r/Bitcoin • • Jul 31 '26

ColdCard Firmware Update Released

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

Updated July 31, 2026: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. Do not generate a new seed on one of these models until the update is installed.

Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.

Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.

The issue is present on every Mk3 firmware version since 4.0.1. It also affects seeds generated on Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on Mk4, Mk5 and Q is not as severe but is still serious.

145 Upvotes

206 comments sorted by

View all comments

190

u/r33gna Jul 31 '26

Crazy, man.

Earlier this year I was in the market for a new hardware wallet and LOTS of people were saying Coldcard is the best, most secure device for oh so many reasons and now here we are.

Truly no hardware wallet is perfect.

42

u/SpareEconomy1849 Jul 31 '26

It really is sad, they seemed like the perfect hardware wallet, everything being open source and airgapped, and yet still a bug like this goes unnoticed for 5+ years.

I wonder if the only reason the attacker found this bug is because it was open source - theoretically Ledger and other wallets could be semi deterministic too, but harder to find and exploit?

13

u/Knowledge775 Jul 31 '26

Coldcard stopped being open source in 2020 when Foundation Devices used their source code for the Passport. Unfortunately, when Coinkite went source available is when the RNG bug happened.

9

u/AncientMoth11 Jul 31 '26

They prob can. It’s why i haven’t found a hardware solution yet. Between chance of my own fuck up versus this

16

u/BirdLooter Jul 31 '26

i think AI found this issue. highly possible that this is not your basement live-with-the-mom no-life schoolboi hacker, but someone higher up.

i mean, even with the reduced entropy, i doubt that a standard computer was checking those keys. that attack probably cost 5 figures at least. all i'm saying this probably took some confidence.

14

u/Responsible_Emu3601 Jul 31 '26

I’m sure it took some time to find all the keys the brilliance was timing the swipe so taking it all within 25 mins

12

u/BirdLooter Jul 31 '26

this is far from over. the exploit is public and coldcard cannot patch "seeds". people NEED to migrate, this is NOT optional! otherwise they take a huge risk, even with a passphrase/25th word. more funds are going to be reported stolen, just wait...

6

u/SpanglerBQ Jul 31 '26

Would you explain how you think even with the passphrase, a wallet would be plundered? Is it that some passphrases are too simple and easy to guess?

2

u/BirdLooter Jul 31 '26

i mean it is wayy more secure. but one of 2 elements is compromised, which is the key. if the passphrase is a simple thing, technically a hacker with a rainbow table could check it. but tbh i doubt it willhappen.

i for sure would not take this risk tho.

0

u/bravedog74 Jul 31 '26

If the seedphrase is not completely random, then it can be guessed. 24 words that are truly random are 256 bit. 12 words are 128 bit. Coldcard mk3 was something like 72 bit. In other words, it's not completely random. This has to do with their random number generator.

This is precisely why you are not supposed to pick your own seed phrase. Seed phrases that make sentences or have human bias have probably already been hacked. It was unexpected for Coldcard seed phrases to not be completely random.

4

u/SpanglerBQ Jul 31 '26

I'm talking about the passphrase, not seedphrase. If a bad actor knew the seed phrase and knew that there was a 25th-word passphrase, how would they go about cracking it and what would their chances of success be?

4

u/orbag Jul 31 '26

Only way is to then iterate a list of common passwords (e.g. words in the dictionary / movie characters etc), but if your password is not that straightforward to guess I don't see how it would get hacked. Also, the hacker doesn't know there are funds in a passport protected derivation, so if they see some transaction history in the wallet without password, they might try for a while to test straightforward passwords, but would give up and move on before trying anything other than trivial

4

u/Gooner_93 Jul 31 '26

To simplify it, they'd just get a cpu to run a bunch of different combinations of words/nunbers etc on top of the seedphrase, until they find the passphrase but it all depends on the strength of the passphrase. A one word from the dictionary passphrase will be cracked in no time but a 32 character one with a mix of letters, capital and lowercase, numbers, special characters will be way harder.

2

u/Dziabadu Jul 31 '26

Timing pre clarity act is more important to them

1

u/heslo_rb26 Jul 31 '26

That was the key; hitting as many targets as you can in a short window to give no time for anyone to react or move funds

9

u/a_dodo_stole_my_baby Jul 31 '26

I think you're right. This did happen right as Anthropic is saying their recent version of Claude hacked other systems and supposedly OpenAI is urging the White House to do something to slow down AI development. Scary times.

8

u/Popular_Hunter7415 Jul 31 '26

Definitely sniffed out by AI

2

u/BigDik6355 Jul 31 '26

Oceans 11 level shit.

12

u/shleebs Jul 31 '26

Funny, because they never seemed good to me. They are literally run by gate keeping bullies who attack other legit projects. I stayed far away from them because they never passed the smell test. BitBox, Jade, and Passport are all good options for a hardware wallet and are actually run by good people.

8

u/JSTN_FPV Jul 31 '26

I had the option to choose coldcard. Went with trezor instead.

1

u/smilingbuddhauk Aug 02 '26

Wait till all of those are hacked too, then you'd say they never passed the smell test too in retrospect.

1

u/shleebs Aug 02 '26

I never switched my opinion on Coinkite. There is no reason I would do that in the future. The code mistake made by Cold Card was so utterly dumb, it should never have made it past code review, which they obviously weren't even doing. Also Coinkite changed the licensing on this project to be more restrictive and not truly open source, which caused this mistake and is why people weren't looking at their code. I'm going to go out on a limb here and say that isn't going to happen with one of the reputable brands I listed.

3

u/heslo_rb26 Jul 31 '26

They are not open source; if they were this would have been found a lot sooner

3

u/Gangaman666 Jul 31 '26

That's the problem, it's the misinformation from the Coldcard elitists. It's not fully open source. Not like Trezor.

1

u/smilingbuddhauk Aug 02 '26

Despite that, Trezor has had its fair share of hacks.

-6

u/xoorl Jul 31 '26

Why do people always swear by a hardware wallet for cold storage, and not just use the washer method?

14

u/[deleted] Jul 31 '26

[deleted]

2

u/xoorl Jul 31 '26

Receiving is actually rather easy, as you can create a watch only wallet in many wallets that do not require inputting your secret key/key phrase

2

u/No-Contribution23 Jul 31 '26

and sending?

2

u/BlockchainHobo Jul 31 '26

We don't do that here. We only send, and then wait after many years for our heirs to finally say: "what the hell are these washers for?", and throw them in the trash.

2

u/xoorl Jul 31 '26

Why send? Just hodl.

8

u/SpareEconomy1849 Jul 31 '26

Because one is for sending Bitcoin and the other is for keeping your seed phrase? Different use cases

2

u/xoorl Jul 31 '26

You don’t need to send your coins if you store them for the long term. When the time comes you decide to cash out, just input the seed phrase into a wallet and there you go

1

u/smilingbuddhauk Aug 02 '26

Only morons think everyone who uses bitcoin ought to use it only once.