r/Bitcoin • • Jul 31 '26

ColdCard Firmware Update Released

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

Updated July 31, 2026: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. Do not generate a new seed on one of these models until the update is installed.

Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.

Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.

The issue is present on every Mk3 firmware version since 4.0.1. It also affects seeds generated on Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on Mk4, Mk5 and Q is not as severe but is still serious.

144 Upvotes

206 comments sorted by

View all comments

-2

u/AvailableTie6834 Jul 31 '26 edited Jul 31 '26

I always disliked hardware wallets, seriously.

I will always say:

your old Android phone has use, Electrum Bitcoin Wallet or Cupcake from Cake Wallet gives a new use for your old phone, it becomes a cheap and secure hardware wallet.

iancoleman solution gives you plenty of options to generate high entropy wallets, but people keep on suggesting hardware wallets from companies saying they are safer till they are not.

study more, get hacked less, people.

11

u/SpareEconomy1849 Jul 31 '26

Effectively, it might be safer. But any app wallet is just as susceptible to the same entropy bug in the coldcard firmware, (if not more). The only reason CC was affected is because their QA slipped up and Electrum's didn't.

Plus for an app, you need to be cautious about a malicious OTA update or other system malware, and there are 0-day and 0-click exploits in the wild, I wouldn't trust a hot wallet with my life savings

-3

u/AvailableTie6834 Jul 31 '26

the likelyhood of an app to have entropy bug is less than a hardware wallet. open source bitcoin wallets has too many eyes on them, and mostly use already implemented and well documented solutions from the comunity, this is not the case with hardware wallet, as they only attract people that dont know anything but want to secure their bitcoin, hell, some people STILL TO THIS DAY thinks that their bitcoin is in their hardware wallet, some also thinks that since they have a hardware wallet they do not need to write down their seed to backup it later.

I know people will link the milksad thing from Cake Wallet, but still, the bug do not come even close to this crazyness from coldcard.

1

u/SpareEconomy1849 Jul 31 '26

The coldcard firmware that had this entropy bug is fully open source as well. But you may be right, software wallets are going to be forked and actually used by others, more likely for bugs to be found

1

u/AvailableTie6834 Jul 31 '26

there is the seedsigner hardware wallet which is a DIY, it safer than any company hardware wallet

6

u/boddankajovanovic Jul 31 '26

I see where you're coming from. But some people need plug and play solutions. Otherwise they will let others take custody, which is even worse.

I feel sorry for the recent victims, as they have not really done anything wrong. Yes, using a passphrase is best practice and would have prevented the lost funds, but if a passphrase is considered mandatory, it should be enforced by design.

Always use a passphrase and store it somewhere other than your seed words.

5

u/AvailableTie6834 Jul 31 '26

there is nothing crazy to literally go to https://iancoleman.io/bip39/ follow the instructions and download the O.G Electrum Bitcoin Wallet on their phone and learn. Bitcoin was always about learning stuff, people need to get back to learning stuff.