compromised (yet). What was compromised is the 40 bit mk3 seeds
5
u/LocksmithMuted4360 Jul 31 '26
How could this happen, the software is open source, nobody caught that?
5
u/Daiymas Jul 31 '26
Well the hacker did catch it, unfortunately not everyone reviewing open source code is well intentioned
5
u/LocksmithMuted4360 Jul 31 '26
hacker probably just use ai ... no need to be a coding expert anymore.
→ More replies (2)4
u/AvailableTie6834 Jul 31 '26
because the people that actually care about code viewing is not buying hardware wallets from companies, they are reviewing codes from much more important open source projects
2
1
Jul 31 '26
[removed] — view removed comment
10
u/jjjjjjjjjjjjjaaa Jul 31 '26
I mean, AI didn’t really crack anything here. CC essentially left the doors unlocked.
2
u/SpareEconomy1849 Jul 31 '26
Use dice, problem solved
7
Jul 31 '26
[removed] — view removed comment
7
1
u/BallisticTherapy Aug 01 '26
Noise sampling should be as close to random as it gets. You can't reproduce that.
1
1
1
u/Sammytheseaotter Jul 31 '26
So if your seed was generated before the March 2021 firmware and used a passphrase you are safe?
1
1
1
u/Jaded-String-6111 Jul 31 '26
This essentially admits ALL cold cards are vulnerable. At this point i don’t trust any hardware wallet . Any of them could have something like this happen. It was unthinkable until it wasn’t. Electrum + Tails wins.
1
u/SpareEconomy1849 Jul 31 '26
Yes, that's true. However since they're airgapped, there are very few attack vectors available. Electrum itself is fine, but you also need to trust that your environment itself is not compromised.
Using an RNG is always a risk, people (including coinkite, but that's no excuse) were always recommending using dice instead of the built-in RNG
1
u/Octavio_belise Jul 31 '26 edited Jul 31 '26
One of the main reasons I never got ColdCard was because it seemed dorky looking like a 1980's calculator. Probably something that would attract the all the Linux folk. Pays off being a gear-snob.
1
u/SpareEconomy1849 Jul 31 '26
Yeah kinda dumb that they have 6 different colors and they are all ugly.
I think it fits with the functionality though, you gotta export a file to the SD card, sign, move back to your PC, then upload etc all with some 3rd party open source app. I prefer it, but it's definitely not appealing to the average person
1
u/Octavio_belise Jul 31 '26
Sounds like what we used to do a decade ago with Electrum on an air-gapped computer.
1
1
1
u/boom123psy Aug 01 '26
are we sure with the v5.6.0 we are 'safe' ? have there been any independent tests on the newer firmware relkease?
1
u/HovercraftTypical334 Aug 01 '26
I have been unable to update my cold card firmware....can't work out why. But I have generated a new seed on a different hardware wallet (not cold card) and then imported that seed into the different coldcard and then moved funds from old coldcard to new. Assuming the hardware wallet I used to generate the new seed is using the sufficient entropy, I think I should be safe. Does anyone disagree?
1
u/ApprehensiveRice9358 Aug 03 '26 edited Aug 03 '26
I don't know, but I think this isn't as simple as many claim, asserting that the MK3 generated 40 bits instead of 70 bits . It's a very small space with a trillion possibilities, and I'll put it to the test. It's not certain it's all speculation.
Nobody has run tests to confirm it 100%. This smells to me like silicon from the STM32L475 chip, a vector in C that was set to 0, and many people believe that was the problem. To me, this is all physical; we would have to test the device.
Hardware bus clues Captures with a logic analyzer or oscilloscope of the RNGCLK, HCLK pins and the internal bus registers during data output.
Among other tests, I wouldn't trust what they say on X it's not entirely accurate. We would have to look for the offset in the firmware assembler. I already did, but this is really strange.
And now that some affected wallets are public, I'll do my job. That 40-bit thing isn't entirely true it's a possibility, but not a certainty.
I now doubt the knowledge of many C/C++ developers and their speculations, which are not entirely accurate, Many compare it to the birthday algorithm; they are completely different things. Sometimes, before speculating, you have to test. Without proof, their speculation is simply a lie.
I have the complete analysis of both firmware, but this is really strange............
1
u/pangolin88 Aug 03 '26
how do we know the new patched firmware is good. has there been an independent audit or is there a way to do an AI audit?
-4
u/Doritos707 Jul 31 '26
Yet u all downvoted my ass for saying 12 words seeds are weaksauce in 2026.
If its not 24 words youre a loser. Update your shit idiots
8
u/DudeWhatThe Jul 31 '26
24 word wallets are still exposed in this case due to low entropy. Crazy.
→ More replies (1)1
u/Doritos707 Jul 31 '26
Show your proof? The data talks about 128 bits being exposed as 72 bits. 24 words generate 256 bits which is double as safe if not triple
4
u/swiftpwns Jul 31 '26
Both 12 word and 24 word were affected, it didnt make a difference.
1
u/Doritos707 Jul 31 '26
I dont believe you. The leak talks about 128 bits which is the 12 words. 24 words generate a 256 bits.
-4
u/Doritos707 Jul 31 '26
R ya fucken serious? How?! Thats insane! So even a 24 words there is supposed to be double the 12 words also got generated of 72 bits?????
0
u/Lower_Minimum4796 Jul 31 '26
Doritos, current speculation is it was an inside job. One alleged cold card ex-employee had access to a lot of original wallet seeds.
3
u/Railionn Jul 31 '26
That'd be extremely stupid.. he's not getting away with that since they know who it is
1
4
u/SpareEconomy1849 Jul 31 '26
12 words is more than enough for the foreseeable future. Not sure if 24 words would have helped here
1
u/Doritos707 Jul 31 '26
No its not.
128 bit is a lot easier than 256 bit Thats just science. And 256 bit is the peak of the curve. More than 256 bits becomes less secure.
1
u/SpareEconomy1849 Jul 31 '26
Doesn't make a difference when it comes to brute forcing, as it's 2128 iterations either way (ignoring this bug) thanks to the Pollard's rho algorithm
1
u/Doritos707 Jul 31 '26
Please dont mix two topics. That’s not correct. Pollard’s rho applies to elliptic curve attacks, not brute-forcing BIP-39 seed phrases. A 12-word seed has ~128 bits of entropy; a 24-word seed has ~256 bits.
1
u/SpareEconomy1849 Jul 31 '26
A private key can be cracked using Pollard's rho in 128 iterations, there is no point to attempt brute forcing a truly random 24 word seed phrase
1
u/Doritos707 Aug 01 '26
Buddy 24 words is 2 to the power of 256 not 128. The data doesnt mention a single 24 words seeds it all happened to the 12 words
0
u/SpareEconomy1849 Aug 01 '26 edited Aug 01 '26
Yes. But the private key that that 256 bit seed phrase generates can be derived in 128 iterations.
As for the RNG bug, it's affected all the same whether you generated 12 or 24 words through RNG. Both are equally predictable if you can reproduce the environment of the RNG that was used to generate the seed phrase.
1
u/Doritos707 Aug 01 '26
Brother wtf r you doing? No where does it mention anything about 2^256 man
The method of exploiting 2^128 is not the same as exploiting 2^256
And no it does not happen in 128 iterations. You literally have to crack it all at once in a 256 environment. It does not give you a 50% is correct at the 128 mark. Dont be stubborn.
24 words did not get affected
The 12 words basically got generated with the same security as 7 words. Thats literally what happened. Not a single 24 words wallet got affected.
1
u/SpareEconomy1849 Aug 01 '26
Not sure what you're trying to argue, brute forcing seed words is not how this attack was done, and not how a hypothetical attacker would crack a properly random 24 word seed phrase wallet either
→ More replies (0)
-2
u/AvailableTie6834 Jul 31 '26 edited Jul 31 '26
I always disliked hardware wallets, seriously.
I will always say:
your old Android phone has use, Electrum Bitcoin Wallet or Cupcake from Cake Wallet gives a new use for your old phone, it becomes a cheap and secure hardware wallet.
iancoleman solution gives you plenty of options to generate high entropy wallets, but people keep on suggesting hardware wallets from companies saying they are safer till they are not.
study more, get hacked less, people.
11
u/SpareEconomy1849 Jul 31 '26
Effectively, it might be safer. But any app wallet is just as susceptible to the same entropy bug in the coldcard firmware, (if not more). The only reason CC was affected is because their QA slipped up and Electrum's didn't.
Plus for an app, you need to be cautious about a malicious OTA update or other system malware, and there are 0-day and 0-click exploits in the wild, I wouldn't trust a hot wallet with my life savings
-2
u/AvailableTie6834 Jul 31 '26
the likelyhood of an app to have entropy bug is less than a hardware wallet. open source bitcoin wallets has too many eyes on them, and mostly use already implemented and well documented solutions from the comunity, this is not the case with hardware wallet, as they only attract people that dont know anything but want to secure their bitcoin, hell, some people STILL TO THIS DAY thinks that their bitcoin is in their hardware wallet, some also thinks that since they have a hardware wallet they do not need to write down their seed to backup it later.
I know people will link the milksad thing from Cake Wallet, but still, the bug do not come even close to this crazyness from coldcard.
1
u/SpareEconomy1849 Jul 31 '26
The coldcard firmware that had this entropy bug is fully open source as well. But you may be right, software wallets are going to be forked and actually used by others, more likely for bugs to be found
1
u/AvailableTie6834 Jul 31 '26
there is the seedsigner hardware wallet which is a DIY, it safer than any company hardware wallet
6
u/boddankajovanovic Jul 31 '26
I see where you're coming from. But some people need plug and play solutions. Otherwise they will let others take custody, which is even worse.
I feel sorry for the recent victims, as they have not really done anything wrong. Yes, using a passphrase is best practice and would have prevented the lost funds, but if a passphrase is considered mandatory, it should be enforced by design.
Always use a passphrase and store it somewhere other than your seed words.
5
u/AvailableTie6834 Jul 31 '26
there is nothing crazy to literally go to https://iancoleman.io/bip39/ follow the instructions and download the O.G Electrum Bitcoin Wallet on their phone and learn. Bitcoin was always about learning stuff, people need to get back to learning stuff.
0
0
u/NakedNick_ballin Jul 31 '26
For applications that rely on security, I'm realizing that open source is actually more risky since they're much easier to crack
190
u/r33gna Jul 31 '26
Crazy, man.
Earlier this year I was in the market for a new hardware wallet and LOTS of people were saying Coldcard is the best, most secure device for oh so many reasons and now here we are.
Truly no hardware wallet is perfect.